SOTI Mobi enrollment from web - FW rules for mirror servers

Solved
LV
Libor Viták
AS Watson Group

Hi,

I came up with problem to enroll our devices on specific WiFi which is secure by FW rules. Basicaly I can say the model of it is everything is closed and what we allow it can be reach.

For our Zebra devices we've got enroll from private FTP on site - it's OK

Problem occures with non-Zebra devices (tablets) which I want to enroll via QR code. I have to use link to http://soti.net/apk/ae2

If we allowed FQDN it's not enough. 

After some research we found out that this link redirects to mirrors addresses(servers).

Is there any list of approved SOTI sites/IPs which must be allow on FW please?

I could find some of them in log but it's always swapping to the new ones. I don't know how big this list can be and finding like that is time consuming.

thank you Libor

SOTI Mobi version: 15.6.1.1048

device: Lenovo TB-X505F

OS: A10

code I'm using in QR:

{"android.app.extra.PROVISIONING_DEVICE_ADMIN_SIGNATURE_CHECKSUM":"xxx",
"android.app.extra.PROVISIONING_DEVICE_ADMIN_COMPONENT_NAME":"net.soti.mobicontrol.androidwork/net.soti.mobicontrol.admin.DeviceAdminAdapter",
"android.app.extra.PROVISIONING_WIFI_SECURITY_TYPE":"WPA",
"android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_DOWNLOAD_LOCATION":"http://soti.net/apk/ae2",
"android.app.extra.PROVISIONING_LOCALE":"cs_CZ",
"android.app.extra.PROVISIONING_WIFI_SSID":"xxx",
"android.app.extra.PROVISIONING_LEAVE_ALL_SYSTEM_APPS_ENABLED":true,
"android.app.extra.PROVISIONING_WIFI_PASSWORD":"xxx",
"android.app.extra.PROVISIONING_TIME_ZONE":"Europe/Amsterdam",
"android.app.extra.PROVISIONING_ADMIN_EXTRAS_BUNDLE":{"enrollmentId":"xxx"}}
2 years ago
SOTI MobiControl
ANSWERS
ZC
Zafer Cigdem
2 years ago

Hi Libor,

It's not a must to use "http://soti.net/apk/ae2".

You can also download the AE agent (from here: MobiControl Device Agent Downloads | SOTI Docs) on your FTP/SFTP server and you can use the link of the source file from your server locally instead of the public address that you mention above. 

Example:

"android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_DOWNLOAD_LOCATION":"http://zafer.cigdem.local/GoogleMobiControl1533_1069.apk",

I hope it helps. Thank you

Zafer

LV
Libor Viták
2 years ago

Hi, thank you for the reply. 

Yes, I know it can be done like that too.

But it ends in same state - I can't enroll device. it's stuck on "getting ready for work setup..." 

I'm suspicious because I found out some of the google sites must be allow too to finish enroll.

Do you know the list here?

thank you

ZC
Zafer Cigdem
2 years ago
Solution
J
JEMOD@SOTI
2 years ago

Hi Libor,

Thank you for posting on SOTI Pulse! 

I am glad to see that you were able to find a solution and your issue was resolved! 

Please feel free to reach out to us if you have any further questions in the future.

Kind regards,

Technical Support Specialist | SOTI | +1 905.624.9828 | SOTI.net lDiscussion Forum | Log a Case Online l Facebook l LinkedIn l Twitter