Cisco Router with IOS 12.2(2)XB/12.2(4)T or later unable to handle New PIN Mode and Next Tokencode Mode Authentications through RADIUS
Originally Published: 2003-11-04
Article Number
Applies To
IOS 12.2(2)XB/12.2(4)T or later
Issue
Resolution
12.2 mainline should not have this problem, but model 3745 only runs 12.2T or 12.3, so there's no other option for the 3745. Bottom line - this is a bug in the IOS. The issue arises because Multitransaction RADIUS authentication uses the state attribute in the server's response packet to maintain continuity of the transaction which is handled in UDP packets. The router fails to respond with the same state attribute in the third packet of the communication. There is no state attribute in the packet.
Cisco is aware of the issue as of November 1, 2003, see Cisco defect CSCed22074. Please contact Cisco for the fix. The problem does appear to be fixed in IOS 12.3.7T.
Related Articles
New PIN Mode and Next Token Mode fail on Cisco VPN 3000 Concentrator with RSA ACE/Server 42Number of Views Authentication using acetest fails TRANSACTION_ROLLBACK on real time authentication activity monitor for RSA Authenticatio… 65Number of Views Enable or disable time sync to NTP from command line for RSA Authentication Manager 8.x 173Number of Views How to Obtain the RSA Root CA Certificate from RSA Authentication Manager 8.x — Browser or SSH 310Number of Views How to calculate the RSA REST API Authentication Response Time 228Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Release Notes: Cloud Access Service and Authenticators RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?