Jump to content

Recommended Posts

Posted

I am in the process of setting up profile manager but I have run in to a couple of issues that I am hoping someone can help me with.

 

The server is configured and profile manager is fully accessible on the network via a web browser using https://servername/profilemanager/ Profile Manager can be opened on the iPads and any Windows machine. The iPads seem to enroll in profile manager, however, they appear only as placeholders and nothing more. I've deployed a proxy pac file with exceptions for the OSX server, but still nothing. The pac file has been tested and works so should hopefully eliminate this.

 

I can enroll our Macbook Pros without issue, but the ipads simply don't want to play. All the usual suspects appear to be working fine - dns, open directory etc. I've also updated the iPads.

 

I wondered if the iPads need a different port opening on the firewall or if anyone could offer any suggestions?

 

Thanks

Posted

Not sure what's happening based on what you've presented? You say the iPads enrol fine but only as placeholders and the MacBooks do the same but not as placeholders. Presumably from there you can 'push/pull' a management profile fine to the MacBooks but not the iPads?

 

"I wonder if the iPads need a different port opening on the firewall . . .?"

 

Perhaps? These are the ports PM needs:

 

https://support.apple.com/en-gb/HT202487

 

Note port 5223. APNs is short for Apple Push Notification. This will be a set of external servers. Apple's APNS is the 'go-between' for your local server and clients, wherever they may be. Basically PM is checked in first with APNS. You should have received an email from Apple notifying you what services have been registered. You should be looking for something that looks like this: apps:apple.com.mgmt. After device enrolment, the devices check with APNS that your server is what it purports to be. Trust is established on enrolment. From there the devices 'accept' the management profile from your local server over-the-air.

 

Things to check will be the usual suspects which you say you've already checked. DNS is absolutely crucial as is the choice of domain name suffix. DNS should properly resolve on forward and reverse pointers and .local should not be used. Of course check your Wi-Fi network is robust enough (no dead-spots wherever possible) and coverage is as good as your institution can afford. I would also make sure there's nothing 'blocking' internal traffic. You never know there may be a legacy network device that hasn't been touched in a while that's interfering in some way?

 

There are many articles available on the web regarding PM and this one from MacWorld is quite thorough and should, hopefully, help?

 

A primer in Profile Manager | Macworld

 

My own preference for managing iDevices (iPads, iPhones, iPods) is to use PM and Apple Configurator combined. PM is OK so far (hopefully it will improve further) and as an MDM is good value for money. Configurator is free. However PM is not the best available IMO. Depending on the numbers involved and what you want to achieve you may want to look at AirWatch, JAMF's Casper Suite and possibly Mobile Iron. There's also a good case to be made for Cisco's System Manager (Meraki).

 

Antonio Rocco (ASP)

Posted

Thanks for this Antonio, I'll certainly check out the links and articles that you have provided. I am also going to have a look at some of the MDMs you've suggested.

 

Yes, we can push/pull management profiles to the Macbooks without problem, but not with the iPads. I'll continue with this on Monday taking in to consideration all you have said and I will report back my findings.

 

Cheers!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...