This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Knowledge Base

Find answers to your questions and identify resolutions for known issues with knowledge base articles written by SecurID experts.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Knowledge Base
  • :
  • Migrating an RSA Authentication Manager deployment from one environment to another
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

Migrating an RSA Authentication Manager deployment from one environment to another

Article Number

000036402

Applies To

RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 Service Pack 1 or later
 

Issue

This article explains the process of migrating an Authentication Manager deployment from one supported environment to another supported environment; for example, from Microsoft Hyper-V to VMware or from a hardware SecurID appliance to VMware.

Resolution

To minimize the impact to a production environment an administrator may want to consider the following steps to migrate an Authentication Manager deployment from one supported environment to another supported environment. For this knowledge article a Microsoft Hyper-V environment hosting a primary and replica instance running Authentication Manager 8.1 Service Pack 1 Patch 4 software in production will be migrated to an Authentication Manager deployment in a VMware environment.

Migration Steps 

  1. Deploy RSA Authentication Manager 8.1 software, in this example the 8.1 .ova template and build a new primary instance using new fully-qualified hostname and network settings. The new primary instance deployment will require an authentication manager 8 license zip file.

Please review 000034558 - How to download RSA Authentication Manager 8.x full kits and service packs from RSA Link.

Relevant documentation

  • RSA Authentication Manager 8.1 SP1 Virtual Appliance Getting Started 
  • RSA Authentication Manager 8.1 SP1 Setup and Configuration Guide

Ensure any configured identity sources used in production are reachable from the new primary instance.

  1. Apply RSA Authentication Manager 8.1 Service Pack 1 software to the new primary instance.
  • Download RSA Authentication Manager 8.1 Service Pack 1  and RSA Authentication Manager 8.1 SP1 Release Notes.

Review the RSA Authentication Manager Updates page.

  1. Apply RSA Authentication Manager 8.1 Service Pack 1 Patch 4 software to the new primary instance.  Download the software and readme for RSA Authentication Manager 8.1 Service Pack 1 Patch 4 (8.1.1.4.0).
  2. Following the steps in Create a Backup Using Back Up Now, perform a backup from the 8.1 SP1 P4 (8.1.1.4.0) production Authentication Manager deployment, in this example running in a Microsoft Hyper-V environment.
  3. Following the steps in Restore from Backup, restore the production backup onto the new primary instance running RSA Authentication Manager 8.1 Service Pack 1 Patch 4 (8.1.1.4.0) software.

An Authentication Manager backup can only be restored into a primary instance running the same software level as the primary instance that performed the backup.

  1. Plan to shut down the production Authentication Manager deployment and change the new primary instance IPv4 network settings to match those used in production.  Refer to Change the Primary Instance IPv4 Network Settings for more information.
Ensure any configured identity sources used in production are reachable from the new primary instance.
 

If you are not changing the new primary instance IPv4 network settings then you will need to update RSA Authentication Agents (and/or third party products) with a new configuration record (sdconf.rec) file.

  1. Confirm the new primary instance can process end user authentications. Use the Real-Time Authentication Activity Monitor to verify authentication activity.  From the Security Console on the primary instance choose Reporting > Real-time Activity Monitors > Authentication Activity Monitor and choose Start Monitor.
  2. Having confirmed the new primary instance is performing its job then deploy Authentication Manager 8.1 software to the new replica then build and attach the new replica instance. This new replica instance can use the old production replica network settings or not, depending on how you want to setup the new replica instance. 
  3. Using the RSA Authentication Manager 8.1 Service Pack 1  and RSA Authentication Manager 8.1 SP1 Release Notes downloaded in step 2, apply RSA Authentication Manager 8.1 Service Pack 1 software to the new replica instance.
  4. Using the software for RSA Authentication Manager 8.1 Service Pack 1 Patch 4 obtained in step 3, apply Patch 4 to the new replica instance.
  5. Check replication between the primary and replica instances.
  6. Verify RSA RADIUS Replication.
  7. Perform further authentication testing.  Use the Real-Time Authentication Activity Monitor to verify authentication activity.  From the Security Console on the primary instance choose Reporting > Real-time Activity Monitors > Authentication Activity Monitor and choose Start Monitor.
Tags (51)
  • 8
  • 8.1
  • 8.1.x
  • 8.2
  • 8.2.x
  • 8.3
  • 8.3.x
  • 8.x
  • AM
  • Appliance
  • Auth Manager
  • Authentication Manager
  • Customer Support Article
  • Helpful Hints
  • How To
  • Informational
  • Instructions
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Migrate
  • Migrating
  • Migration
  • Migration Help
  • Migration Instruction
  • Migration Steps
  • Process Steps
  • Product Migration
  • RSA AM
  • RSA Auth Manager
  • RSA Authentication Manager
  • RSA SecurID
  • RSA SecurID Access
  • RSA SecurID Suite
  • SecurID
  • SecurID Access
  • SecurID Appliance
  • SecurID Suite
  • Tip &amp Tricks
  • Tips and Tricks
  • Tutorial
  • Version 8
  • Version 8.1
  • Version 8.1.x
  • Version 8.2
  • Version 8.2.x
  • Version 8.3
  • Version 8.3.x
  • Version 8.x
  • Walk Through
  • Walkthrough
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2021-04-23 02:29 PM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.