Praxis Posted June 7, 2019 Posted June 7, 2019 Hi, I am trying to open the required ports for Mosyle to function correctly. These are: TCP 5223 TCP 2195 TCP 2196 TCP 443 UDP 16386 We are using Smoothwall and have a DrayTek Vigor 2860 router. I have opened these ports in Smoothwall by creating a firewall rule, but when I test them, the ports are still blocked. I am assuming this is the router causing this. When I go to open ports on the router it is asking for a private IP, I am unsure what to input into this box as it's not just one device I want to open the ports for? We have around 45 iPads that need managing via Mosyle.
ibpalle Posted June 7, 2019 Posted June 7, 2019 (edited) If the Smoothwall is behind another NAT device like the draytek, the private IP you need will be the external IP configured on the Smoothwall. Basically your network is in NAT behind the Smoothwall. The Smoothwall is in NAT behind the draytek. Smoothwall port forwards to your Mosyle IP. Draytek port forwards to Smoothwall. EDIT: Disregard all I just said. While correct, it's not relevant. You are wanting outgoing traffic to be allowed. The router should not block anything outgoing. Please contact support as there are a few additional questions that needs resolving before we can answer adequately. Edited June 7, 2019 by ibpalle
Brimstone Posted June 7, 2019 Posted June 7, 2019 You will need to ensure your network can access Apple APNS Servers as well.. https://support.apple.com/en-gb/HT203609 1
CCCSecMan Posted June 10, 2019 Posted June 10, 2019 Praxis - that screen on the draytek is port forwarding inbound, if I am not mistaken. You need to be concerned about Outbound, which by default on a Draytek is fully allowed, however you should double check. If you have a smoothwall UTM you would be best configuring the Draytek to pass all traffic to the smoothwall, rather than having the Draytek doing NAT etc - best to let smoothwall handle it all. If you are not familiar it would be worthwhile engaging Draytek and smoothwall support to get it configured properly. 1
Praxis Posted June 10, 2019 Author Posted June 10, 2019 Thanks for the suggestions everyone. I'll try and get it sorted this afternoon
uke Posted July 23, 2019 Posted July 23, 2019 Did you get this sorted? I use smoothwall and have been trying mosyle and have noticed that it works find in ISO 10 but does not want to work in IOS 12. I think its got something to do with the smoothwall certificate but am unsure.
DGardiner Posted July 23, 2019 Posted July 23, 2019 Did you get this sorted? I use smoothwall and have been trying mosyle and have noticed that it works find in ISO 10 but does not want to work in IOS 12. I think its got something to do with the smoothwall certificate but am unsure. if the devices arent supervised the certificates have to be manually trusted again if i remember right 1
rckngslnd Posted May 5, 2021 Posted May 5, 2021 Hi, does anyone have complete list of ports and sites etc that need to be unblocked for Mosyle
ITGuyNW Posted December 3, 2024 Posted December 3, 2024 Bringing up an old thread.... I have shared ipads (pick up and go) where students login via the SSL page. Once thats logged in, apps etc all download fine but without that, the mosyle app is blocked. What do I need to unblock to allow the Mosyle app to work without having to be logged in via the SSL page ? These used to be on Meraki and that worked fine.
Olliedawg Posted December 3, 2024 Posted December 3, 2024 I put a firewall rule in above our captive portal rule, which allows the traffic to all required Mosyle domains/IP's before they sign in. Otherwise we have the same problem you face
Davit2005 Posted December 3, 2024 Posted December 3, 2024 (edited) Praxis - that screen on the draytek is port forwarding inbound, if I am not mistaken. You need to be concerned about Outbound, which by default on a Draytek is fully allowed, however you should double check. If you have a smoothwall UTM you would be best configuring the Draytek to pass all traffic to the smoothwall, rather than having the Draytek doing NAT etc - best to let smoothwall handle it all. If you are not familiar it would be worthwhile engaging Draytek and smoothwall support to get it configured properly. 100% On the draytek you should be able to pass the public IP address or even subnet through to Internal devices. I have that setup at home, DrayTek passes the public subnet I have with my ISP to the FW and the FW deals with the NAT and so you are not double NAT'ing. The days of me opening any ports are numbered as I use a lot of Cloudflare Zero trust now and that deals with MFA :-) Docker CloudFlare container in DMZ, docker container has additional internal network on the docker host that talks to the service that I host. Edited December 3, 2024 by Davit2005
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now