DNS Server Configuration on the Amazon Web Services Virtual Private Cloud
For hostname resolution, the Amazon Web Services (AWS) appliance requires you to configure a DNS server in the Virtual Private Cloud (VPC).
You must create a DHCP options set, associate it with the VPC, and then change the VPC properties. In a mixed on-premises and AWS deployment, any on-premises RSA Authentication Manager primary and replica instances need to use the DNS server that is configured in the VPC.
The default DNS server for AWS uses the IP address 169.254.169.253. If you use the default DNS server, any subnet within the VPC can use 169.254.169.253 as the primary DNS server for AM.
For more information on DNS servers, see the Amazon Virtual Private Cloud User Guide at https://docs.aws.amazon.com/vpc/.
Note: AWS also includes a default Network Time Protocol (NTP) server with the IP address 169.254.169.123 that you can specify during Quick Setup.
Create a DHCP Options Set
Each VPC requires at least one DHCP options set. You can create multiple sets of DHCP options, but you can only associate one set of DHCP options with your VPC at a time.
Procedure
Open the Amazon VPC console at https://console.aws.amazon.com/vpc/.
In the navigation pane, select DHCP Options Sets, and then select Create DHCP options set.
In the dialog box, enter values for the options that you want to use. For the Domain name servers value, specify your own DNS server or Amazon's DNS server (AmazonProvidedDNS). The default DNS server for AWS uses the IP address 169.254.169.253.
Note: This must be the same DNS server that is used to configure RSA Authentication Manager during Quick Setup.
Select Yes, Create.
The new set of DHCP options appears in your list of DHCP options.
Record the ID for the new set of DHCP options (dopt-xxxxxxxx). The ID is required to associate the new set of options with your VPC.
Associate DHCP Options with a VPC
You can change the DHCP options associated with the VPC.
Procedure
- Open the Amazon VPC console at https://console.aws.amazon.com/vpc/.
In the navigation pane, select Your VPCs.
Select the VPC, and select Edit DHCP Options Set from the Actions list.
In the DHCP Options Set list, select a set of options.
Click Save.
Any existing AWS instances and all new AWS instances that you launch in that VPC will use the options.
You do not need to restart or relaunch the AWS instances. The instances automatically pick up the changes within a few hours, depending on how frequently the instance renews its DHCP lease. You can explicitly renew the lease in AWS. For instructions, see the AWS documentation.
- Open the Amazon VPC console at https://console.aws.amazon.com/vpc/.
In the navigation pane, select Your VPCs.
Select the VPC, and select Edit DNS Resolution. Select Yes.
Select the VPC, and select Edit DNS Hostnames. Select No.
Change the VPC Properties
You can change the VPC properties. Any on-premise RSA Authentication Manager primary and replica instances need to use the DNS server that is configured in the VPC.
After you finish
You must update the on-premise primary instance and replica instance hostname and IP address to the DNS server that was used in the above configuration. For instructions, see Change the Primary Instance IPv4 Network Settings and Change the Replica Instance IPv4 Network Settings.
Related Articles
DNS Server Configuration on the Azure Virtual Network 12Number of Views IDR Cannot Register with Cloud Authentication Service with Explicit Proxy and DNS Does not Resolve Authentication Service … 226Number of Views How to configure an RSA Authentication Manager 8.1 server to accept a system-generated PIN when a token is in new PIN mode… 286Number of Views Determine the correct root (base DN) and user search filter when configuring an identity source for the RSA SecurID Access… 132Number of Views Scheduled backups fail and Backup Now fails with 'A replication or backup task is in progress' in RSA Authentication Manag… 1.05KNumber of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)