For Hexnode-managed iOS devices, the firewall rules are primarily outbound from the device network. Inbound access to the devices is not required for standard MDM communication.
– Direction: iOS device network to Hexnode/Apple service endpoints
– Used for: enrollment, device check-in, policy sync, app management, profile installation, and secure HTTPS communication with the Hexnode portal and related service domains.
2. Outbound TCP 5223
– Direction: iOS device network to Apple Push Notification service
– Used for: maintaining the persistent APNs connection required for MDM wake-up notifications.
No inbound rule is required for standard MDM commands. Hexnode sends a wake-up notification through APNs, and the device then contacts the MDM server over the allowed outbound HTTPS connection.
If the firewall supports domain-based allowlisting, use the Hexnode network ports documentation and Apple’s APNs network requirements as the source for the latest domains and destination ranges. This is preferable to hardcoding static IPs wherever possible, as cloud service endpoints may change.
Regards,
Mary Romero