Check Point on Nokia appliances not able to authenticate users with RSA SecurID
Originally Published: 2004-08-31
Article Number
Applies To
Nokia
IPSO
RSA ACE/Server
Issue
Users cannot successfully perform a SecurID authentication
In /var/log/messages, the following message is recorded: [LOG_ERR] ACEAGENT: The message entry does not exist for Message ID: 1008
Cause
Resolution
1. Create the sdopts.rec file in the /var/ace directory
2. Using VI, edit the sdopts.rec file and insert the line:
CLIENT_IP=10.10.111.10 {main_ip_address ## as determined in step 1}
3. On the ACE/Server, create a new node. The main IP address is the "unique" IP address you determined in step 1.
4. Define as secondary IPs the IP addresses used as source IP address in the SecurID packet send to the SecurID server (NOTE: You can determine the address by sniffing an ACE request on the ACE/Server).
5. Stop and start FW-1 and try to authenticate.
For more information about using SDOPTS.REC, see the solution regarding How to set an IP address override for an RSA ACE/Agent and RSA Authentication Agent
Related Articles
Not able to click on Member/Entitlements/Analytics tabs of a role in role review in RSA Identity Governance & Lifecycle 14Number of Views NIC EA Startup resource is not able to be brought online 25Number of Views CA node not able to start the cluster service 24Number of Views Citrix Netscaler Version 11 device is not able to process NEW PIN post migration from RSA Authentication Manager 7.1 to AM… 123Number of Views pam_securid.so is busy, not able to remove/replace 53Number of Views
Trending Articles
This certificate or its signing CA is not valid error when importing a certificate chain in RSA Authentication Manager 8.x… RSA Authentication Manager Upgrade Process Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… RSA Authentication Agent 1.0.1 for Active Directory Federation Services (AD FS) sends domain\samAccountName instead of UPN…
Don't see what you're looking for?