Jump to content

Recommended Posts

Posted

Hi!

I had realized that the setup that I had inherited and running for too long for our Smoothwall had holes in and the students gave me much information on where they were and closed them

In the organized chaos I allowed access to 17.0.0.0/8 all (Apple IPs )

Is there any real issue in allowing access to all Apple IPs for students on the Firewall? Or am I missing something

Many Thanks

Darren

Posted (edited)

Honest to god, when I started editing that post, @DGardiner hadn't submitted his post yet.

 

Anyway, reading that, it says that iCloud Private Relay uses QUIC. When I was working in schools, I was blocking QUIC because otherwise SSL inspection didn't work on Google, so possibly blocking QUIC will kill that too.

 

/edit Dang it, ninja'd twice in like ten minutes. I'm going to stop now.

Edited by Norphy
  • Thanks 2
Posted
Those are egress ranges, i.e. the IP address the relay uses to send traffic out from. You'd need to block their ingress ranges.
  • Thanks 1
Posted
We would typically URL block their relay FQDNs and deny TCP/UDP 80+443 to them at the firewall too. Then 17.0.0.0/8 is allowed undecrypted but firewalled to their service ports only.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...