Skip to main content
Question

APN issue

  • May 10, 2013
  • 4 replies
  • 17 views

Forum|alt.badge.img+8

Currently, we are able to create configuration profiles and have them pushed to computers outside of the network but not to computers that are on our internal network. I assume that this means that we have an issue with APNs connecting to our internal computers. Anyone know what we would need to unblock on our firewall for this to work?

4 replies

Forum|alt.badge.img+11
  • Contributor
  • May 10, 2013

I think you need to allow the APN ports through your firewall to your clients


Forum|alt.badge.img+8
  • Author
  • Contributor
  • May 10, 2013

I do currently allow all traffic to all internal clients from any external address from TCP ports 5223, 2195 and 2196 for testing purposes, so it should work as long as those are the ports used.


Forum|alt.badge.img+21
  • Employee
  • May 10, 2013

Every client needs to be able to reach the JSS over 8443. They also need to be able to reach Apple (17.0.0.0/8) over 5223. The JSS needs to be able to reach Apple over 2195 and 2196.

With push notifications, clients have to make an outbound connection which then persists and data from Apple comes back down the open pipe. It's possible that your corporate firewall allows outbound traffic, but blocks what is called established traffic. Both need to work for push notifications.


Forum|alt.badge.img+15
  • Valued Contributor
  • May 10, 2013

Unable to use Apple Push Notification service (APNs)
http://support.apple.com/kb/TS4264

This is a great tool for trouble shooting APNS from the server.
http://twocanoes.com/push-diagnostics/