<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00006SjTRGSA3Okta Classic EngineMulti-Factor AuthenticationAnswered2025-01-20T09:02:26.000Z2019-07-18T19:39:25.000Z2019-08-16T12:46:22.000Z

inyq9 (inyq9) asked a question.

Set up RSA MFA with Okta

Has anyone here actually set up the on-prem MFA with RSA authentication manager and Okta?

I have followed the instructions on set up, but the RADIUS client of the Okta agent never hits the RADIUS server running on the AM. Try to use the hardtoken code, and get nothing.

 

Would be interested to know if anyone else in the community has used this successfully, or if they have used the RSA as an IDP into Okta, for use with hardtokens.


  • inyq9 (inyq9)

    Just for anyone else who searches this post in the future, make sure in the Okta dashboard, where you set up the MFA connector to RSA, that instead of FDQN, that it is an actual IP. The port we used was also 1812.

    We didn't need an external IP or the "rsa cloud authenticator/cloud SAML", etc what RSA support was thinking we needed. once we set the IP and restarted the on-prem okta MFA agent service on the host (windows) server, it all worked like a charm. finally.

    Expand Post
    Selected as Best
  • inyq9 (inyq9)

    Right, I have spoken to support, but the question remains: is anyone actually using this? I can't find any proof that this works or that someone is using it, so I am asking the Okta community.

     

  • EricK.22493 (Kohl&amp;#39;s)

    +1 here for 'actively using successfully' at scale in production. We have been using it for 2+ years

  • inyq9 (inyq9)

    Eric, if you ever check this again, is there a way to ask you questions about your setup? RSA and Okta support don't really have any answers for our set up issues.

    Are you using the Okta Agent in On-Prem setup as a RADIUS client to an Authentication Manager running your hardtokens? Did you have to add inbound SAML?

  • inyq9 (inyq9)

    Just for anyone else who searches this post in the future, make sure in the Okta dashboard, where you set up the MFA connector to RSA, that instead of FDQN, that it is an actual IP. The port we used was also 1812.

    We didn't need an external IP or the "rsa cloud authenticator/cloud SAML", etc what RSA support was thinking we needed. once we set the IP and restarted the on-prem okta MFA agent service on the host (windows) server, it all worked like a charm. finally.

    Expand Post
    Selected as Best
  • GregH.00578 (Customer)

    I have set up on prem RSA.

    No issues using a FQDN.

    We are using the On Prem Okta Agents as radius clients in RSA.

    We have been using this for approx 2 years.

     

This question is closed.
Loading
Set up RSA MFA with Okta