Thanks for taking the time to reply, but I didn't ask how to block. I already have a blocking mechanism in place. I need to allow updates through.
Think.
I tried allowing apple.com but even their home page wouldn't load.
I think you have a different problem. Perhaps port 80 is blocked. Perhaps some other router in your network is blocking apple.com.
A diagnostic app might be of help. You need to do a trace route on apple.com Goto a public library to install.
https://itunes.apple.com/us/app/network-ping-lite/id289967115
https://itunes.apple.com/us/app/inettools-network-diagnose/id561659975?mt=8
Here are some common ports used by apple.
http://support.apple.com/kb/TS1629
mybe your dns server is blocked.
I like to use google for my dns server
8.8.8.8 or 8.8.4.4
ping google.
ping 74.125.228.2
apple like to run incognito so you will not see much with trace route