MDM Profile install fails outside our LAN
I'm attempting to enroll an iPad outside our organization's LAN. It's connected to the ATT cell network and is able to see our Profile Manager just fine. It sees our certificates and shows the various warnings, I go ahead and tap 'Install'. Then I tap 'Trust'. A key is generated. The certificate is enrolled. Then at the 'install profile' step it fails with a non-descript message of "Profile installation failed".
I monitor the logs on our MDM server and can see the iPad communicating.
The server log for devicemgrd.log reports incoming requests.
But something is happening after that. And, there's no log file indicating what's going on.
Before I go down the rabbit hole and trace TCP packets on our firewall, is there something more simple to check?
For example, is there something about our self-signed certificates? Or something else?
Thanks in advance.
iPad 2, iOS 9.3.5