cancel
Showing results for 
Search instead for 
Did you mean: 

Vasco OTP on IAS and SA 2000

ssltest_
Occasional Contributor

Re: Vasco OTP on IAS and SA 2000

The issue exits without the Vasco so this look like IAS and Juniper issue.

Radius ping works so Microsoft IAS is working fine I guess. Also, moving

to another server with IAS didnt helped.

There is no firewall/LAN so this look like a mystry for now.

ssltest_
Occasional Contributor

Re: Vasco OTP on IAS and SA 2000

Hi, There is no firewall (flan LAN) and the juniper can ping to the IAS etc.

I even setup a new IAS server on a fresh installed server and the same error

prompt.

I tried to downgrade to IVE Platform version 6.3 R1.1 Build # 13563 and now

I getting a new error:

2008/12/12 23:16:33 - [10.0.0.1] - username(Users)[] - Sign-in rejected using auth server Tadius_Server (Radius Server). Reason: Failed

Very strange... Look like IVE bug.. The same errors message was reported in the past on 6.0R3 if I dont mistake.

Also, the TAC doesnt find any solution until now.

Thanx

keith_
Contributor

Re: Vasco OTP on IAS and SA 2000

Does anything appear in the Vasco Audit Viewer? (ie failed login attempt etc)

Also, you say that you're using both NICs on the IVE. I assume that the routes are set up correctly? Can you ping the Vasco server from the IVE? When you set up RSA, was it in the same subnet as the Vasco server now is?

ssltest_
Occasional Contributor

Re: Vasco OTP on IAS and SA 2000

Hi,

I cant ping to the internal SA Nic and the SA can ping to the server.

The RSA was setup in another server in the LAN (In the same subnet).

The login attempt sometimes appear in the Vasco log and sometimes no.

However, Vasco simulator works fine (i.e the same apply to Vasco logs while using

Vasco simulaotr).

I tried also to install a fresh IAS without Vasco and the same error occured so I guess

that this isnt Vasco issue.

Internal Nic 10.0.0.253 /24

DG 10.0.0.254 /24 (SSG 140 LAN/Trust zone)

External Nic 1.0.0.1 /24

DG 1.0.0.254 /24 (SSG 140 DNZ Zone)

Thanx

keith_
Contributor

Re: Vasco OTP on IAS and SA 2000

If you don't mind me asking, why are you using IAS? Vasco can also answer RADIUS calls, if that's all you're using IAS for