...
An index of several common issues that you can encounter when setting up RSA SecurID, RADIUS or SAML authentication with Vmware Unified Access Gateway.
Setup Guidelines:Rsa SecureID Setup: VMware Documentation: Configure RSA SecurID Authentication in Unified Access GatewayVendor Documentation: VMware Unified Access Gateway - RSA Ready SecurID Access Implementation Guide (3rd party link maintained by Vendor - Content not under VMware control) Radius Setup: VMware Documentation: Configuring RADIUS for Unified Access GatewayVmware KB: Guidelines when Integrating Radius (82726) Saml Setup: VMware Documentation: Authentication Methods for Unified Access Gateway and Third-Party Identity Provider IntegrationVMware Documentation: Configure SAML Authentication for Admin UI VMware Walkthrough Tutorial with Okta: Vmware Techzone: Enabling SAML 2.0 Authentication for Horizon with Unified Access Gateway and Okta: VMware Horizon Operational Tutorial Saml Vendor Documentation (3rd party link maintained by Vendor - Content not under VMware control) Microsoft Azure Tutorial: Azure Active Directory single sign-on (SSO) integration with VMware Horizon - Unified Access GatewaySecureAuth: VMware Horizon and UAG SAML integrationInWebo: VMWare Unified Access Gateway (UAG) SAML integrationOracle Cloud Infrastructure (OCI): Enable SAML 2.0 authentication for VMware Horizon with Unified Access Gateway and OCI IAM Identity DomainsWatchGuard: VMware Unified Access Gateway Integration with AuthPoint An Index of Known Issues:RSA: RSA AM invalid certificate issues on UAG 2111 and later (88004) - This article outlines issues with certificate trust between the Unified Access Gateway and the RSA server. Logging in to Horizon with RSA SecurID on UAG appliance fails with an incorrect username or passcode (88005) - This article outlines potential alternate causes beyond an incorrect username and password. “Authentication method could not be configured” error when configuring RSA SecurID settings on UAG (88003) - This article outlines a typical configuration error caused by a setting required by UAG (Authentication API) set to disabled by default.Authentication using RSA SecurID on UAG fails with routing issues or firewall block (88002) - This article outlines a situation where the RSA AM server REST API is not reachable from UAG and methods to troubleshoot this. RADIUS: Unified Access Gateway(UAG): Access Denied with RADIUS authentication and ERROR_AUTHENTICATOR logline (87337) - This article outlines a specific scenario where there is a mismatch of client-secret between server and client. SAML: SAML authentication fails with Azure Active Directory B2C as a 3rd party Identity provider (IDP) (81878) - This article outlines a scenario where an invalid UPN causes failure. Resolved Issues: Unified Access Gateway(UAG): RADIUS and RSA SecurID Authentication Failure with Unified Access Gateway (UAG) 2111 and 2111.1(87253) - This has been rectified in Unified Access Gateway versions 2111.2 and later.