Posted on
03-12-2019
01:30 PM
- last edited on
03-04-2025
04:24 AM
by
kh-richa_mig
Hi there
At my school we have a wireless network solely of the purposes for new students to use when enrolling their iPads into Jamf. Once enrolled they would get a config profile with settings for another secure SSID their iPads then join.
We had some firewall rules on the enrollment SSID, locking it down so the only destinations accessible was the on-site Jamf server and the apple 17.0.0.0 subnet
This had previously proven effective, users would enroll their iPads successfully without using this network to access the wider internet. However as of late enrollment is failing, and will only work if I remove the firewall rules and allow traffic to anywhere.
Does anyone else out there use a similar method to allow users to enrol?
Thanks
Posted on 03-12-2019 01:32 PM
@OJCJAMF Do you have any logging in the firewall to determine what is being dropped?
Posted on 03-12-2019 02:46 PM
Yeah that is our next step to check, its just a bit of a pain as we (the IT provider) only visit the school once a month and the firewall is managed by a 3rd party!
The ACL's I mentioned are configured on the wireless controller which we have access to.
Posted on 03-12-2019 03:55 PM
There are some non-Apple domains you need to be able to access as well. I'd recommend just using the following list and not doing 17.0.0.0.
Posted on 03-13-2019 11:58 AM
How about using your webfilter to limit web access for that IP block instead of the firewall?
The basic idea would be to filter the open network so heavily that no user would be able to or want to use if for anything other than device registration. Sort of like, it is open, you can get on it but you can't surf anywhere nice.