About ports to open to communicate with APNs

I'm an engineer at an MDM vendor.
MDM push to devices via Apple Push Notification Service (APNs).

According to the document below, port 5223 needs to be opened in order for the device to communicate with APNs.

Does this port need to be open for both in and out?
Or should I only open out?

in : APNs → iOS Device
out: iOS Device → APNs

About ports to open to communicate with APNs