Skip to main content
Question

JSS Firewall Policies Setting for APNs.

  • December 3, 2021
  • 2 replies
  • 13 views

Forum|alt.badge.img+2

Hi,

A customer will set up their two JSS servers from internal network to DMZ, they will also have a load balancer (F5) before two JSS Servers in DMZ, so the Infosec team asks the following question:

Could they only open the network access policies between the F5 and APNs except the network access polices between JSS Servers and APNs?

Any feedback will be appreciated.

Nan

2 replies

Steven_Xu
Forum|alt.badge.img+7
  • Contributor
  • December 3, 2021

Load balancer is for the connections initiated by remote clients, the APNs traffic is initiated by Jamf Pro Servers. For the Firewall, if the APNs traffic's initiation source IP is JSS server's local IP, then they should open network access for JSS servers. 


Forum|alt.badge.img+2
  • Author
  • New Contributor
  • December 3, 2021

Load balancer is for the connections initiated by remote clients, the APNs traffic is initiated by Jamf Pro Servers. For the Firewall, if the APNs traffic's initiation source IP is JSS server's local IP, then they should open network access for JSS servers. 


Thanks Steven.