# RSA RADIUS authentication fails when connecting from an external SmartEvent/Log Server

**Product**: Multi-Domain Security Management, Security Management, SmartEvent / Eventia Analyzer  
**Version**: R80.40 (EOS), R81 (EOS), R81.10 (EOS)  
**Last Modified**: 2023-08-14

## Symptoms

- In a Multi-Domain Security Management (MDS) environment, with RSA RADIUS authentication:
  
  - connecting from MDS is successful,
  - login from the SmartEvent Server (using SmartConsole client) fails.

## Cause

The `tcpdump` command capture shows that MDS sent two authentication requests to the RADIUS Server but one RSA token was already supplied by the user, so the authentication fails.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 26
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 110
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 87
- [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 198

If you choose not to upgrade, the **workaround** is to run `$MDS_FWDIR/scripts/reload_env_vars.sh -e "USE_FWM_AUTHENTICATOR=false"` on the SmartEvent Server.

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level**: General  
**Status**: Approved by TAC  
**Date Created**: 2023-02-13  
**Last Modified**: 2023-08-14
