dazza007 Posted May 27, 2022 Posted May 27, 2022 Hi! I had realized that the setup that I had inherited and running for too long for our Smoothwall had holes in and the students gave me much information on where they were and closed them In the organized chaos I allowed access to 17.0.0.0/8 all (Apple IPs ) Is there any real issue in allowing access to all Apple IPs for students on the Firewall? Or am I missing something Many Thanks Darren
Norphy Posted May 27, 2022 Posted May 27, 2022 (edited) I don't know what IP address range the iCloud private relay service sits on. If students can get onto that from a BYOD/guest device, they'll be able to bypass all of your browsing policies. /edit this might be useful: https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay/ Edited May 27, 2022 by Norphy 1
DGardiner Posted May 27, 2022 Posted May 27, 2022 https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay/ some info there thats probably of use 1
dazza007 Posted May 27, 2022 Author Posted May 27, 2022 Good point - I blocked QUIC which their service uses for Relay intheory this should stop it dead, might have to test it out!
Norphy Posted May 27, 2022 Posted May 27, 2022 (edited) Honest to god, when I started editing that post, @DGardiner hadn't submitted his post yet. Anyway, reading that, it says that iCloud Private Relay uses QUIC. When I was working in schools, I was blocking QUIC because otherwise SSL inspection didn't work on Google, so possibly blocking QUIC will kill that too. /edit Dang it, ninja'd twice in like ten minutes. I'm going to stop now. Edited May 27, 2022 by Norphy 2
dazza007 Posted May 27, 2022 Author Posted May 27, 2022 Thank you! I guess if I block these I should be doubly ok! https://mask-api.icloud.com/egress-ip-ranges.csv
Norphy Posted May 27, 2022 Posted May 27, 2022 Those are egress ranges, i.e. the IP address the relay uses to send traffic out from. You'd need to block their ingress ranges. 1
PaddyNewman Posted May 27, 2022 Posted May 27, 2022 We would typically URL block their relay FQDNs and deny TCP/UDP 80+443 to them at the firewall too. Then 17.0.0.0/8 is allowed undecrypted but firewalled to their service ports only.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now