cancel
Showing results for 
Search instead for 
Did you mean: 

sdconf.rec upload issue

jaf_
Occasional Contributor

sdconf.rec upload issue

Felt a bit silly even just asking this here.


So I inherited a SA4000 and I want it to play nice with RSA SecurID tokens we have here.
I am having issues uploading sdconf.rec to the system.

It's weird, since the box is working fine (I've created a test resource profile, user group, linked it to our domain controllers, all good) but everytime I upload the file, I get Error ID-37: Cannot upload configuration file: Server unreachable.

What I've tried:
1. Tried uploading the files from the computers on the same switch (just incase this is an issue with our network)
2. Tried uploading from different computers and different browsers (Opera, IE, Firefox), no go.

Am I missing something?
Like I said, I inherited the box, I changed the internal and external ip addresses and played around with the config, which works. That's about it.
10 REPLIES 10
whiffind_
Not applicable

Re: sdconf.rec upload issue

I'm getting exactly the same problem with one of my SA4000's and ACE, but haven't had a problem before. What version of the IVE O/S are you on? I'm on 6.3R3.

Mrkool_
Super Contributor

Re: sdconf.rec upload issue

well hae you tried pinging the rsa server from the juniper box? also can you do a tcp dump on the internal interface of the juniper to see if the juniper is trying to connect to the rsa server?
dusannovakovic_
Contributor

Re: sdconf.rec upload issue

There is a port blocked between IVE internal IP and RSA Server IP.

I think it was UDP5500 or something like that. Read the Documentation.

Pinging RSA Server is not enough. Check Firewall between the two devices.

Cheers

Mrkool_
Super Contributor

Re: sdconf.rec upload issue

yeah teh port is udp 5500 and if you have a firewall between the juniper and the rsa that will be a good place to start.
jaf_
Occasional Contributor

Re: sdconf.rec upload issue

Thanks.


There is a firewall between the rsa and the juniper box, I'll make sure with the network admin that the port is open.
If not, is there anything else I can try?
jaf_
Occasional Contributor

Re: sdconf.rec upload issue

OK, need more help.
I've made sure the ports are open between the two DMZs.
No go.
I've even moved the juniper server to the same network, no firewall.
Still no go. Same error.
Like I said, I inherited this unit, apparently out of warranty and all I did was change the ip addresses to match our network.
What am I missing here??
jaf_
Occasional Contributor

Re: sdconf.rec upload issue

So I moved the server to the same network as the RSA server. Re-created the file, still no go. Any help? Smiley Indifferent
stine_
Super Contributor

Re: sdconf.rec upload issue

Have you defined the sslvpn box as an an "agent host" on the RSA server?

stine

jaf_
Occasional Contributor

Re: sdconf.rec upload issue

Yes, I have.
Going to try again a bit later.