11.07.2015 Views

RSA Authentication Manager 6.1 Administrator's Guide - The Ether ...

RSA Authentication Manager 6.1 Administrator's Guide - The Ether ...

RSA Authentication Manager 6.1 Administrator's Guide - The Ether ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>RSA</strong> <strong>Authentication</strong> <strong>Manager</strong> <strong>6.1</strong> Administrator’s <strong>Guide</strong><strong>The</strong> <strong>RSA</strong> <strong>Authentication</strong> <strong>Manager</strong> provides:• Continuous authentication service to Agent Hosts• Offline authentication data to computers whose users are often disconnected fromthe network (computers with <strong>RSA</strong> <strong>Authentication</strong> Agent <strong>6.1</strong> only)• Cross-realm authentication services for users visiting from other realms• Administrative functions for the <strong>Authentication</strong> <strong>Manager</strong> system (on the Primaryonly—administrative functions are limited on Replicas)• Real-time monitoring of <strong>RSA</strong> SecurID authentication and administrative activityAutomatic Load BalancingVersion 5.0 (and later) <strong>RSA</strong> <strong>Authentication</strong> Agents can do automatic load balancingby polling the <strong>Authentication</strong> <strong>Manager</strong>s and selecting the one that responds mostquickly to an authentication request. You can also balance the load manually byconfiguring Agents to give higher priority to different <strong>Authentication</strong> <strong>Manager</strong>s. Formore information, see “Load Balancing by Agent Hosts” on page 69.<strong>Authentication</strong> <strong>Manager</strong> and Agent Host Communication ThroughFirewallsAn <strong>RSA</strong> <strong>Authentication</strong> Agent Host can use up to three alias <strong>Authentication</strong> <strong>Manager</strong>IP addresses to communicate with an <strong>RSA</strong> <strong>Authentication</strong> <strong>Manager</strong> that is located onthe other side of one or more firewalls. When one of these firewalls intercepts anauthentication request, it recognizes one of the <strong>Authentication</strong> <strong>Manager</strong>’s alias IPaddresses and uses an established protocol to match the alias with a valid IP address.For information on setting alias <strong>Authentication</strong> <strong>Manager</strong> IP addresses, see theWindows Installation <strong>Guide</strong>.<strong>The</strong> configuration file of an Agent Host separated from the <strong>Authentication</strong> <strong>Manager</strong>by a firewall must contain the list of available aliases. If you have legacy Agent Hoststhat must authenticate through a firewall, and you want to use an alias IP address thatis not listed in the database as an available alias, you can use the Configuration RecordEditor to edit the Acting Master and Slave <strong>Authentication</strong> <strong>Manager</strong> fields in anysdconf.rec file. For more information, see “Legacy Agent Hosts” on page 75.Legacy Agent SupportTwo changes in <strong>RSA</strong> <strong>Authentication</strong> <strong>Manager</strong> 5.0 (and later) architecture improvedauthentication rates over previous major versions: the use of multiple authenticatingReplicas and the ability of the new <strong>RSA</strong> <strong>Authentication</strong> Agent software to select theReplica that will respond most quickly to an authentication request. <strong>The</strong> new Agentsoftware is aware of all the Replicas in your realm and can send authenticationrequests to any one of them.Lacking this ability, Agent Hosts running versions of <strong>RSA</strong> ACE/Agent software prior to5.0 can authenticate users against only the Master or the Slave, because the Agent Host’sconfiguration file (sdconf.rec) identifies only these two <strong>Authentication</strong> <strong>Manager</strong>s.For more information about legacy Agent issues, see “Legacy Agent Hosts” on page 75.1: Overview 25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!