#Michael Posted May 18, 2015 Share Posted May 18, 2015 I have a very weird question and not sure if anyone here knows it. I am trying to gather the complete list of Apple services domains so they can be whitelisted on our firewall and proxy. So far I have:*.phobos.itunes-apple.com.akadns.net*.gateway.push-apple.com.akadns.net*.ax.itunes.apple.com*.mesu.apple.com*.phobos.apple.com*.albert.gcsis-apple.com.akadns.net*.ax.init.itunes.apple.com*.init.itunes.apple.com*.oscp.apple.com*.deploy.static.akamaitechnologies.com*.itunes.apple.com.edgekey.net*.swcdn.apple.com*.swdownload.apple.com*.swquery.apple.com*.swscan.apple.comThe reason for the wildcard is because they all go through akamai before they get routed over to Apple's IP.Is there any other domains I am missing? Link to comment https://www.neowin.net/forum/topic/1256948-apple-services-domains-that-need-to-be-whitelisted/ Share on other sites More sharing options...
neufuse Veteran Posted May 18, 2015 Veteran Share Posted May 18, 2015 I know there are a few for Apple OS restore... because our Barracuda web filter stops us from doing any restores... it always comes back with a contact apple error if you don't white list the IP of the device... yet it logs nothing as blocked if you look in the logs... if anyone knows what it's blocking there add that to the list too, because I've never figured it out by looking at the logs, only fixed it by IP white list at the Baracudda level during the OS restore... Link to comment https://www.neowin.net/forum/topic/1256948-apple-services-domains-that-need-to-be-whitelisted/#findComment-596854204 Share on other sites More sharing options...
#Michael Posted May 18, 2015 Author Share Posted May 18, 2015 I know that blocking mesu.apple.com will prevent iOS devices from checking for any updates. And blocking albert.apple.com prevents iOS restores from re-activating (??). Link to comment https://www.neowin.net/forum/topic/1256948-apple-services-domains-that-need-to-be-whitelisted/#findComment-596854232 Share on other sites More sharing options...
#Michael Posted May 19, 2015 Author Share Posted May 19, 2015 In case anyone else is interested, after spending some additional time with wireshark, here are a few additional domains I found: *.appldnld.apple.com *.suconfig.apple.com *.serverstatus.apple.com Link to comment https://www.neowin.net/forum/topic/1256948-apple-services-domains-that-need-to-be-whitelisted/#findComment-596855496 Share on other sites More sharing options...
Recommended Posts