cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
620
Views
0
Helpful
2
Replies

Strange RSA issue

smjaggers
Level 1
Level 1

Hello,

I am trying to have a new VPN profile on a ASA 5520 at one of my remote sites authenticate to an RSA server in our main data center.  The sites are connected via MPLS.  I have set my SDI interface to the MPLS interface, verified the settings in RSA, and verified all the SDI settings.  My issue is everytime I try and do the Auth test with a legit user I recieve:

ERROR: Authenication Server not responding: No Error

I next began checking NATs, and routes and verified all was in place.  I set up a packet capture on my remote office ASA on the MPLS interface, and on the main DS MPLS and inside (where the RSA server resides) interface.  Below is the capture:

Remote office MPLS:

   1: 14:55:06.883209 192.168.0.2.28306 > 192.168.20.15.5500:  udp 508
   2: 14:55:08.906081 192.168.20.15.5500 > 192.168.0.2.28306:  udp 508

Main DS MPLS:

  1: 14:55:06.884750 192.168.0.2.28306 > 192.168.20.15.5500:  udp 508
  2: 14:55:08.894729 192.168.20.15.5500 > 192.168.0.2.28306:  udp 508

Main DS inside:

  1: 14:55:06.884826 192.168.0.2.28306 > 192.168.20.15.5500:  udp 508
  2: 14:55:08.894729 192.168.20.15.5500 > 192.168.0.2.28306:  udp 508

So the network is ruled out as I am seeing all the packets at each interface.  When I run a packet tracer fromt he remote office ASA I get the packet dropped due to a configured ACL rule. (the default deny)  However I have a permit IP any any on the MPLS interface, and if the packet were actually getting dropped, then the packets would not show up in the packet capture.

Any ideas?  I am banging my head against a wall here.

Thanks

2 Replies 2

Marcin Latosiewicz
Cisco Employee
Cisco Employee

I'm by no means an epxert on SDI but I would definetly check logs for this agent on RSA side.

Do you already have the *.sdi file donwloaded on your flash? Is the RSA server set or not to send node secret?

Make sure that RSA will use SDI 5.0 or 6.0 to communicate to ASA:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_aaa.html#wp1057621

Hope this helps,

Marcin

Thanks for the response, I am off site today, but will check this in the morning and update.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: