Jump to content

Recommended Posts

Posted

Hi all,

 

We’re currently being plagued by Google’s "unusual traffic" CAPTCHA prompts across our site, and I’m struggling to pinpoint the root cause. As usual, the Google error page is incredibly vague about what triggered it.

 

What I’ve investigated so far:

  • Staff BYOD: Suspected this initially due to high DNS volume and blocked VPN/tunneling attempts. I’ve disabled this network temporarily, but the prompts persist.

  • Managed Mobile BYOD: This is still live as it’s primarily staff mobiles. It has some "noise" (DNS/VPN traffic), but I can’t easily kill it without causing a riot.

  • Traffic Logs: i dont feel like im seeing any massive outbound spikes or bot-like behavior in our logs.

  •  

I’ve checked the Google Admin console and support pages, but there doesn’t seem to be a dedicated channel for reporting or resolving this.

 

Has anyone else dealt with this recently? Any specific pointers on what to look for in the traffic logs, or a way to get google to help out?

 

We are a Google school, and use a Sophos XGS.

 

Cheers!

Posted

Its phones and VPNs, always is. If you have multiple public addresses, put your BYOD on a different public IP to your clean network and let them ruin it for themselves and not the school overall :)

  • Haha 1
Posted (edited)
34 minutes ago, PaddyNewman said:

put your BYOD on a different public IP to your clean network and let them ruin it for themselves and not the school overall :)

 

That's so evil it's genius! i'm sure we do have more than one public IP... no idea how i would implement that on our sophos Gateways. 

Edited by Jaan
Posted

I've just rerouted the BYOD networks from our 1gbp/s internet line to our "cold" back up 200kbp/s line.

 

Let's see how long it take for Google to remove the prompt.

Posted

Long shot but we recently had this with a customer who had extensive chromebook users and it was an issue with their google authentication for login - if your problem persists and you use chrome books can go into more detail for you, cheers

Posted

this is a pretty niche issue i think but>>

Root cause; 

 

"Through the joint investigation we were able to identify an anomaly within our Google configuration linked to pupil accounts that had been set to “change password at next login.” As our pupils authenticate using MyLogin QR codes, this requirement was not visible to the user and therefore was not being surfaced or flagged during the login process. This resulted in repeated authentication attempts from accounts unable to complete the password change requirement, which we believe triggered Google’s automated security and IP reputation controls, leading to the CAPTCHA challenges."

 

 

  • 1 month later...
Posted

This is driving me mad. i also remoted in out of hours with the client pcs off and we still getting it. only things on were Phones and Verkarda CCTV

Posted (edited)
On 19/03/2026 at 10:26, Jaan said:

 

That's so evil it's genius! i'm sure we do have more than one public IP... no idea how i would implement that on our sophos Gateways. 

Normally a different NAT rule using spare public IP for the source ip range/subnet, put it normally above the NAT rule that allows all other default traffic i.e. traffic that the rest of the wider network uses. If rules work top to bottom then it should apply the new NAT rule only to the source ip range/subnet then anything that does not match goes to next rule. Not 100% on Sophos but if rules work top to bottom the first one that matches traffic that rule is used then it should work 🙂

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...