Solved

RSA SecurID 6.1 RADIUS Server Configuration

Posted on 2011-03-24
3
2,477 Views
Last Modified: 2012-05-11
I'm using a SecurID appliance together with my Cisco ASA to authenticate VPN users.  I also have a Cisco wireless LAN controller, and would like to use SecurID to authenticate WLAN users.  Problem is, the ASA supports SecurID's native SDI authentication mode, but the WLC only supports RADIUS.

I found a Cisco guide, which details how to get the WLC talking to SecurID via RADIUS, but I've run into a problem when setting up the built-in SecurID RADIUS server.  In Authentication Manager, under the RADIUS menu, I select Manage RADIUS Server, and receive the warning message 'RADIUS Server has not been configured'.

I've Googled this and come up empty.  I do not have a current RSA support agreement, but I contacted my sales rep, and he told me that the RADIUS server is included with the appliance, so I should already have everything I need.  I just need a guide or some help on getting the SecurID RADIUS server working.
0
Comment
Question by:FWeston
  • 2
3 Comments
 
LVL 76

Expert Comment

by:arnold
Comment Utility
As far as configuring a radius server:
First thing you have to make sure is that you add the cisco wireless LAN controller's IP as a client on the RADIUS server that came with secureID with a secert (password that is used to authenticate the messages).
Check the log on the radius server to see whether you were getting errors dealing with invalid/unknown client, ignoring message
Presumably RSA has a knowledge base/guides for just such an occasions.

http://www.rsa.com/rsasecured/guides/imp_pdfs/Cisco_PIX_702_AuthMan61.pdf
Is an example of configuring the Appliance to be used with a PIX.

What options are available within the appliance that deal with configuring/enabling RADIUS?
0
 
LVL 3

Accepted Solution

by:
FWeston earned 0 total points
Comment Utility
The only options I see in the appliance are what I detailed above in my original question.  I contacted my sales rep and apparently the RSA RADIUS server is a separate piece of software that runs on another server, which explains why I couldn't find anything on the appliance to configure.  He said he would get a copy of the RADIUS server and e-mail it to me since I don't have a support agreement and can't access the download on their website.  So I guess this question is solved.
0
 
LVL 3

Author Closing Comment

by:FWeston
Comment Utility
Determined that RADIUS server is a separate piece of software that must be downloaded from RSA.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Join & Write a Comment

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now