RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.6 and later
Component: RADIUS (Free RADIUS)
When troubleshooting RADIUS authentication failures or unexpected behavior in RSA Authentication Manager 8.6 and later, it may be necessary to enable RADIUS debug logging and verbose tracing to capture detailed diagnostic information.
RADIUS debug logs can help identify:
- Authentication request and response details
- RADIUS packet-level communication errors
- Misconfigurations in RADIUS server settings
CAUTION: Enabling RADIUS debug logging increases log verbosity and may impact server performance. Enable it only during active troubleshooting and disable it immediately when testing is complete.
NOTE: These steps must be repeated on each RADIUS server in your deployment.
-
Log in to the Operations Console using the Operations Console administrator username and password.
- Navigate to Deployment Configuration > RADIUS Servers > Manage Existing.
Once prompted, enter the Super Admin credentials for the Security Console. - Click the dropdown arrow next to the primary Authentication Manager server and select Manage Server Files.
- Click the dropdown arrow next to the radiusd.conf file and select Edit.
- Change the debug_level value to 2, as shown:
debug_level=2 - Click Save & Restart RADIUS Server to apply the changes.
NOTE: The server restart is required for the debug changes to take effect. - Verify: Confirm that RADIUS debug logging is active by checking the log file at
/opt/rsa/am/radius/radius.logon the respective server. - When RADIUS troubleshooting is complete, disable debug logging by repeating Steps 1–6, setting debug_level back to 0, then clicking Save & Restart RADIUS Server.
-
Log File Location: RADIUS log files for Authentication Manager 8.6 and later are stored at /opt/rsa/am/radius/radius.log on their respective servers.
-
Performance Impact: Debug logging at level 2 generates a high volume of log data and may affect RADIUS server performance. Always disable debug logging promptly after troubleshooting is complete.
-
Alternative Editing Method: While it is recommended to edit the
radiusd.conffile through the Operations Console, the file can also be edited directly on the server at/opt/rsa/am/radius/radiusd.confusing a text editor. However, changes made directly to the file still require a RADIUS server restart to take effect. -
Version Scope: These steps apply to RSA Authentication Manager 8.6 and later only, which uses Free RADIUS
For a step-by-step video guide, please view this YouTube tutorial: here
Related Articles
Trending Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide How to Download OTP Token Seed Files from myRSA Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU