MDM Network Ports
A fully working Mobile Device Management system needs a correctly deployed set of CapaInstaller services in the company’s network. Use this page to plan the firewall rules for those services and for the managed devices. For the ports of the other CapaInstaller services, see CapaInstaller Network Port Reference.
Services
Section titled “Services”| Service | Port | Protocol | Direction | Outgoing destination | Description |
|---|---|---|---|---|---|
| cimdm | 443 (SSL) | TCP | PUBLIC → DMZ | Mobile devices retrieve configurations and applications. | |
| cimdm | 443 (SSL) | TCP | DMZ → PUBLIC | api.capaone.com | Gateway for: Apple Push Notification service (APNs): http://support.apple.com/kb/TS4264 Google Cloud Messaging: http://en.wikipedia.org/wiki/Google_Cloud_Messaging Microsoft Open Mobile Alliance (OMA): https://en.wikipedia.org/wiki/OMA_Device_Management |
| Self Service Portal | 9443 (default) | TCP | PUBLIC → DMZ | Devices access the Self Service Portal. | |
| cibackend | 5023 (default) | TCP | DMZ → SERVER | cimdm gets profiles and configurations. | |
| cifrontend | 5022 (default) | TCP | DMZ → SERVER | cimdm authenticates users when they enroll devices. | |
| cifrontend | 443 (SSL) | TCP | SERVER → PUBLIC | download.capainstaller.com | Retrieves updated information about device models and versions. |
Devices
Section titled “Devices”To support mobile device management, end-user devices must communicate with these network services:
| Devices | Port | Protocol | Direction | Outgoing destination | Description |
|---|---|---|---|---|---|
| All devices | 443 (SSL) | TCP | LAN → PUBLIC | DMZ server | Secure communication between the devices and the MDM server. |
| Android devices | 5228 (Google server) | TCP | LAN → PUBLIC | android.apis.google.com gcm-http.googleapis.com fcm.googleapis.com |
Communication between Android devices and Google Cloud Messaging (GCM), which sends push notifications and other data to Android devices. |
| Android devices | 5229 (Google server) | TCP | LAN → PUBLIC | android.apis.google.com gcm-http.googleapis.com fcm.googleapis.com |
Communication between Android devices and GCM over a secure connection. |
| Android devices | 5230 (Google server) | TCP | LAN → PUBLIC | android.apis.google.com gcm-http.googleapis.com fcm.googleapis.com |
Communication between Android devices and GCM for sending and receiving multicast messages. |
| Android devices | 443 (Google server) | TCP | LAN → PUBLIC | android.apis.google.com gcm-http.googleapis.com fcm.googleapis.com play.google.com |
Secure communication between Android devices and the MDM server. |
| Apple devices | 2195 (Apple server) | TCP | LAN → PUBLIC | gateway.push.apple.com | Sends push notifications to iOS devices. |
| Apple devices | 2196 (Apple server) | TCP | LAN → PUBLIC | feedback.push.apple.com | The APNs Feedback Service tells the MDM server about failed push notifications. |
| Apple devices | 5223 (Apple server) | TCP | LAN → PUBLIC | Communication between iOS devices and APNs. Also used for device activation. | |
| Windows Phone devices | 443 (Microsoft server) | TCP | LAN → PUBLIC |