We have a clustered setup with a JSS in the DMZ (no Distibution Point) set to Mobile Device Access Only in Limited Access.
If we try to register a new DEP-enabled device when on cellular network, it fails during the profile installation because of a network error.
It works fine when on our local WiFi, but it would be nice if users could activate when they are elsewhere.
Ports 636 and 3306 are open in to our local network, and port 8443 can be accessed externally.
Am I missing something?