There's a new home for Articles. Find Articles on Our Product Support Page.
Hi all, feels like this question is most probably asked similarly a thousend times, however I did not find an answer for my specific problem. My MobiControl Server is running in the Soti Cloud and my devices should be enrolled in a partially restricted WiFi.This WiFi can access the Soti Server with Port 443 and 5494. Once enrolled this works perfectly.If I try enrolling a new device, it fails during enrollment with "no internet connection", while it actually was able to download the agent => so standard Internet via 443 is possible. Are any other Ports needed during the enrollment process or does the device need to communicate to some other URL during enrollment and with wich Port?
Hi, I came up with problem to enroll our devices on specific WiFi which is secure by FW rules. Basicaly I can say the model of it is everything is closed and what we allow it can be reach. For our Zebra devices we've got enroll from private FTP on site - it's OK Problem occures with non-Zebra devices (tablets) which I want to enroll via QR code. I have to use link to http://soti.net/apk/ae2 If we allowed FQDN it's not enough. After some research we found out that this link redirects to mirrors addresses(servers). Is there any list of approved SOTI sites/IPs which must be allow on FW please? I could find some of them in log but it's always swapping to the new ones. I don't know how big this list can be and finding like that is time consuming. thank you Libor SOTI Mobi version: 15.6.1.1048 device: Lenovo TB-X505F OS: A10 code I'm using in QR: {"android.app.extra.PROVISIONING_DEVICE_ADMIN_SIGNATURE_CHECKSUM":"xxx","android.app.extra.PROVISIONING_DEVICE_ADMIN_COMPONENT_NAME":"net.soti.mobicontrol.androidwork/net.soti.mobicontrol.admin.DeviceAdminAdapter","android.app.extra.PROVISIONING_WIFI_SECURITY_TYPE":"WPA","android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_DOWNLOAD_LOCATION":"http://soti.net/apk/ae2","android.app.extra.PROVISIONING_LOCALE":"cs_CZ","android.app.extra.PROVISIONING_WIFI_SSID":"xxx","android.app.extra.PROVISIONING_LEAVE_ALL_SYSTEM_APPS_ENABLED":true,"android.app.extra.PROVISIONING_WIFI_PASSWORD":"xxx","android.app.extra.PROVISIONING_TIME_ZONE":"Europe/Amsterdam","android.app.extra.PROVISIONING_ADMIN_EXTRAS_BUNDLE":{"enrollmentId":"xxx"}}
Hi We have some devices that are been set in some more restricted enviroment and we are having some issues getting the device connected to server, I'm looking for some more info how this works in practise. MobiControl version: 15.4.3.1012Agent version: 15.1.5.1049 IT has confirmed that Ports are open for (Outbound) as described in MobiControl documents, we have other applications on devices that are currently working and communicating ok. SOTI MobiControl Device Agents Binary/HTTPS 5494, 443 Outbound from the device agents to the deployment server If my understanding is correct this is only needed for communications, is there any answer from server that possible can be blocked after Agent initiates connection?Would there be possible for server respond to be blocked in FW even tho (Outbound) rule is set? Also how much would "Latency" be impacting the Agent connection, how high result would we talk before Agent would see problems whit connections and starting throw "Time-Out" before server could respond? Scenario for these devices might have an high "Latency" as we are currently awaiting answer and testing on this.
I am testing the firewall configuration in the Android Classic Profile, and I am having a problem with the cellular data restriction not applying correctly. I am testing by restricting all network traffic on both WIFI and Cellular for the google Chrome application. I have outlined the process I used below along with screenshots for reference 1. screenshot below displays the rule configuration in MobiControl2. screenshot below shows that the profile was successfully installed to the device 3. screenshot below shows in the Deployment server logs that the Knox Firewall rule is being pushed to the device 4. writeprivatestring_FirewallCommand.png shows the specific MobiControl script commands that are being pushed to the device 5. screenshot below shows the commandin logcat on the android phone the IPTables command being run on the device. 6. logcat_enableFirewallFailed.png - shows the line in logcat on Android where it says "Enable Firewall failed" I have verified that the rules I am using successfully restrict traffic on a WIFI network, but for some reason, they do not work over a cell connection (I am using Verizon Wireless) I have tested on a Samsung J3 and a Samsung S21 using the Samsung ELM agent along with varying OS versions and Samsung Knox versions and I get the same result. Can someone help with figuring out why the firewall rule will not apply over a cellular connection?
Hi All, We have just installed a 2nd deployment server for our externally android devices. I can see that we are connection from the device to the server on 2 different ports. copied from MCSetup.ini DeploySvr1=Serveraddress:5494 MCEnrollmentSvr1=Serveraddress:443 The issue is that our Network department aren't happy that we will use port 443 for or MCEnrollmentSvr1 - End they would like us to change the port. But when i look in MobiControl Administration Utility i can't find MCEnrollmentSrv. If i look in the Deployment Server menu, port 443 is mention under Device Management Address and Management Service Address, but the server address are not the same as the MCEnrollmentSvr1 in the configuration file on the device.
Hello Support Staff, as stated in this article https://discussions.soti.net/kb/upcoming-change-in-firewall-settings-for-soti-services , there will be some new adresses that have to be whitlisted. Can you elaborate what those new adresses are for: --NEW ADDRESSES-- 13.248.157.19 76.223.23.230 75.2.25.8 99.83.149.241 Do They have to be whitelisted only for the server or also for clients etc.? What is the use for each of the adresses or what are mandatory and voluntary for MobiControl to work properly (i.e. Skins-Services).
Can any one know that SSL offloading at firewall is supported by Soti MDM ???
Greetings. We want to enroll some Android Enterprise devices. We have a firewall that does not allow communications to download the required google components. Can you tell us what rules to create in our firewall?
If BOTH MobiControl servers and devices are all restricted to a CLOSED Wifi-only corporate network, and only the MobiControl server can have firewall exception(s) added for very limited access to support servers, then what firewall exceptions should be added to allow Bitdefender Antivirus latest definition update file be REGULARLY updated (as configured in the Antivirus payload in a profile) to the targeted devices via MobiControl deployment server?
What do I need to open for MobiControl to communicate internally or externally.
Top-tier experts who are delivering outstanding content. Should have more than 7000 points.
Experts who are consistent with great content. Should have more than 1000 points
Highly experienced members with valuable inputs. Should have more than 700 points
Beginners taking the initiative. Should have more than 500 points