IDR: Authentication Manager Connection Notification Status Appears Unhealthy
16 days ago
Article Number
000073726
Applies To

RSA Product Set: SecurID Access
RSA Product/Service Type: IDR
RSA Version/Condition: All supported versions
Component: Authentication Manager Notification Status

 

Issue

When viewing the Authentication Manager connection status in IDR, the Notification Status appears as Unhealthy.
This can be observed by navigating to: Cloud Administration Console > Platform> Identity Routers 

Cause

This issue occurs when TCP port 5555 is not open between IDR and Authentication Manager, particularly in environments where the legacy TCP agent is still used for the CAS-to-AM connection.
Port 5555 is required for the REST-based Notification Service on Authentication Manager. If this port is blocked or inaccessible, Authentication Manager cannot receive notification messages from IDR.

Resolution
  1. Ensure that the API port is enabled on the Authentication Manager. For instructions, see Configure Authentication Manager API

  2. On the firewall or network device between IDR and Authentication Manager, enable bidirectional communication on TCP port 5555.

  3. Ensure that port 5555 is open in both directions:

    • From IDR to Authentication Manager
    • From Authentication Manager to IDR
  4. Verify: Once port 5555 is open, navigate to Cloud Administration Console > Platform> Identity Routers and confirm that the Notification Status now displays as Healthy.

Notes