Jump to content

Recommended Posts

Posted

Hey Guys

 

So all my iPads here are supervised now with the latest iOS on them. They are all linked to Meraki and since Meraki now claims you can redeem VPP codes and transfer them to different clients depending on the tag they are assigned to I thought I'd give it a shot!

 

The issue here is that county no longer will be doing our internet filtering and we control all our filters through Smoothwall, since Apple no longer supports NTLM authentication I have had to create an SSL page where students and staff can log into and out and then time them out after no activity around 15 minutes long. This has worked well although this also means that:

 

1. I can't get rid of the SSL page as I have to make damn well sure we are monitoring what 365safe says we should.

2. If an iPads app is 2GB big it takes longer than 15 minutes to download and stops half way and then just gives up.

3. If the iPads aren't active (disconnected from the internet due to our SSL page as no one is logged in) how can I tell Meraki to sync next time they are active on the internet so Meraki can constantly update them?

 

Cheers guys :)

Posted
Welcome to the nightmare that is Apple and education. We use Meraki and Smoothwall together and the best way was to setup all the iPads to ident by location rather than get indivduals to logon via SSL or NTLM.
Posted
But then how do you know that little timmy has been looking at naughty images all day and it wasn't jenny who were at the exact same location?! I know Apple is a nightmare check the I hate VPP post on behind the red door I have linked an email from Apple that's quite intresting! So how do you push paid apps out to them if you have an SSL page anyone??
Welcome to the nightmare that is Apple and education. We use Meraki and Smoothwall together and the best way was to setup all the iPads to ident by location rather than get indivduals to logon via SSL or NTLM.
Posted

The teachers here are required to sign in and out the iPads and write an individuals name to check for any damage etc so it is up to them to put Timmy's name next to which iPad he took and that way we can say well it wasn't Jenny that went on the norty website.

 

Not ideal I know but then nor are the iPad's as they are finding out. Question I got yesterday is in Popplet and Pixntell both apps that don't support the Open In button to save to SkyDrive how do we save to Skydrive? I was like I'm sorry but you don't its up to the App to support that button. I agree VPP is a nightmare too but that's a whole other story.

Posted
Can you setup a location group in Smoothwall, that is unauthenticated, if something naughty is went on, you can ask the teacher etc who it was - And hopefully, if they tried to go on something naughty, it would be blocked.
Posted
Or another way which would achieve what you want but keep the SSL login is to add all of the Apple URL's and IP's, as well as Meraki's (which I'm sure you can find with a bit of Googling) to the proxy exception list in Smoothwall so that all Apple traffic including updates won't require authentication and should just go through ok.
  • Thanks 1
Posted
Ah cheers mate! This would be great have you got any idea how to do this or is this contact Smoothwall time :)?
Or another way which would achieve what you want but keep the SSL login is to add all of the Apple URL's and IP's, as well as Meraki's (which I'm sure you can find with a bit of Googling) to the proxy exception list in Smoothwall so that all Apple traffic including updates won't require authentication and should just go through ok.
Posted
Ah cheers mate! This would be great have you got any idea how to do this or is this contact Smoothwall time :)?

 

I would do roughly the following. Login to Smoothwall go to Guardian, Policy Objects, User Defined. Go to Manage category content create a new one called Apple Updates. Add the appropriate URLs and IP's of all of the Apple Stuff apple.com, meraki.com, meraki.cisco.com, ios.meraki.com would be a good start but get a new up-to-date list from their websites and then save this list.

 

Then go to Web Proxy, Exceptions and then find this list in the category groups and add it to the exceptions. This way anything in that list would bypass the SSL login and go straight through to the internet. If you have any issues you can check the smoothwall logs for any addresses not caught in the list and add them where appropriate.

  • Thanks 1
Posted

Taken from the user guide. Not sure if this is complete but may help you.

 

Systems Manager

 

Clients using Meraki Systems Manager initiate outbound management connections to the Meraki cloud using the following addresses and ports:

 

Mac/Windows

 

46.165.246.229, 74.50.56.176, *.amazon.com - TCP ports 80, 443, 993, 60000-61000

 

iOS

 

46.165.246.229, 74.50.56.176, 50.18.152.159 - TCP port 443

* - TCP ports 2195, 2196, 5223

 

Android

 

46.165.246.229, 74.50.56.176 - TCP port 443

* - TCP port 5228

Posted

Guardian > User defined > Custom allowed content > Add in the above URLs?

 

You also require APNS open.

 

push.gateway.apple.com and also the entire 17.0.0.0/16 subnet, which is reserved to Apple.

 

(Ports 2195, 2196 for Feedback)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...