I will suggest that you add an exclusion to *.apple.com sites.
Cannot remember the specific Apple update IP site. But will get back to you with it.
Main Topics
Browse All TopicsWe have several users who have Macs and they can't seem to access the Apple software updates, iTunes or the App Store. If they go home with their Macs, they can access these sites fine. We have a Watchguard Firebox and my suspicion is that we're somehow blocking something but I have no idea what. It's a pretty standard configuration and we don't have problems with any other web stuff. Apple hasn't been much help to us, either.
Any thoughts?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
If you are HTTP proxy service then this might cause problems; please look at firebox traffic logs which would indicate if the firebox is blocking anything.
Allowing that in the policy would solve the issue; you can create another HTTP proxy service or filteredHTTP service.
In Policy Manager, edit the service; go to Properties; View/Edit Proxy; go to HTTP Response->Content type and add [allow] the blocked content. This would allow for all sites; so you can add one more HTTP proxy [with blocked content allowed] or packet filter policy and configure as:
Putbound connected are Enabled; from any-trusted OR speicifc-host-ip-addresses
Please let know if you need more details.
Thank you.
Good Morning,
Since the problem is only specific to MAC users, I suggest opening ports 3689 and 5353 on the Firebox:
In Policy Manager, click the + sign;
Expand the Custom policy and click New;
Name the new policy iTunes - MAC, (or whatever you prefer;)
Add TCP 3689 and UDP 5353;
Add the new Policy to your Policy Manager.
LJ
Business Accounts
Answer for Membership
by: strungPosted on 2009-10-30 at 10:31:56ID: 25705146
See this thread: http://www.experts-exchang e.com/Hard ware/Netwo rking_Hard ware/ Firew alls/Q_235 47777.html
Likely your firewall is blocking the type of files that are used by software update, particularly .dmg files.