Re: Adding Rules for Blackberry ES to ISA 2000 - SOLVED



Thanks to Steve for the reply, unfortunately that was not a solution.

After much hair pulling, I finally detected that the blackberry process
was not performing as advertised in the manual, or as the three tech
support reps said. That is that the bbes required only port 3101,
outbound, initiated, pure nat to work.

I found that their connection actually initiated a connection on port
3101 to their server, and then their server "asked" for a connection on
another (random, ranged) port in the 34000 range.

So I modified my rules from what RIM doc & support emphatically states:
allow TCP 3101, any lan machine to any outside host :: allow host to
reply on 3101

TO a "cascaded dynamic" port rule:
allow TCP 3101, any lan machine to any outside host :: allow host to
reply on 3101
AND ONCE CONNECTED,
allow dynamic outbound AND
allow dynamic inbound

With this rule in place everything works fine

I called RIM support and after much discussion the 1st level rep put me
on hold for about 10 minutes and then came back and stated that the
escalation team confirms that this is actually true. It would be nice
if their documentation was technically correct, and even nicer if their
support reps had accurate information, or at least would check as i
requested on my first 3 calls to them.

Note that in order to get outbound bes to work on an isa server (when
running on the isa server itself) you must configure a packet filter
rule the same as the protocol rule

.



Relevant Pages

  • Re: Adding Rules for Blackberry ES to ISA 2000 - SOLVED
    ... I found that their connection actually initiated a connection on port ... any lan machine to any outside host:: allow host to ... Note that in order to get outbound bes to work on an isa server (when ...
    (microsoft.public.isaserver)
  • Re: setting up RD without a VPN connection ?
    ... Remote Desktop only needs TCP Port 3389. ... > The PC in Brazil (the host) is connected via radio internet connection. ... The client cannot connect to the host. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: SMPT inbound not working
    ... Have you tried with the setting "Requests appear to come from the ISA Server ... > than the fact it was working prior to an upgrade. ... > from an external IP I recieve a connection failed. ... In fact the only port I seem to be ...
    (microsoft.public.isaserver)
  • Re: Socket error when restarting host app
    ... TCP includes a mechanism to ensure that packets delayed by the network will ... not be accepted by another connection to the same host and port combination. ...
    (microsoft.public.dotnet.framework.remoting)
  • ICS and port-forwarding
    ... Does port forwarding work in XP? ... internet connection sharing features work fine, ... One client computer is running a web-server, and the host ... the client web-serving machine, the web server is ...
    (microsoft.public.windowsxp.network_web)