RADIUS replication error after importing a migration package to primary with a new IP address in RSA Authentication Manager 8.1
Originally Published: 2016-04-07
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.0/8.1
Platform: SUSE Linux Enterprise
O/S Version: SUSE Linux 11 SP3
Product Description: RSA SecurID Appliance
Issue
This option preserves the overall setup that you tested, and you import data that was updated on version 7.1 during the testing period, such as user and token data.
If a primary IP Address was updated, and AM7.1 migration package was imported, then RADIUS Replication fails with an error:
“Initiating Data Transfer”
Critical Notification Event generates as below:
Attention!
The following critical system event occurred:
RADIUS replication failed. RADIUS replica am81r1.vcloud.local did not acknowledge a replication attempt.
Cause
Workaround
1. Install 8.1 SP1 Standalone
2. Import Migration Package from 7.1
3. Add a Replica server
4. Confirm replication is healthy (both AM and RADIUS)
5. Change Primary IP address (Operations Console > Administration > Network > Appliance Network Settings)
6. On the Replica, manually modify '/etc/hosts':
Operations Console > Administration > Network > Hosts File
6. Manually modify '/etc/hosts' on both Primary and Replica to have the correct entries (add missing entries, correct Primary IP address etc.)
Operations Console > Administration > Network > Update Primary Hostname
Note: The Primary IP should be correct and 'Test Connection' should be successful
8. Click Save
Note: This among other things configures RADIUS. At this point both AM and RADIUS Replication should be healthy
For subsequent migration import (retaining system setting) scenario:
9. Perform another 7.1 migration but this time select 'Retain system settings and the deployment topology during import.'
10. When finished, on the Replica Go to:
Operations Console > Administration > Network >Update Primary Hostname
Note: The Primary IP should be correct and 'Test Connection' should be successful
11. Click Save
Note: At this point Radius replication should be broken and Initiate replication on the Primary won't be able to resolve the issue.
12. Configuring RADIUS again running the command on both Primary and Replica.
Type:
rsaadmin@am81p:~>cd /opt/rsa/am/config/
/opt/rsa/am/config> ./config.sh RadiusOCConfig.configure
13. Then restart RADIUS services on respective instances. You may require click Initiate Replication in some cases.
Type:
rsaadmin@am81p:~>cd /opt/rsa/am/server/
/opt/rsa/am/server> ./rsaserv restart radius
Related Articles
Recover from an Incorrect IP Address Change 127Number of Views Radius Server Crashed with status Unknown after adding alternate IP to authentication Agent on AM 8.x 127Number of Views How to send authentication requests to alternative/secondary IP addresses of the RSA Authentication Manager 8.x server 81Number of Views RSA Authentication Manager 8.x RADIUS unreachable or initiating data transfer after changing IP address of the replica server 2.26KNumber of Views Update the Primary Instance Hostname and IP Address on a Replica Instance 184Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Artifacts to gather in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide How to Download OTP Token Seed Files from myRSA
Don't see what you're looking for?