Solved

Firewall issue with iPad restore though iTunes

Posted on 2015-02-06
8
98 Views
Last Modified: 2015-02-17
I just installed a Fortigate 80D at a client site.  Installed fine but now client is saying that they cannot do a restore of their iPads and are getting a error when it tries to verify software?  Nothing is blocked going out of the firewall.  There is a content filter on Fortigate.  I have opened *.apple.com and *.verisign.com through the filter.  Any ideas what I might be missing?
0
Comment
Question by:DaveKall42
  • 5
  • 3
8 Comments
 
LVL 7

Accepted Solution

by:
Peter Loobuyck earned 500 total points
ID: 40595642
My best guess is that you scanning ssl traffic. I suggest you turn off all ssl filtering on the 17.0.0.0/8 subnet (it's all Apple).

The ipads will get through now..
0
 

Author Comment

by:DaveKall42
ID: 40595705
Ok, let me try that.
0
 

Author Comment

by:DaveKall42
ID: 40595709
I just created a new policy for lan to wan any to 17.0.0.0/8  for any ports with no services enabled on the policy.  That should work?
0
 
LVL 7

Expert Comment

by:Peter Loobuyck
ID: 40595754
Yes, lan to wan to 17.0.0.0/8, without any um profile, just nat.
It's probably the deep ssl inspection. That replaces the ssl certificate to inspect it. Apple won't allow that I bet!
That should work.

Can you test it?
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:DaveKall42
ID: 40595755
I cannot today as I am not onsite.  Its a school so will be only able to test on Monday.
0
 
LVL 7

Expert Comment

by:Peter Loobuyck
ID: 40595768
Allright, let me know on Monday if it's working or not..
0
 

Author Comment

by:DaveKall42
ID: 40595770
Will do, thanks so much for your help!
0
 

Author Closing Comment

by:DaveKall42
ID: 40615518
Worked!!
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
If you other experts are anything like me you are always looking into and testing out new features. While I was doing some research one day I ran across an app that I installed on my Mac and used as a security system. Mac OS X: SecureHome uses your …
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now