[REQUEST] Unblocking Apple/Google/Microsoft Activation Login Server By IP

NviGate Systems

Well-Known Member
Reaction score
1,022
Location
Vancouver
At our shop we have an Ubiquity AP, and it's configured and maintained by a tech I know. I've asked him about unblocking these services as when clients want to get a loan (we are a Pawn Shop) we require that customers sign out of a device so if they default on a loan we are not stuck with a paperweight. Up till now we have to enable an AP on our phones, but they are getting tired of it.

Our AP is configured as a firewall device which only opens access at certain times to avoid staff spending too much time on internet and not working. However, we can unblock certain IP's.

What's the best way to discover the IP's for these servers or is there a list somewhere?

I think the Apple Activation server is albert.apple.com (17.149.240.70). I did a brief web search but I was at work on my phone, so couldn't spend too much time figuring it out. Is there a list somewhere for sysadmins or can I run a trace app to figure out where my requests are going?

This is the "thus far" list of servers we need:

Apple Activation/Login/Updates
Google Activation/Login
Microsoft Activation/Updates
Playstation Updates
XBOX Updates

Any help to point me in the direction would be awesome, or if perhaps a second AP that allowed access to specific domains, cause I doubt there is much work time wasting stuff to do on most of Microsoft's or Apple's Servers. :)
 
What is actually doing the blocking? APs are just bridges.

The problem with big services such as activation servers...is they are typically clustered from many different servers, spread out in different geographical locations. And they're tend to change IPs as time goes on, data centers move, servers get replaced, etc. So it's a DNS host name that stays the same, but the IPs slowly change...making it hard to keep up an ACL via IPs only.

Usually tight control of internet stuff is done by a UTM at the edge...you can make a user group, special wifi network, vlan...that only has access to those DNS names.
 
Back
Top