Portfreigaben C10 und Android-Box
Problem
Das Netzwerk soll mit einer Firewall abgesichert werden. Die Tafel soll weiterhin vollumfänglich nutzbar sein.
Lösung
Folgende Netzwerk-Ports werden von der Digitalen Tafel C10 sowie von der HKM Android-Box benötigt.
Function | Protocol | Port | Description | Address |
http | TCP | 80 | AirClass | |
http | TCP | 80 | System firmware OTA | http://iwbota.com |
https | TCP | 443 | System firmware OTA | |
https | TCP | 443 | Screen Share Pro / Bytello Share | |
webrtc | TCP | 3478 | Screen Share Pro / Bytello Share | / |
https | TCP | 443 | Cloud Drive | https://account-platform.bytello.com-(only for bytello os) |
https | TCP | 80 | QR code scan & Go function | |
https | TCP | No limitation | Bytello Class | |
WebSocket | TCP | No limitation | Bytello Class | / |
http/https | TCP | No limitation | Browser | / |
WebSocket | TCP | 4664 | AndroidRemote/DMS | localhost |
https | TCP | 443 | AMS | |
https | TCP | 443 | Bytello account | https://id.bytello.com |
TCP TCP, UDP | 443 5228-5230 | Google Play und Updates
gstatic.com und googleusercontent.com – enthalten von Nutzern erstellte Inhalte (z. B. App-Symbole im Play Store)
*.gvt1.com, *.ggpht.com, dl.google.com, dl-ssl.google.com und android.clients.google.com – Download von Apps und Updates, Play Store-APIs
gvt2.com und gvt3.com – Monitoring und Diagnose der Play-Konnektivität | play.google.com android.com google-analytics.com googleusercontent.com *.gstatic.com *.gvt1.com *.ggpht.com dl.google.com dl-ssl.google.com android.apis.google.com *.gvt2.com *.gvt3.com | |
TCP | 443 | EMM, Google APIs, PlayStore APIs, Android Management APIs | *.googleapis.com | |
TCP | 443 | Authentifizierung Ersetzen Sie bei accounts.google.[Land] den Platzhalter [Land] durch Ihre lokale Top-Level-Domain. Beispiel: Für Australien ist das accounts.google.com.au und für das Vereinigte Königreich accounts.google.co.uk. | accounts.google.com accounts.google.[Land] | |
TCP | 443, 5228-5230 | Google Cloud Messaging (GCM, z. B. Kommunikation zwischen EMM-Konsole und DPC wie das Übertragen von Konfigurationen) | gcm-http.googleapis.com gcm-xmpp.googleapis.com android.googleapis.com | |
TCP | 443, 5228–5230 | Firebase Cloud Messaging (z. B. „Mein Gerät finden“, Kommunikation zwischen EMM-Konsole und DPC wie das Übertragen von Konfigurationen). Aktuelle Informationen zu Firebase Cloud Messaging (FCM) | fcm.googleapis.com fcm-xmpp.googleapis.com firebaseinstallations.googleapis.com | |
TCP | 5235, 5236 | Bei Verwendung einer dauerhaften bidirektionalen XMPP-Verbindung zu FCM- und GCM-Servern | fcm-xmpp.googleapis.com gcm-xmpp.googleapis.com | |
TCP | 443 | Prüfung der Zertifikatssperrliste (Certificate Revocation List, CRL) nach von Google ausgestellten Zertifikaten | pki.google.com clients1.google.com | |
TCP | 443 | Domains, die von verschiedenen Backend-Diensten von Google verwendet werden, darunter Absturzberichte, Synchronisierung von Lesezeichen in Chrome und Synchronisierung der Uhrzeit (tlsdate) | clients2.google.com clients3.google.com clients4.google.com clients5.google.com clients6.google.com | |
TCP | 443 | Chrome-Updates | chromiumdash.appspot.com | |
TCP | 443 | Android Device Policy-Download-URL für die NFC-Bereitstellung | android.apis.google.com | |
TCP | 443 | Wird unter Android OS zur Konnektivitätsprüfung verwendet, wenn sich das Gerät mit einem WLAN oder Mobilfunknetz verbindet. | connectivitycheck.android.com www.google.com | |
TCP | 443 | Wird von OEMs verwendet, die GOTA-Updates (Google Over-the-Air) nutzen, um Over-the-air-Updates bereitzustellen. Erkundigen Sie sich bei Ihrem OEM, ob diese erforderlich sind. | ota.googlezip.net ota-cache1.googlezip.net ota-cache3.googlezip.net | |
TCP | 443, 5228–5230 | Lässt zu, dass Mobilgeräte eine Verbindung zu FCM herstellen, wenn eine Firewall im Netzwerk vorhanden ist (weitere Informationen). | mtalk.google.com mtalk4.google.com mtalk-staging.google.com mtalk-dev.google.com alt1-mtalk.google.com alt2-mtalk.google.com alt3-mtalk.google.com alt4-mtalk.google.com alt5-mtalk.google.com alt6-mtalk.google.com alt7-mtalk.google.com alt8-mtalk.google.com android.apis.google.com device-provisioning.googleapis.com | |
UDP | 123 | Während der Bereitstellung benötigen Android-Geräte Zugriff auf einen NTP-Server, auf den in der Regel über den Port UDP/123 zugegriffen wird. Dies kann von einem OEM geändert werden. | time.google.com | |
TCP | 443 | Safe Browsing-Endpunkte werden für Google Play Protect verwendet. | android-safebrowsing.google.com safebrowsing.google.com | |
TCP | 443 | Play EMM API (falls zutreffend – EMM-Anbieter fragen) Android Management API (falls zutreffend – EMM-Anbieter fragen) | www.googleapis.com androidmanagement.googleapis.com | |
TCP | 443 | Google Play Store Play Enterprise-Neuregistrierung | play.google.com www.google.com | |
TCP | 443 | iFrame JS Google Fonts Von Nutzern erstellte Inhalte (z. B. App-Symbole im Play Store) | fonts.googleapis.com *.gstatic.com | |
TCP | 443 | Kontoauthentifizierung Länderspezifische Domains für die Kontoauthentifizierung | accounts.youtube.com accounts.google.com accounts.google.com.* | |
443, 5228-5230 | Firebase Cloud Messaging (z. B. „Mein Gerät finden“, Kommunikation zwischen EMM-Konsole und DPC wie das Übertragen von Konfigurationen) | fcm.googleapis.com | ||
TCP | 443 | Zertifikatsvalidierung | crl.pki.goog ocsp.pki.goog | |
TCP | 443 | GCM, andere Google-Webdienste und iFrame JS | apis.google.com ajax.googleapis.com | |
TCP | 443 | App-Genehmigung | clients1.google.com payments.google.com google.com | |
TCP | 443 | iFrame-UI-Elemente | ogs.google.com | |
TCP | 443 | Desktop- und mobile Benachrichtigungen | notifications.google.com | |
TCP | 443 | Zero-Touch-Konsole | enterprise.google.com/android/* |
Hat diese Anleitung geholfen?