Skip to content

MDM Network Ports

A fully working Mobile Device Management system needs a correctly deployed set of CapaInstaller services in the company’s network. Use this page to plan the firewall rules for those services and for the managed devices. For the ports of the other CapaInstaller services, see CapaInstaller Network Port Reference.

Service Port Protocol Direction Outgoing destination Description
cimdm 443 (SSL) TCP PUBLIC → DMZ Mobile devices retrieve configurations and applications.
cimdm 443 (SSL) TCP DMZ → PUBLIC api.capaone.com Gateway for:
Apple Push Notification service (APNs): http://support.apple.com/kb/TS4264
Google Cloud Messaging: http://en.wikipedia.org/wiki/Google_Cloud_Messaging
Microsoft Open Mobile Alliance (OMA): https://en.wikipedia.org/wiki/OMA_Device_Management
Self Service Portal 9443 (default) TCP PUBLIC → DMZ Devices access the Self Service Portal.
cibackend 5023 (default) TCP DMZ → SERVER cimdm gets profiles and configurations.
cifrontend 5022 (default) TCP DMZ → SERVER cimdm authenticates users when they enroll devices.
cifrontend 443 (SSL) TCP SERVER → PUBLIC download.capainstaller.com Retrieves updated information about device models and versions.

To support mobile device management, end-user devices must communicate with these network services:

Devices Port Protocol Direction Outgoing destination Description
All devices 443 (SSL) TCP LAN → PUBLIC DMZ server Secure communication between the devices and the MDM server.
Android devices 5228 (Google server) TCP LAN → PUBLIC android.apis.google.com
gcm-http.googleapis.com
fcm.googleapis.com
Communication between Android devices and Google Cloud Messaging (GCM), which sends push notifications and other data to Android devices.
Android devices 5229 (Google server) TCP LAN → PUBLIC android.apis.google.com
gcm-http.googleapis.com
fcm.googleapis.com
Communication between Android devices and GCM over a secure connection.
Android devices 5230 (Google server) TCP LAN → PUBLIC android.apis.google.com
gcm-http.googleapis.com
fcm.googleapis.com
Communication between Android devices and GCM for sending and receiving multicast messages.
Android devices 443 (Google server) TCP LAN → PUBLIC android.apis.google.com
gcm-http.googleapis.com
fcm.googleapis.com
play.google.com
Secure communication between Android devices and the MDM server.
Apple devices 2195 (Apple server) TCP LAN → PUBLIC gateway.push.apple.com Sends push notifications to iOS devices.
Apple devices 2196 (Apple server) TCP LAN → PUBLIC feedback.push.apple.com The APNs Feedback Service tells the MDM server about failed push notifications.
Apple devices 5223 (Apple server) TCP LAN → PUBLIC Communication between iOS devices and APNs. Also used for device activation.
Windows Phone devices 443 (Microsoft server) TCP LAN → PUBLIC