APNS on a PCI network

Does use iOS devices on a secure PCI network? If so, can you tell me what you have done to allow APNS to communicate with those devices? Did you open your firewalls to allow communication to Apple's entire network as many MDM providers suggest? Or did you only open it to Apple's APNS URLs?

1-courier.push.apple.com 5223
gateway.sandbox.push.apple.com 2195
gateway.push.apple.com 2195

i cannot fathom opening our firewall to the entire class A network - even if it is all owned by Apple. That's over 16.5 million IP addresses!

