Keep 443 open for profile updates, but limit profile manager login

I notice that port 443 is used by clients to communicate with the server when profiles are pushed (I assume as an encrypted connection for transmitting the profile file). Therefore it seems that for profiles to be pushed to devices outside the LAN 443 needs to be available when clients come calling to the FQDN to get a new profile (when Apple's push notification service says 'hey something is waiting for you').
However, from a security standpoint I'm not thrilled about exposing the profile manager login to the page to the whole world. Is there a way to limit access to this page to say just our LAN (e.g., using .htaccess) and still allow clients to come calling to the server from anywhere on 443 to fetch profiles? How have others handled this scenario?
Thanks!

...minor updates (see below) after some additional testing. Added /auth as this is another mechanism for authenticating against the admin panel. Also Added an additional allow for loopback traffic since logs showed some items being blocked on : : 1
<Location /profilemanager>
    AllowOverride None
    Options MultiViews FollowSymlinks
    Order deny,allow
    Deny from all
    Allow from 10.0.0.0/8                   #OUR LAN
    Allow from XXX.XXX.XXX.XXX              #SERVER'S PUBLIC IP
    Allow from 127.0.0.0/255.0.0.0 ::1/128    #FOR INTERNAL LOOPBACK TRAFFIC
    Header Set Cache-Control no-cache
</Location>
<Location /mydevices>
    AllowOverride None
    Options MultiViews FollowSymlinks
    Order deny,allow
    Deny from all
    Allow from 10.0.0.0/8                   #OUR LAN
    Allow from XXX.XXX.XXX.XXX              #SERVER'S PUBLIC IP
    Allow from 127.0.0.0/255.0.0.0 ::1/128    #FOR INTERNAL LOOPBACK TRAFFIC
    Header Set Cache-Control no-cache
</Location>
<Location /auth>
    AllowOverride None
    Options MultiViews FollowSymlinks
    Order deny,allow
    Deny from all
    Allow from 10.0.0.0/8                   #OUR LAN
    Allow from XXX.XXX.XXX.XXX              #SERVER'S PUBLIC IP
    Allow from 127.0.0.0/255.0.0.0 ::1/128    #FOR INTERNAL LOOPBACK TRAFFIC
    Header Set Cache-Control no-cache
</Location>

Similar Messages

  • HT204306 my ipad's disabled and while restoring, it keeps on requesting for an update but whenever i try to download the udpates an error occurs, plz help

    my ipad's disabled and while restoring, it keeps on requesting for an update but whenever i try to download the udpates an error occurs, plz help

    You might want to try disabling your firewall and antivirus software while you attempt to update/restore.

  • I reset my apple ID password here on the website, but my computer isn't recognizing my new password. what should I do? I just need to update my adobe flash player but it keeps asking me for my password but won't take my new password I just updated.

    Model Name: iMac
      Model Identifier: iMac12,1
      Processor Name: Intel Core i5
    I reset my apple ID password here on the website, but my computer isn't recognizing my new password. what should I do? I just need to update my adobe flash player but it keeps asking me for my password but won't take my new password I just updated.

    "If you've forgotten the Apple ID password how did you log in to make the last post?"
    Exactly! The password I used to log on here and write my post I figured was the same Apple ID password I would use to reset my computer login password. But my computer isn't recognizing it as the correct password so it wont let me update my login password. I have 2 user accounts on my computer.
    As far as the link you provided, I already looked to that for help earlier. It states:
    Choose Apple menu > System Preferences, click Users & Groups, click the lock to unlock it, then provide an administrator name and password. Select a user, then click Reset Password.
    I did these steps, but I don't remember my admin password. The question is: How do I reset my admin password so I can reset my log in password.
    Is my admin password the same password I use to log onto this website to post questions? If so, like I said previously, I already reset that password and my computer isnt recognizing it.

  • I have tried to download an app but it says that i need 10.8 or later on my macbook air i have checked for software update but none i am on 10.7.5

    i have tried to download an app but it says that i need 10.8 or later on my macbook air i have checked for software update but none i am on 10.7.5 the app is pocket planes HELP PLZ
    i would really apprechiate it
    thank you very much
    Josh Stainsby
    [email protected]

    http://www.apple.com/osx/specs If your Mac is supported, open App Store, make a backup and purchase Mountain Lion. See if your programs are compatible > http://www.roaringapps.com

  • HT4623 I'M TRYING TO SEARCH FOR SOFTWARE UPDATE BUT I DID NOT GET ?

    I'M TRYING TO SEARCH FOR SOFTWARE UPDATE BUT I DID NOT GET ?
    I'm using i phone 4 ..for your information.

    Over the air update did not come out until iOS 5.  You need to open iTunes on your computer and connect your phone to it and follow the prompts to update.  Do a manual back before you do that

  • I upgraded to Mountain Lion yesterday, but since doing so I find that my 1Password app will not work. I have checked for 1Password updates but there are none. Is there a compatibility issue

    I upgraded to Mountain Lion yesterday, but since doing so I find that my 1Password app will not work. I have checked for 1Password updates but there are none. Is there a compatibility issue

    Hmmm...I'm using 1Password Version 3.8.20 (build 31499) with a fresh install (scrape and pave) of Mt. Lion on my iMac and it's working fine.
    I use Dropbox to sync 1Password so for my fresh install I simply downloaded 1Password from Agilbits website and installed it.
    Have you tried reinstalling 1Password?  Depending on how you purchased it, download it from their website or from the Mac App store to reinstall/replace it.  (IIRC v3.8.x comes directly from Agilbits and v3.9 from the Mac App store.)  You shouldn't have to uninstall it, the new download should overwrite the existing copy.
    As with anything else, be sure to run a  backup first!
    More here:
    http://support.agilebits.com/discussions/1password-38-for-mac-from-agilebits-web site/17861-finding-existing-data-file-when-reinstalling-1password
    http://support.agilebits.com/discussions/1password-in-mac-app-store/3377-how-to- reinstall
    http://support.agilebits.com/discussions/1password-38-for-mac-from-agilebits-web site/13769-reinstall
    http://support.agilebits.com/discussions/1password-in-mac-app-store/2394-reinsta lling-1-password
    Hope that helps.
    D'oh!  Mende1 beat me to it! 

  • Safari and Firefox quits unexpectedly after attempting to attach or upload a file online. I checked for software updates, but no pending updates were found, I'm running OS X vr 10.5.8.

    I checked for software updates, but no pending updates were found, I'm running OS X vr 10.5.8.

    None of the above answers have helped me.

  • Why can I not download the latest version of Flash? Keeps asking me for my password but won't accept

    Why can I not download the latest version of Flash? Keeps asking me for my password but won't accept even though I go through a reset process of a new passwork to ensure it is correct.

    What kind of password?  Can you post a screenshot of that prompt?
    Also, what is your operating system & version?
    What is your web browser?

  • Updated! App-V: A Configuration Template for Deploying to Stateless RDS Clients on Citrix Published Desktops with Citrix UPM for Profile Management

    I've updated my App-V Startup script that I use.  The new version includes Event Logging as well as detailed logging, and its in PowerShell finally)
    Check out the wiki!
    http://social.technet.microsoft.com/wiki/contents/articles/25318.app-v-a-configuration-template-for-deploying-to-stateless-rds-clients-on-citrix-published-desktops-with-citrix-upm-for-profile-management.aspx

    I've updated my App-V Startup script that I use.  The new version includes Event Logging as well as detailed logging, and its in PowerShell finally)
    Check out the wiki!
    http://social.technet.microsoft.com/wiki/contents/articles/25318.app-v-a-configuration-template-for-deploying-to-stateless-rds-clients-on-citrix-published-desktops-with-citrix-upm-for-profile-management.aspx

  • HT4623 i checked for an update but it said there wasnt one, but i have the very first software! what do i do ?

    i checked for an update but it said there wasnt one, but i have the very first software! what do i do ?

    To update to iOS 6.0 requires iTunes 10.7. You need to first update your version of iTunes.

  • Why does Apple need to charge for feature updates, but Sony doesn't?

    Ok, so I know all about the subscription-based accounting reasons for why Apple has to charge a nominal fee for firmware updates that provide new features to the iPod touch (but not iPhone).
    I don't have a problem with this fee, and personally think its quite reasonable, and am happy to pay it.
    However, I'm curious as to why Apple has to charge for these updates, but Sony doesn't - and I've not been able to find a reason.
    Since the release of both Sony's PSP and PS3 video game consoles, Sony have frequently released firmware updates that add many minor and some very significant new features to both consoles, as Apple have done with the iPod touch.
    However, Sony has never charged for these new features. Does anyone really know why there's this difference?

    You better believe that any company doing business in the US has to follow US laws. You don't get to just say, oh well we have our headquarters in another country so we can do what we want in yours. Hehe I am pretty sure diplomatic immunity doesn't come with selling something in the US. The accounting reason is a sham. Apple knows that their customers are desperate for "coolness" and will sacrifice features and customer service and pay for that privelege.
    What really gets me is that I already bought the January update. The only thing 2.0 adds is the "priveledge" of paying Apple to buy applications. So of course I bought the 2.0 update because I am an idiot and now my audiobooks will not play. Will they support it no. I buy an update from them, it screws up my ipod and then I can't even call or email to get some help. Instead I have to travel an hour to the nearest Apple store. I recently bought my first iPod but after all the horrendous experiences I have had with their lack of support and idiotic "geniuses" at the genius bar, I will never buy another apple product. Which is too bad because they have the most elegant and fun to use interfaces. However, I would rather have something a bit less elegant but that I can get service on without a 3 hour time commitment on my part.

  • Why will firefox not start on my laptop? can't uninstall or open the profile manager either. it simply does not run. it used to work fine until i had to restore my system.

    had firefox 4.0 & have been a user of firefox for a few years now. never had any problems. had to do a system restore after my computer detected a virus of some sort & i couldn't do anything. the virus kept popping up a bogus add for me to buy an antivirus program. had to restart laptop in safemode to initiate the restore. ever since then firefox has not opened. can't even uninstall it or open the profile manager. anything that has to do with firefox will simply not run/open at all. i'm stumped.

    System restore can cause problems as well as solve them, it has probably completely mucked up your Firefox installation.
    Try deleting your Firefox installation directory, the default location on 32 bit Windows is C:\Program Files\Mozilla Firefox\
    Now re-install Firefox, it should pick up your current profile folder so you should not lose your bookmarks, passwords etc.

  • App-V: A Configuration Template for Deploying to Stateless RDS Clients on Citrix Published Desktops with Citrix UPM for Profile Management

    Please Vote if you find this to be helpful!
    App-V:  A Configuration Template for Deploying to Stateless RDS Clients on Citrix Published Desktops with Citrix UPM for Profile Management
    Just posted this to the wiki:
    http://social.technet.microsoft.com/wiki/contents/articles/25318.app-v-a-configuration-template-for-deploying-to-stateless-rds-clients-on-citrix-published-desktops-with-citrix-upm-for-profile-management.aspx

    I would not recommend this and keep the package cache and the client on the same non-persistent drive and enable the Shared Content Store. If you separate the cache and the App-V client they could get out of sync and strange behaviour can occur. 
    You can use a temporary local profile with Citrix UPM or UE-V and specify what to roam/save.
    You can use the Shared Content Store so packages will stream over the network. When the user logs on there is a publishing phase where shortcuts etc are created for the user, this will take some time.
    Are you using the App-V full infrastructure?
    Are you using a boot disk, partition or PXE in combination with PVS?

  • Where are the profiles stored for Profile Manager.

    Where are the profiles stored for Profile Manager?
    I created a profile attached to a user group and then made the mistake of removing the group without first deleting the profile.
    Now the orphan profile can't be managed (it's no longer visible) and is still being pushed out to users.
    The group I deleted had another group as it's members.
    Example:
    Active Sync User Group was a member of VPN Group.
    VPN Group was deleted (it had the VPN settings payload)
    Profile with VPN settings are still pushed out to Active Sync User Group even though VPN Group no longer exists.
    I'm hoping I can manually remove this profile but I'm thinking it may be contained in Postgres. If that's the case I would appreciate any suggestions/methods to access the database to make modifications.
    Thanks

    The information/data for apps is stored together with the app in both the iPad and in the backup on your computer. When you drop a file in the file sharing section of apps it gets added to the backup and to the iPad. When you delete it it get deleted from the backup and from the iPad.

  • I keep getting the 'Profile missing or inaccessible' error message. I've tried some of the advice given to others but none of it is working for me. I've tried opening the Profile Manager but I get the same error message when I try to do that.

    Since yesterday when trying to use Firefox I've been getting error 'Profile missing or inaccessible'.
    I've tried uninstalling & reinstalling it & from looking at advice to others with this problem I tried to access the Profile Manager but when I try to do that I again get the Profile missing error message.

    Create a new profile as a test to check if your current profile is causing the problems.
    See "Basic Troubleshooting: Make a new profile":
    *https://support.mozilla.com/kb/Basic+Troubleshooting#w_8-make-a-new-profile
    There may be extensions and plugins installed by default in a new profile, so check that in "Tools > Add-ons > Extensions & Plugins" in case there are still problems.
    If that new profile works then you can transfer some files from the old profile to that new profile, but be careful not to copy corrupted files.
    See:
    *http://kb.mozillazine.org/Transferring_data_to_a_new_profile_-_Firefox

Maybe you are looking for

  • Adf AutoSuggest Popup not working properly with af:InputText

    Hi, I have a scenario where I have a inputText box with autoSuggest . Now I need to validate the inputText for having minimum of three characters . I added the af:ValidateLength .The moment I added af:ValidateLength or any customValidator ,the af:aut

  • Film 'damage' filter in PremPro? Artificial grain, yes I see. But I need damage.

    I have used the artificial grain filter from time to time and it can wrk when applied properly, however, I am in need of a film damage filter. I'd like to add scratches, dirt, etc. is there a filter in premiere pro for that or one I can use in After

  • Will the 3300 I Trigue 2.1 3300 Work with An mp3 Player

    I am ordering the 3300 ITrigue and I don'tk now if I can set it up with an mp3 player or not. I know in back of it the subwofer only has an output not and input....if there is a way could someone let me know thatnks Denny

  • Material PR transfer from ECC to SRM without Account Assignment

    Hello, When a material PR without account assignment is transferred to SRM. The scenario is determined as direct procurement and system will behave in extended classic scenario. I would need the PO to be posted in backend ie Classic scenario. We are

  • Pre-populate Portal sign-on screen

    Is there a way to pre-populate the portal sign-on screen with user-id and password ? We are in the process of migrating users to SAP portal, and are looking at re-directing (auto login if possible (or) pre-populate login fields at the least) them to