Jump to content

Recommended Posts

Posted

Hi, I am trying to open the required ports for Mosyle to function correctly. These are:

 

TCP 5223

TCP 2195

TCP 2196

TCP 443

UDP 16386

 

We are using Smoothwall and have a DrayTek Vigor 2860 router. I have opened these ports in Smoothwall by creating a firewall rule, but when I test them, the ports are still blocked. I am assuming this is the router causing this. When I go to open ports on the router it is asking for a private IP, I am unsure what to input into this box as it's not just one device I want to open the ports for?

 

We have around 45 iPads that need managing via Mosyle.

 

Screenshot 2019-06-07 at 14.22.14.png

Posted (edited)

If the Smoothwall is behind another NAT device like the draytek, the private IP you need will be the external IP configured on the Smoothwall.

 

Basically your network is in NAT behind the Smoothwall. The Smoothwall is in NAT behind the draytek.

 

Smoothwall port forwards to your Mosyle IP. Draytek port forwards to Smoothwall.

 

EDIT: Disregard all I just said. While correct, it's not relevant.

 

You are wanting outgoing traffic to be allowed. The router should not block anything outgoing. Please contact support as there are a few additional questions that needs resolving before we can answer adequately.

Edited by ibpalle
Posted

Praxis - that screen on the draytek is port forwarding inbound, if I am not mistaken.

 

You need to be concerned about Outbound, which by default on a Draytek is fully allowed, however you should double check.

 

If you have a smoothwall UTM you would be best configuring the Draytek to pass all traffic to the smoothwall, rather than having the Draytek doing NAT etc - best to let smoothwall handle it all. If you are not familiar it would be worthwhile engaging Draytek and smoothwall support to get it configured properly.

  • Thanks 1
  • 1 month later...
Posted
Did you get this sorted? I use smoothwall and have been trying mosyle and have noticed that it works find in ISO 10 but does not want to work in IOS 12. I think its got something to do with the smoothwall certificate but am unsure.
Posted
Did you get this sorted? I use smoothwall and have been trying mosyle and have noticed that it works find in ISO 10 but does not want to work in IOS 12. I think its got something to do with the smoothwall certificate but am unsure.

 

if the devices arent supervised the certificates have to be manually trusted again if i remember right

  • Thanks 1
  • 1 year later...
  • 3 years later...
Posted

Bringing up an old thread....

 

I have shared ipads (pick up and go) where students login via the SSL page. Once thats logged in, apps etc all download fine but without that, the mosyle app is blocked. What do I need to unblock to allow the Mosyle app to work without having to be logged in via the SSL page ? These used to be on Meraki and that worked fine.

Posted

I put a firewall rule in above our captive portal rule, which allows the traffic to all required Mosyle domains/IP's before they sign in.

 

Otherwise we have the same problem you face

Posted (edited)
Praxis - that screen on the draytek is port forwarding inbound, if I am not mistaken.

 

You need to be concerned about Outbound, which by default on a Draytek is fully allowed, however you should double check.

 

If you have a smoothwall UTM you would be best configuring the Draytek to pass all traffic to the smoothwall, rather than having the Draytek doing NAT etc - best to let smoothwall handle it all. If you are not familiar it would be worthwhile engaging Draytek and smoothwall support to get it configured properly.

 

100% On the draytek you should be able to pass the public IP address or even subnet through to Internal devices. I have that setup at home, DrayTek passes the public subnet I have with my ISP to the FW and the FW deals with the NAT and so you are not double NAT'ing.

 

The days of me opening any ports are numbered as I use a lot of Cloudflare Zero trust now and that deals with MFA :-) Docker CloudFlare container in DMZ, docker container has additional internal network on the docker host that talks to the service that I host.

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...