Jump to content

Recommended Posts

Posted

Hi,

 

I've got an issue with iMessages and cyber bullying on ipads. I want to be able to block access to imessages on BYOD. I can't use an MDM to block them as they are BYOD devices. I have managed to block access to all the other messaging services snapchat, whatsapp, facebook messenger etc.

 

Ive done some research and ive come across some information that suggests if you close port 5223 but this hasn't made any difference.

 

Ive watch the real time traffic on the smoothwall UTM1000 and there isn't an entry for the devices when a message is sent or received.

 

Anyone got any ideas? Google has let me down on this one :(

 

Roll on next March when i can upgrade to a layer 7 firewall/filter..

Posted
We have only a handful of ports open and it works on our BYOD. I should imagine it goes down 443. If you don't do SSL inspection it might start getting tricky.
Posted

We do Ssl decrypt and inspect on byod so that part isn't a problem.

 

I sit with a device with the ip in the smoothwall realtime webfilter and no other filters set sending imessages and there isn't a single entry appearing. How can this be? I know it's the right device as I can see corresponding safari based browsing on the filter.

 

I've tried adding rules to block push.Apple.com as some people suggests that is the origin of the messages but still works.

 

The critical thing is that I can't afford to ruin access to iTunes and app store trying to block this.

Posted
It isn't sending the message via 3G is it because the WIFI is blocking it? My Windows phone does that, block a port on the firewall and it sends it via the mobile data connection instead!
Posted (edited)

Ive just looked at the firewall logs and it seems that there is regular traffic on port 5223 which is listed as a iMessage port on the apple website. Ive tried adding an outgoing port rule to block this specific port and traffic is still going through. Do smoothwall need a reboot to pick up firewall rule changes?

 

EDIT: Apparently we do. Its now blocking port 5223.......RIP iMessages.....I WON

Edited by stgoodyeara
Posted
A little bit premature with my victory dance, port 5223 is also the port devices use to communicate with the MDM. so in killing iMessages i've also killed my MDM. :( any other suggestions greatly accepted...
Posted

Its going to have to be something along these lines, the problem is that i am trying to do this deployment on a shoe string so opted for the free version of meraki as the MDM which doesn't have the time based policies for iMessages so even if i fix the BYOD area ive still got the issues on the supervised devices.

 

I had notification from our LA that our smoothwall is being changed in late october, hopefully the application aware part of the smoothwall will be able to boot out iMessages without killing the MDM. We shall see,

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...