Gotchas Flashcards
Thanks to Vicky for these notes! Contact me to get in touch. These decks will be from her notes she shared. I'll likely add my own as well
For your Apple devices to work with APNs, allow network traffic from the devices to the Apple network (17.0.0.0/8) directly or by network proxy. Apple devices must be able to specific ports on specific hosts:
TCP port 443 during device activation, and afterward for fallback if devices can’t reach APNs on port 5223
TCP port 5223 to communicate with APNs
TCP port 443 or 2197 to send notifications from MDM to APNs
Apple Remote Desktop and Classroom Ports
3283
TCP/UDP
Apple Remote Desktop, Screen Sharing
5900
TCP - Remote Framebuffer - 6143 -rfb
Remote Framebuffer, Real-Time Transport Protocol (RTP), Real-Time Control Protocol (RTCP)
5900 - UDP - Apple Remote Desktop, Screen Sharing
Real-Time Transport Protocol (RTP), Real-Time Control Protocol (RTCP)
5901–5902 -UDP - Apple Remote Desktop, Screen Sharing
Network relays in iOS, iPadOS, macOS, and tvOS
relays can be applied to managed apps, domains, or the entire device.
entire device, and when accessing internal resources. Multiple network relays can be used in parallel including iCloud Private Relay, with no app required. For more information, see Use network relays.
What are the 3 content caching selection options ?
macOS content caching
- All Content
- Only Shared content
- Only iCloud Content
By default, content caching is limited to a specific subnet. However, you can set the caching server to provide content caching for these configurations:
● Subnets of the local network that share a common public IP address
● Subnets of publicly accessible IP addresses (with additional DNS changes being required)
Apple Business Manager and Apple School Manager accounts that CANNOT be federated:
● Administrator
● People Manager
Understand the Apple Business Manager roles:
- Administrator
- People Manager
- Device Enrollment Manager
- Content Manager
- Staff
Apple School Manager can sync with :
SIS
Student information system
Integrate Apple School Manager with your Student Information System (SIS)
Apple School Manager cannot sync with Apple Business Manager
Apple School Manger - More Information
You can also use Apple School Manager to securely integrate with your Student Information
System (SIS) or use the Secure File Transfer Protocol (SFTP) to upload all the CSV files from
your SIS to Apple School Manager. You may want to use SFTP if your SIS isn’t currently
supported by Apple School Manager or if you want to import the exact same information from a
different system you currently use.
Terminal command for network quality:
networkQuality
How does a PAC file influence the way an Apple device communicates over a network?
The device follows the PAC file rules that define the proxy server’s location and traffic allowed to
connect directly. The proxy server’s location and rules for allowed direct traffic defined in the PAC file manage the way an Apple device communicates over a network.
How do you ensure that only trusted host computers can pair with your organization’s iPhone and iPad devices?
Distribute the correct supervision identities to users’ devices. When you deselect the “Pair with non-Apple Configurator hosts” restriction — and distribute the correct supervision identities to users’ devices — you ensure that only trusted computers holding a valid supervision host certificate are allowed to access iPhone or iPad over Thunderbolt or USB.