Topic
This article lists the Apple services that connect to iCloud Private Relay hosts and explains what to change in ControlOne when those connections are blocked.
Environment
- Cytracom ControlOne
- iPhone, iPad, Mac and Apple Vision Pro running iOS 27 and later, or the matching iPadOS, macOS and visionOS releases
Description
Symptom
Apple Intelligence features such as the new Siri show an error like "Sorry, something's wrong. Please try again" on a network protected by ControlOne. Security session reports show Blocked sessions to mask.icloud.com or mask-api.icloud.com, and the Proxy avoidance category is the cause.
Hosts involved
Apple's enterprise network article lists these three iCloud Private Relay hosts:
- mask.icloud.com (UDP 443)
- mask-h2.icloud.com (TCP 443)
- mask-api.icloud.com (TCP 443)
Apple documents these hosts for iCloud Private Relay, which protects Safari browsing, and doesn't say which Apple Intelligence features depend on them. On iOS 27 and later, and the matching iPadOS and macOS releases, we've seen Siri fail with the error above while these hosts were blocked. Community reports also show that blocking mask-api.icloud.com breaks Apple Intelligence features such as Safari summaries.
Apple's Private Cloud Compute uses separate relay hosts: apple-relay.cloudflare.com, apple-relay.fastly-edge.com and cp4.cloudflare.com. Apple Intelligence Extensions use apple-relay.apple.com. Allow those as well if the problem continues.
Why ControlOne blocks them
Private Relay sends traffic through two relays, so the network can't see the destination site or the DNS lookup. That is the behavior the Proxy avoidance category is meant to stop, and the Content filtering levels article lists which levels block that category. Apple's own guidance for networks that don't want Private Relay is to block mask.icloud.com and mask-h2.icloud.com, and users then see a prompt to turn Private Relay off for that network.
Concerns before you allow these hosts
- Anyone on the policy who has iCloud+ and Private Relay turned on can send Safari traffic through the relay. ControlOne then sees only an encrypted connection to Apple, so category filtering and destination logging don't apply to that traffic.
- Allowing the hosts in a policy affects every zone that uses the policy. Put the Apple devices that need this on their own policy and zone.
- Changing the policy to permit VPN traffic is broader than an exclusion, because it unblocks every proxy and VPN service and not only Apple's. Use exclusions first.
- Apple states that its services fail when HTTPS inspection is applied to these hosts, so don't inspect them.
Procedure
1. Add an exclusion for each of the three hosts above, with Allow selected and Include Subdomains? turned on.
2. Assign the policy to the zone that holds the affected devices.
3. Retest the feature after the change.
Additional Resources
- ControlOne: Excluding a Site from a Security Policy
- Cytracom ControlOne: Content filtering levels
- Cytracom ControlOne: Adding a custom security policy
- Adding Custom Security Policy to a Zone
- Apple: Use Apple products on enterprise networks
- Apple: Prepare your network or web server for iCloud Private Relay