ODA (on demand access) token.will not authenticate when connecting thru a Netscaler VPN Gateway
2 years ago
Originally Published: 2015-03-30
Article Number
000061010
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1.0
Platform: Linux
Platform (Other): null
O/S Version: null
Product Name: null
Product Description: null
Issue
On Demand Token don't work when authenticating thru a Netscaler Access Gateway
Cause
Load balancing was configured on the Netscaler to point to one Authentication Manager primary and three replica servers. 

When the authentication request with the PIN was sent to the primary, the RADIUS challenge for the next tokencode was being sent to the Netscaler.

The Netscaler sent the next authentication request with the tokencode in reply to the RADIUS challenge to the replica configured for load balancing.

We removed the load balancing configuration and ODA started to work correctly  
Resolution
Remove Load balancing from the Netscaler configuration