GlennJames Posted October 25, 2021 Posted October 25, 2021 Hi, We recently bought 32 iPads and a M1 Mac Mini to act a a caching server for iOS and app updates. Our ISP is Exa Networks and we use the SurfProtect 'Quantum' filtering platform, having moved from their 'Fusion' platform a few months back. When we had Fusion in place, I used a Mac Book as a caching server and it worked great but since we've moved to Quantum, I just can't seem to get the new Mac Mini to cache anything. Quantum uses a proxy server for filtered traffic from domain joined Windows devices, but the iPads and Mac Mini do not use the proxy settings so use the default transparent proxy instead. The schools devices appear externally as several different public IP addresses within a range. I have tried all sorts of combinations of settings on the caching server option screen but just can't get this to work. The Mac Mini and iPads all work as expected when I connect them at home using the default options so I know it should work and it used to work before we moved to Quantum. I was just wondering (hoping) that somebody else here might have come across this issue before and could give me a few pointers of things to check? Thanks in advance. Glenn
k-strider Posted October 25, 2021 Posted October 25, 2021 ours works we had to add these three ranges in here... above out of shot is our raneg of ips from EXA
GlennJames Posted October 25, 2021 Author Posted October 25, 2021 Thanks for that k-strider. I did try to add some I ranges but I can't remember off the top of my head what they were. I'm back at the school on Wednesday so I'll check them then. Did you have to add the DNS entries as advised on under the DNS configration section? I figured out the correct syntax to add the entry with the ranges I entered on my DNS server, but it didn't make any difference. Do you have the DNS entries in place on your setup?
k-strider Posted October 26, 2021 Posted October 26, 2021 yes under _tcp in our domain this: Record Name: _aaplcache FQDN: _aaplcache._tcp.myinternaldomain.lan Text: prs=82.219.17.1-82.219.17.254,82.219.X.X-82.219.X.X,82.219.7.1-82.219.7.254,82.219.10.1-82.219.10.254 the X.X is our public ip addresses not that i think any of our kit ever present themselves with these as they all go trough surf protect.
GlennJames Posted October 26, 2021 Author Posted October 26, 2021 That's great - many thanks. I'm back at the school tomorrow so I'll have another crack at it and hopefully I can get it working this time.
GlennJames Posted October 29, 2021 Author Posted October 29, 2021 Well, I've checked all the settings, added the correct IP ranges, DNS settings etc., and content caching still isn't working. I've tried just about every combination of settings on the Mac but nothing seems get things moving. The only time I've had this working is when I took the Mac Mini home and it cached without any problems! I've got two others schools with Mac Mini's used for content caching and they just work - the big difference is that they have different ISP's. I'm pulling my hair out with this. Does anybody have any other suggestions? Failing that, does anyone have a direct contact for Apple education support? I tried the standard helpline but they couldn't really help with this.
subhi Posted November 22, 2021 Posted November 22, 2021 Do you have the right ports open? Does exa intercept apple traffic? See https://support.apple.com/en-gb/HT210060 and you can test your network using JET https://github.com/jamf/Jamf-Environment-Test 1
GlennJames Posted November 22, 2021 Author Posted November 22, 2021 Thanks for the tips. I've ran the Jamf tester on the Mac Mini and passed the results and the Apple KB article back to Exa. The Jamf tester gave a few SSL certificate errors for a handful of Apple URLs so hopefully Exa can bypass these and we might finally get somewhere!
GlennJames Posted March 31, 2022 Author Posted March 31, 2022 I just thought I'd update this thread I've finally reached the conclusion. Here's the content caching best practices from Apple article https://support.apple.com/en-gb/guide/mac-help/mchl9388ba1b/mac : - Content caching best practices The following are best practices for content caching. Whenever possible, you should follow these recommendations: Allow all Apple push notifications. Don’t use manual proxy settings. Don’t proxy client requests to content caches. Bypass proxy authentication for content caches. Specify a TCP port for caching. (See Port key in Configure advanced content caching settings.) Manage inter-site caching traffic. Block rogue cache registration. Use a static public IP address for content caches. Here's the response from Exa: - I can already see the issue see below: "Don’t proxy client requests to content caches." "Use a static public IP address for content caches." We are unable to send traffic without it coming from a proxy as this is how the filtering works, it makes sense why it worked on Fusion but now does not on Quantum as Fusion did not use a proxy service. the static IPs are also not possible as we use a load balance of IPs as you are on a proxy service, unfortunately, we are not going to be able to fix this due to Apple not accepting dynamic ips and proxy connections. So basically don't buy a Mac Mini and expect to use it for content caching if your ISP is Exa and you are on their Quantum platform.
mavhc Posted March 31, 2022 Posted March 31, 2022 So the problem is the iPads need to appear on the same external IP as the Mac otherwise they don't know to use it for caching, you can't tell the ipads to use this local IP anyway?
Brimstone Posted March 31, 2022 Posted March 31, 2022 I just thought I'd update this thread I've finally reached the conclusion. Here's the content caching best practices from Apple article https://support.apple.com/en-gb/guide/mac-help/mchl9388ba1b/mac : - Content caching best practices The following are best practices for content caching. Whenever possible, you should follow these recommendations: Allow all Apple push notifications. Don’t use manual proxy settings. Don’t proxy client requests to content caches. Bypass proxy authentication for content caches. Specify a TCP port for caching. (See Port key in Configure advanced content caching settings.) Manage inter-site caching traffic. Block rogue cache registration. Use a static public IP address for content caches. Here's the response from Exa: - I can already see the issue see below: "Don’t proxy client requests to content caches." "Use a static public IP address for content caches." We are unable to send traffic without it coming from a proxy as this is how the filtering works, it makes sense why it worked on Fusion but now does not on Quantum as Fusion did not use a proxy service. the static IPs are also not possible as we use a load balance of IPs as you are on a proxy service, unfortunately, we are not going to be able to fix this due to Apple not accepting dynamic ips and proxy connections. So basically don't buy a Mac Mini and expect to use it for content caching if your ISP is Exa and you are on their Quantum platform. You do not need a static public I.P. address any longer to use content caching, you might have to work with your DNS provider (Exa) in order to add the TXT records, see below... https://support.apple.com/en-gb/guide/mac-help/mchld4ab5cdc/mac
GlennJames Posted March 31, 2022 Author Posted March 31, 2022 (edited) The best solution I can come up with is to admit defeat, give up and move on to the next problem. Edited March 31, 2022 by GlennJames
mavhc Posted April 1, 2022 Posted April 1, 2022 Have you excluded apple's domains from https interception in Surfprotect?
Michael Posted April 1, 2022 Posted April 1, 2022 In my experience, if you're fortunate enough to have a decent internet connection (minimum 100Mb lease line), a caching server makes little difference. If anything WUfB is far more efficient than WSUS as a comparison.
RLR Posted April 1, 2022 Posted April 1, 2022 In my experience, if you're fortunate enough to have a decent internet connection (minimum 100Mb lease line), a caching server makes little difference. If anything WUfB is far more efficient than WSUS as a comparison. This will depend on the number of Apple devices. I think 32 devices is probably okay to not have a caching server but once you start getting any more devices then a caching server can really help. Our caching server has served 420GB of data in the last 7 days for one of our sites. Another site that uses shared iPads has served 825GB in the last 30 days.
mavhc Posted April 4, 2022 Posted April 4, 2022 Does depend if they're smart enough to download updates at night, 420GB on a 100Mb line is 9 hours
Tefters Posted May 27, 2022 Posted May 27, 2022 What size SSD are you using in your caching servers? I'm about to buy a mac mini M1 for a caching server that will initially serve 500 iPads and eventually reach 1200. I know the cache recycles off old apps/updates automatically so 500GB sufficient?
GlennJames Posted June 29, 2022 Author Posted June 29, 2022 I've got the M1 model with a 256GB but it doesn't cache so can't really advise! Before we moved to Exa Quantum, we used to use a MacBook Pro with a 128GB SSD in for caching when I was refreshing the iPads over the summer break. Approx 100-ish devices, with maybe 20 apps installed and the cache set to 40GB and I didn't run into any problems. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now