Profile Manager uses certain ports for device enrollment and management. 

To use Profile Manager, you should make sure that the following ports are open on your network.

Incoming or Outgoing

2195, 2196 Outgoing TCP Used by Profile Manager to send push notifications
5223 Outgoing TCP Used to maintain a persistent connection to APNs and receive push notifications
80/443 Incoming TCP Provides access to the web interface for Profile Manager admin
1640 Incoming TCP Enrollment access to the Certificate Authority

