Threat Mitigation
A VPN (Virtual Private Network) routes your internet traffic through a remote server, which make it appear that your traffic is coming from a different IP address.
To mitigate some of threats in the cybersecurity landscape, SNC disallows authentication of Okta and anything that uses Okta for login while using a VPN service.
Common consumer VPN services include:
- NordVPN
- Surfshark
- Proton VPN
- ExpressVPN
IP addresses are loosely associated with locations, and are directly associated with things like Internet Service Provider. Check yours out with a tool like this: https://www.ip2location.com/
Due to the nature of these VPN services, account and credential thieves use them when attacking victims. For example, if an organization detects repeated login attempts from a suspicious IP address, it can block that IP. It's much more challenging to block traffic from every IP address an attacker could have access to, if they use an VPN service. If an IP address is blocked, the attacker will simply switch to a different IP address they have access to with their VPN software (this will often be an IP address in a different geographical location as well).
Blocking Okta authentication from VPN connections helps reduce this type of activity and provides an additional layer of protection for SNC accounts.
FAQs
Q: I'd still like to be able to use the VPN service on my device. Can I do that?
A: Yes. We do not prohibit the use of VPN services on the SNC network. However, you will need to disconnect from your VPN before logging in to Okta or any application that uses Okta for authentication. Once you have successfully logged in, you may reconnect to your VPN.
Q: Will this affect the college provided VPN (FortiClient)?
A: No. You will still be able to use our VPN services as normal whether you are on-campus or off-campus.
Q: Will this affect iCloud Private Relay?
A: No. iCloud Private Relay is not affected by this change and will continue to work normally.