Context Aware Access - know issue with some ISPs

rdnixon
Contributor

Just flagging an know issue with Context Aware access. We restrict access to the UK using context aware access. Some ISP issue what presents as a UK IP - but does not validate as being definitely UK in the Google backend and therefore get flagged and blocked. The one I had today was BT - someone at home could not access anything. Google say they are working with ISPs to make this more robust. So the workaround for now was to stick in another rule to explicitly allow the users home IP address. Only one so far...... Hoping there are not anymore.

5 REPLIES 5

Bill_Gibson
Contributor III

We're switching to US only on 10/1
🤞

sujka
New Contributor III

Hey,

I enabled it over 2  summer ago and had to turn it off. I am not sure where geographically you are in the USA but we have major issues.

Without a policy or governance/compliance program, you are going to run into several things like teachers traveling during the summer internationally, students who travel during the summer, even during the school year, internationally, and possible contractors who are international (e.g. we use Google as are source of auth but turn off all the other services by OU). 

If you figure that out the next hurdle is what you are experiencing. When I had it on, I had people literally standing next to me, within my building, who were blocked by geographical restrictions. Their ISP was handling out IPv6 addresses (cell phone) that were originating the IP addresses from upper New York. I had to believe that the close proximity to Canada was the issue. In addition, I had teachers within the town, the state, and the continental USA who were getting blocked. I started to have to whitelist all our islands (not just Hawaii), Canada, and Mexico, and then without a policy (referring to above) Italy, Germany, UK, and even China (had a student there). 

Now I hope some how they have smarter intelligence (oxymoron I know) for when you turn it on or are trying it. Maybe geographically in the USA are more central to the country then I am but if they are going off only originating IP addresses, not announcing, you could still be in a pickle and huge inconvenience. 

We geo block at our firewall for inbound connections to our sites, use the whitelist IP allow for Google Admin Console, but have to look the other way on the geo feature of the context aware until they have a way to truly allow and only allow the USA.

Mike

We have had it on since it's been a thing and are UK based - not US. To date this is the only issue we have had. Simple to fix by whitelisting the IP. As far as overseas travel goes we expect people to inform us via a support ticket and we whitelist their destination (if appropriate) or if they are working there for an extended period - just their IP address. If they don't inform us in advance - its just a canned response from the helpdesk - short version is "No - tough".

Bill_Gibson
Contributor III

Day 1 of enabling this service:
No issues limiting access to US based connections with "Block users from accessing Google desktop and mobile apps if access levels aren’t met" for all named apps.

Immediate issues from "Block other apps from accessing the selected apps via APIs, if access levels aren’t met". Connections we saw in the log were coming from the web front end of US registered IP addresses when attempting to login to 3rd party apps such as our cloud based web filter vendor. Left this disabled for now.

 

Screenshot 2023-10-02 at 8.56.28 PM.png

sujka
New Contributor III

Hey, 

Thanks for following up on the post. I am very interested to know/see how it goes because I want to reenable mine. Maybe I ask where geographically you are in the USA? just state/region, don't have to be specific.

Mike