BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 10-19-2007, 04:40 PM   #1
Truestream
Knows Where the Search Button Is
 
Join Date: Apr 2007
Location: Vancouver, BC, Canada
Model: 8800
Carrier: Rogers
Posts: 20
Default Firewall Ports?

Please Login to Remove!

Ok, I've searched around and all I've found is port 3101.

Let's say that you've got a last resort software firewall installed on the BES itself, what ports would I need to setup rules for in order for it to work properly with Exchange 07.
Offline  
Old 10-19-2007, 05:56 PM   #2
x14
BlackBerry Extraordinaire
 
Join Date: Jul 2005
Location: NYC
Model: 9800
OS: 6.0.0.546
Carrier: AT&T
Posts: 2,344
Default

No matter what kind or how many fw you have, you need 3101 to the SRP.
__________________
Exchange 2007/BES 5.0.2 MR2
Offline  
Old 10-19-2007, 05:57 PM   #3
southwestcomm
BlackBerry Extraordinaire
 
Join Date: Jan 2005
Model: Many
Carrier: Sprint
Posts: 1,475
Default

Firewall on the BES? Isn't behind your corporate firewall or did you stick the box in your DMZ?
Offline  
Old 10-19-2007, 06:09 PM   #4
x14
BlackBerry Extraordinaire
 
Join Date: Jul 2005
Location: NYC
Model: 9800
OS: 6.0.0.546
Carrier: AT&T
Posts: 2,344
Default

Quote:
Originally Posted by southwestcomm View Post
Firewall on the BES? Isn't behind your corporate firewall or did you stick the box in your DMZ?
Actually, one of the extreme security recommendation is to put each of the BES component behind a firewall and only allow the that component to talk to the next component.
__________________
Exchange 2007/BES 5.0.2 MR2
Offline  
Old 10-19-2007, 08:57 PM   #5
Truestream
Knows Where the Search Button Is
 
Join Date: Apr 2007
Location: Vancouver, BC, Canada
Model: 8800
Carrier: Rogers
Posts: 20
Default

It is behind a firewall and out of the DMZ, but this is a last resort, kind of emergency measure we're testing out. I'm well aware of port 3101 to the SRP, but are there any other specific ports I'll need to setup rules for so that I can communicate with the Exchange Server (it's 07). Thanks.
Offline  
Old 10-19-2007, 10:01 PM   #6
penguin3107
BlackBerry God
 
penguin3107's Avatar
 
Join Date: Jan 2005
Model: iOS 5
Carrier: VZW
Posts: 11,701
Default

Quote:
Originally Posted by Truestream View Post
It is behind a firewall and out of the DMZ, but this is a last resort, kind of emergency measure we're testing out. I'm well aware of port 3101 to the SRP, but are there any other specific ports I'll need to setup rules for so that I can communicate with the Exchange Server (it's 07). Thanks.
Isn't your Exchange server on the same LAN as as your BES?
Why would you need a firewall between the two?
Honestly... I think you're making a mistake putting a software firewall on your BES. Seems like your overcomplicating your security model for no good reason.
Even if you absolutely insist on putting software firewall on a LAN server... why the BES? Wouldn't it make more sense to firewall the Exchange box? That's really where you'd want more protection against a hack anyway.

If you do indeed have a firewall between your BES and Exchange box.. then there's definitely going to be ports to open up to allow communication between the two servers.
Couldn't tell you what they are, since I don't know much about Exchange and this would also be the first time I've ever heard of anyone doing what you intend to do.

Doesn't make a whole lot of sense to me.
__________________
BCSA
BES 5.0.3 MR4 :-: Exchange 2007 SP3 RU3
http://port3101.org

Last edited by penguin3107; 10-19-2007 at 10:03 PM..
Offline  
Old 10-19-2007, 10:41 PM   #7
Truestream
Knows Where the Search Button Is
 
Join Date: Apr 2007
Location: Vancouver, BC, Canada
Model: 8800
Carrier: Rogers
Posts: 20
Default

Well, it isn't my idea, I was just asked to make it happen. I don't really have a choice in the matter, I totally agree that setting up a software firewall on the BES is absolutely useless.
Offline  
Old 10-20-2007, 09:27 AM   #8
Drork
Knows Where the Search Button Is
 
Join Date: Mar 2005
Model: 8707
Carrier: Orange Israel
Posts: 22
Default

hi
as far as I know you only need to open the srp port in fw goining out (LAN->Internet) meening no trafic from the interner can come in so there is no reson ading a software fw to the machine.
Offline  
Old 10-20-2007, 05:09 PM   #9
hdawg
BlackBerry Genius
 
hdawg's Avatar
 
Join Date: Aug 2006
Model: hdawg
PIN: port3101.org
Carrier: hdawg
Posts: 6,632
Default

In addition to 3101 Outbound initiated to srp.na.blackberry.net you'll need any port open that an Outlook client would need open to an Exchange mailbox server.

You'll also need requisite ports for Domain Controller / Global Catalog access, and access to SQL Server (port 1433 by default).
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


MATRIX SYSTEMS SWITCH RADIO FREQUENCY MFR/PN 7705DRRIS picture

MATRIX SYSTEMS SWITCH RADIO FREQUENCY MFR/PN 7705DRRIS

$299.00



Lot of 50 HDW-IMP-80 Imprivata RF IDEAS Radio Frequency Proximity Reader picture

Lot of 50 HDW-IMP-80 Imprivata RF IDEAS Radio Frequency Proximity Reader

$375.00



19 pieces Raycom Radio Frequency Coil p/n SM-C-877265  PE110736  New  picture

19 pieces Raycom Radio Frequency Coil p/n SM-C-877265 PE110736 New

$592.54



Honeywell Radio Frequency Combo NG Control RV8310E4002 ,3103GG picture

Honeywell Radio Frequency Combo NG Control RV8310E4002 ,3103GG

$55.00



RF Radio Frequency Cautery High Electro Electrosurgery Surgical Generator Set picture

RF Radio Frequency Cautery High Electro Electrosurgery Surgical Generator Set

$299.00



AngioDynamics Rita Model 1500x RF Radio Frequency Surgical Generator picture

AngioDynamics Rita Model 1500x RF Radio Frequency Surgical Generator

$299.00







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.