Exclusions needed to allow systems to download updates without proxy auth

I'm having issues with updates downloading and applying automatically, or even accessing the app store, when systems are connected to my internal network. This occurs when the customer is not on the domain or has not authenticated to the proxy. I was possible going to have an exclusion added just wanted to ensure that the only site needed should be itunes.apple.com. Was there any other sites/Ips/Ports that needed to be allowed?

The official answer from Apple will be to exclude the entire 17.x.x.x network (Apple's Class A address space), but if your security folks are anything like mine, they will laugh in your face for making such a request.