Forum Discussion
Martijn_van_de1
Nov 17, 2017Cirrus
Jacob,
What is the RSA Authentication Report (logs) telling you?
Do you have a Primary and Replica RSA server? When you delete the sdstatus.12 file, the BIG-IP is performing the first authentication to the Primary RSA server. Once authentication is successfull, the node secret is exchanged and the sdstatus.12 file is updated telling the BIG-IP there is a Replica in the network.
This RSA setup is active/active meaning both RSA servers are accepting authentication request. The difference is, the Replica has a read-only database.
Could it be there is a firewall between BIG-IP and RSA and the firewall is not configured to allow SecurID traffic to the Replica RSA server?
Regards, Martijn.