TOLOGIX - ISLG App Rebuild

URGENT - Problem with IP Access

Assigned to
Harsh Parikh, Tech Lead at DevIT Harsh P. Martin Laporte, CTO at Tologix Martin L.
Notes
Further to the video below, there is currently a problem with the Freshfields Bruckhaus Deringer LLP group account on ISLG. It is currently registering a high number of sessions from IP addresses outside the ranges specified in the account. These IP ranges were updated my Marysia Raptis Marysia   last week, but I cannot identify any clerical errors in the ranges that would be causing this issue. Please resolve the following:
  1. Ensure access is only getting granted to the authorized IP address ranges for the group.
  2. Reassign any recorded sessions outside the authorized IP address ranges to other applicable group accounts (i.e., determine if these IP address that is associated with a session falls within the ranges of other group accounts and reassign the applicable sessions to those group accounts - sessions that do not fall within an applicable range can be discarded).
Please resolve ASAP. We are currently in renewal discussions with the client, and I do not want this to be something that jeopardizes the renewal.

Thanks,

Morgan


Comments & Events

Harsh Parikh, Tech Lead at DevIT
Hi Morgan Maguire, CEO Morgan and Marysia Raptis Marysia ,

We checked the IP ranges for Freshfields Bruckhaus Deringer LLP group and found that as per following screen shot due to red mark ipv4 range this issue is occurred.

The range is start with 54.14.114.168 and end with 154.14.114.175. I assume this is typo mistake for ip 154.14.114.175.  The start IP range should start with 154 digit or End IP range should start with 54 digit


Please check and confirm.
Morgan Maguire, CEO
Hi Harsh Parikh, Tech Lead at DevIT Harsh ​,

Great. Thanks for catching that. Marysia Raptis Marysia ​, I have turned off that IP address range. Could you please confirm what the correct range should be?

Martin Laporte, CTO at Tologix Martin ​, can we do something about the usage data? I really don't want this to show up in the client's usage reports.

Thanks,

Morgan
Martin Laporte, CTO at Tologix
Morgan Maguire, CEO Morgan and Marysia Raptis Marysia : I am pretty sure that the correct IP begins with 154.*, because 154.* IP addresses originate from the U.K, whereas 54.* IP addresses are US-based.

Is it ok if we remove all usage data entries for that group from 6/23 until now? This would be the easiest way.

Thanks,
--Martin
Morgan Maguire, CEO
Hi Martin Laporte, CTO at Tologix Martin ,

Ok. It may very well be a US-based IP, because Freshfields has several offices in the US, so I'll wait for Marysia Raptis Marysia to confirm the correct range.

I'd prefer a more precise correction of the data. This is a high volume account and there was probably legitimate usage that occurred during this period. Once Marysia Raptis Marysia confirms the correct range, could we please remove only the sessions that do not fall within an authorized range?

Thanks,

Morgan
Marysia Raptis
HI Morgan and Martin,

I confirm the range is 154.14.114.168 - 154.14.114.175

Marysia
Marysia Raptis
Also, have made the correction on their account.

Marysia
Morgan Maguire, CEO
Great. Thanks Marysia Raptis Marysia . Could you confirm exactly when the IP addresses were updated so that Martin Laporte, CTO at Tologix Martin can isolate what sessions data needs to be corrected.

Thanks,

Morgan
Marysia Raptis
June 23
Morgan Maguire, CEO
Ok. Thanks Marysia Raptis Marysia .

Martin Laporte, CTO at Tologix Martin , could you please determine whether it's possible to cleanse session data between June 23 and June 30 of sessions where access came from IP address outside the authorized IP ranges. 

Thanks,

Morgan
Marysia Raptis
Actually looks like I would have updated on 22 June and confirmed on 23rd.

Marysia
Martin Laporte, CTO at Tologix
Morgan Maguire, CEO Morgan , I will work on isolating the erroneous sessions today, but will wait tonight for Harsh Parikh, Tech Lead at DevIT Harsh before removing them since I want to make sure they are properly removed.
Morgan Maguire, CEO
Ok. Sounds good. Thanks Martin Laporte, CTO at Tologix Martin ​.

Note this can wait until Monday. I don't want to unduly interrupt your long weekend.

Morgan
Martin Laporte, CTO at Tologix
Hi Harsh Parikh, Tech Lead at DevIT Harsh ,

See attached spreadsheet for the list of erroneous sessions that should be deleted.

What I did to get there:
  1. Collect list of IP ranges belonging to client (using SelectGroupIPRangesByGroupID stored proc)
  2. Collect list of sessions linked to client (using SelectSessionDetailsForExport stored proc)
  3. Brought the data into a spreadsheet and created a simple formula to validate each session from 6/22 until now.
Take a look at the "Sessions" tab, column R. The goal would be to remove any "FALSE" entries from the database.

Hopefully this spreadsheet will help you achieve that.

Thanks,
--Martin
Harsh Parikh, Tech Lead at DevIT
Hi Martin Laporte, CTO at Tologix Martin ,

As per your attached sheet, We have removed false session data entries from Freshfields Bruckhaus Deringer LLP ' s group. 

Please check and confirm.
Martin Laporte, CTO at Tologix
Hi Harsh Parikh, Tech Lead at DevIT Harsh ,

I believe we are looking good now, as their June sessions count are back within normal ranges:

Morgan Maguire, CEO Morgan : do you agree?

Thanks,
--Martin
Morgan Maguire, CEO
Look good, Martin Laporte, CTO at Tologix Martin and Harsh Parikh, Tech Lead at DevIT Harsh . Thank you. Marking to-do complete.

Morgan
Morgan Maguire, CEO
Morgan Maguire completed this to-do.