For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

OM's avatar
OM
Icon for Altocumulus rankAltocumulus
Jun 18, 2016

RSA SecurID Multiple domain partitions

hello, I have 2 partition domains sharing the same RSA securid aaa. As the 2 partitions are using the same self-ip, the RSA server does not accept the connection from 2 apm instances at the same time, so the authentication is rejected.

 

did you guys experiment such a scenario ? any idea how to get over this issue ?

 

thank you.

 

O.

 

1 Reply

  • Lucas_Thompson_'s avatar
    Lucas_Thompson_
    Historic F5 Account

    RSA can handle this OK, it's a configuration item called "Secondary node address". It's meant to be used in the situation that the authentication clients are behind a source-NAT or other similar situation.

     

    The root of the problem is that there is only one copy of the linux RSA authentication daemon in BIG-IP at a time that runs in user space.