Greetings. We want to enroll some Android Enterprise devices. We have a firewall that does not allow communications to download the required google components. Can you tell us what rules to create in our firewall?
Greetings. We want to enroll some Android Enterprise devices. We have a firewall that does not allow communications to download the required google components. Can you tell us what rules to create in our firewall?
This should get you an idea of what you need:
https://www.soti.net/mc/help/v14.2/en/setup/installing/network_ports.html
I have already reviewed this documentation. I need the addresses of the google play services servers, necessary for the correct Android Enterprise enrollment.
How mine are wrote out is:
| tcp-80;tcp-443 | Soti_Services | activate2.soti.net;mc-enroll.soti.net;location2.soti.net;*.soti.net;*.samsungknox.com/*;*.secb2b.com;*.samsung.com |
| tcp-80;tcp-443 | Soti_APP_Downloads | amazon.com/*;play.google.com/* |
Greetings.
I am testing with the following rules in the firewall
|
Destination Host |
Ports |
|
TCP/443 TCP,UDP/5228-5230 |
|
|
TCP/443 |
|
|
TCP/443 |
|
|
TCP/443,5228-5230 |
|
|
TCP/443 |
Hi All,
I have been looking into this myself and I have found the following detail online:
VPN: Ensure that your EMM is configured to send the full certificate chain if your company uses intermediate certificates.
Proxy: You can test proxy settings in Chrome by opening the Chrome Browser in your phone and entering in “Chrome://Policy” to view the configurations that were sent down to the device.
Wi-Fi: Ensure the Google Play Store isn't blocked via Wi-Fi
Certificates: Ensure the EMM uses the certificate alias API so that the user does not see the “Certificate Chooser” when they open an app that needs to use a certificate.
James
Took me a while to find but:
https://static.googleusercontent.com/media/www.android.com/nl//static/2016/pdfs/enterprise/Android-Enterprise-Migration-Bluebook_2019.pdf
Full Blueprint on how to use Android Enterprise (also firewall settings)