User name included in RADIUS response packet in RSA ACE/Server; 'Passcode Accepted' message followed 'Access Denied' and 'auth lock' errors
Originally Published: 2002-05-09
Article Number
Applies To
Sun Solaris 2.8
Microsoft Windows 2000
UNIX (AIX, HP-UX, Solaris)
All supported platforms
All UNIX platforms
RADIUS
3rd-party access server, Jtec frame switch module, FSM-16
Issue
Response delay time is set to 1 second but RADIUS authentications still fail
Error: "ACCESS DENIED, auth lock error"; users locked out for 10 minutes after the error
Dial-up through access server doesn't work after upgrade to ACE/Server 5.0.x
Error: "auth lock error" in the ACE/Server logs
In the ACE/Server logs, "Passcode Accepted" message is immediately followed by "Access Denied" and auth lock errors
RADIUS authentications were working before upgrade
RADIUS authentications fail
Other RADIUS devices are working fine
A packet sniffer shows that successful response packet from ACE/Server includes attribute 1, User NAME in response packet
ACE/Server LOG show:
04/24/2002 01:33:42U jsilk/Jtec_server 000072629150
04/24/2002 11:33:42L Passcode accepted cyclone
04/24/2002 11:33:42L Johan Silkenas
04/24/2002 01:33:46U jsilk/Jtec_server 000072629150
04/24/2002 11:33:46L ACCESS DENIED, passcode incorrect cyclone
04/24/2002 11:33:46L Johan Silkenas
04/24/2002 01:33:46U ------/Jtec_server 000072629150
04/24/2002 11:33:46L ACCESS DENIED, auth lock error cyclone
04/24/2002 11:33:46L -----
04/24/2002 01:33:50U jsilk/Jtec_server 000072629150
04/24/2002 11:33:50L ACCESS DENIED, passcode incorrect cyclone
04/24/2002 11:33:50L Johan Silkenas
04/24/2002 01:33:50U ------/Jtec_server 000072629150
04/24/2002 11:33:50L ACCESS DENIED, auth lock error cyclone
04/24/2002 11:33:50L -----
04/24/2002 01:33:54U jsilk/Jtec_server 000072629150
04/24/2002 11:33:54L ACCESS DENIED, passcode incorrect cyclone
04/24/2002 11:33:54L Johan Silkenas
04/24/2002 01:33:54U ------/Jtec-server 000072629150
04/24/2002 11:33:54L ACCESS DENIED, auth lock error cyclone
04/24/2002 11:33:54L -----
Cause
Resolution
Workaround
Related Articles
Error: 'Problem processing request: message is 'Authentication Failure: 0 Access Denied.'' in RSA ACE/Server Quick Admin; … 25Number of Views Error message "Access denied - User not a member of any identity source in access policy" in RSA SecurID Access 81Number of Views How to use Microsoft Windows Powershell to find the checksum values of RSA Authentication Manager files 170Number of Views Setting Up an Application Trust 16Number of Views Warning message "WARN Unable to find an Attribute length for : business_unit_id or supervisor" logging after installation… 24Number of Views
Don't see what you're looking for?