book

Required firewall ports and IP Ranges

Firewall ports:

To ensure Xinca can communicate properly with the devices you’re managing, make sure the following ports are allowed in your Firewall.
  • TCP 5223 (APNS)
  • TCP 443 (HTTPS)
If you choose to use LDAP(S) for authentication, make sure the following ports are also allowed.
  • TCP 389 (LDAP)
  • TCP 636 (LDAP over SSL)

Whitelist IP’s:

  • The Apple Push notification servers use load balancing. Your devices will not always connect to the same public IP address for notifications. The entire 17.0.0.0/8 address block is assigned to Apple, so it’s best to allow this range in your firewall settings.
  • The Xinca macOS clients uses an custom push server for delivering commands.
  • Authentication requests to your LDAP server may come from the following IP addresses:
    • 94.130.139.182
    • 94.130.139.190
    • 94.130.139.187
    • 94.130.139.188
    • 212.178.82.42
  • All MDM requests will go through CloudFlare. This is a list of the definitive source of Cloudflare’s current IP ranges:
    • 103.21.244.0/22
    • 103.22.200.0/22
    • 103.31.4.0/22
    • 104.16.0.0/12
    • 108.162.192.0/18
    • 131.0.72.0/22
    • 141.101.64.0/18
    • 162.158.0.0/15
    • 172.64.0.0/13
    • 173.245.48.0/20
    • 188.114.96.0/20
    • 190.93.240.0/20
    • 197.234.240.0/22
    • 198.41.128.0/17
    • 199.27.128.0/21
  • macOS packages
    • 46.4.54.150

Also please make sure you haven’t blocked any of the url's below in your web filter to avoid problems with app installations.

Apple software, such as macOS, iOS, and iTunes, uses different ports and servers to connect to various services. iTunes for Windows also installs some processes that run in the background when the software is open.

The following servers are used by macOS, iOS, and iTunes:

Apple servers Other servers
albert.apple.com evintl-ocsp.verisign.com
ax.itunes.apple.com evsecure-ocsp.verisign.com
deimos3.apple.com *.amazonaws.com
gg*.apple.com *.symcb.com
gs.apple.com *.symcd.com
itunes.apple.com  
*.itunes.apple.com  
mesu.apple.com  
phobos.apple.com  
skl.apple.com  

Click here for more information about Apple's server host connections and iTunes background processes

Click here for a full list of Apple TCP and UDP Ports

Have more questions? Submit a request

0 Comments

Article is closed for comments.