Version Affected: 19.07.01 and later
Overview
After upgrading from an older version of SecureAuth, Adaptive Authentication's Country Restrictions behave differently for internal IP addresses in the Classic Experience.
Cause
Country Restrictions' behavior for IP addresses it can't resolve to a country has changed several times over the years. As of 19.07.x, the Adaptive Auth tab has separate options for how to react when the user's location can't be determined due to a service disruption, and for IPv6 addresses. An internal IP address can never resolve to a country, so it's treated the same as those unresolvable cases by default.
Resolution:
To treat internal users the same as users coming from an allowed country, add a trailing - entry to the realm's allowed-country list:
- Open the Admin Console and navigate to the realm in question.
- Click the Adaptive Auth tab.
- In the Country Restriction section, add , - to the end of the allowed-country list -- for example, if the realm currently allows US, change it to US, -.
- Save.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.