Get trough filtered port

I have a very important device on my network that I have no access to.

I have nmapped the device and all I see is a filtered port 80. So there is probably some web access. It is almost certainly filtered on the host.

Is there any elegant way to figure out to which IP addresses it filters?

