Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Web Exception - Apple Update and iCloud

Good day! We've added in Web Exception the recommended links from Apple to except it from policy checks and https decryption. Unfortunately yesterday, our company issued Apple phones to it's employees and it seems even if weset Allow All in Web Policy and Application Policy the apps can't be downloaded or retrieve... Halp.



This thread was automatically locked due to age.
Parents
  • We've already added these to Web Exception

    ^([A-Za-z0-9.-]*\.)?mzstatic\.com\.?/

    ^([A-Za-z0-9.-]*\.)?apple\.com\.?/

    ^([A-Za-z0-9.-]*\.)?icloud\.com\.?/

    ^([A-Za-z0-9.-]*\.)?cdn-apple\.com\.?/

    And are these four necessary to allow Apple updates?

    And also when you do Web Exception do you always check Https Decryption and Policy Checks?

    We've checked the four...

  • Hi,

    You also need to add exceptions from policy checks, HTTPS certificate validation.

    I ended up creating a specific rule for all my apple devices that points at apple sites as well using the FQDN list.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

  • Hi. How do you that FQDN in Firewall. Can you site an example?

    rfcat_vk said:
    Hi,

    You also need to add exceptions from policy checks, HTTPS certificate validation.

    I ended up creating a specific rule for all my apple devices that points at apple sites as well using the FQDN list.

    Ian

  • Hi,

    a warning this does not work in the IPv6 firewall rules.

    the firewall rule screenshot is from V18 EAP3.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    a warning this does not work in the IPv6 firewall rules.

    the firewall rule screenshot is from V18 EAP3.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

Children