cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2136
Views
0
Helpful
3
Replies

Cisco ACS with RSA ACE (Callback)

schimekh
Level 1
Level 1

Hi !

I am using a Cisco ACS box combined with RSA ACE. Authentification is successful for the first time. But the router issues a callback and wants to authenticate twice. On the second attempt the tokencode is no longer valid - and callback is not successful because of the failure : RE-USE ATTACK

on the RSA ACE Server.

Why do I need a second authentification ? The call is successfully authenticated on the first time - why is there a second authentication needed ?

Thx Hans

3 Replies 3

lisa.hall
Level 2
Level 2

You may need to configure Token Caching as shown here:

http://www.cisco.com/warp/public/129/25.html

http://www.cisco.com/warp/public/129/26.html#intro

You may also want to ask your RSA people if a similar feature is avalable in the ACE Server.

guy.alexander
Level 1
Level 1

we are having the same problem you are describing .I see that your case is from september, did you solve it and how

thanks

guy

Hi,

You have to instruct the router to only authenticate on dialin and not on dialout with the following command:

ppp authentication pap callin

Also, you have to mak e sure that you use PAP (instead of the default CHAP) when authenticating with RSA tokens. Hope this helps,

Regards,

VS

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: