BlackBerry Forums Support Community

BlackBerry Forums Support Community (http://www.blackberryforums.com/index.php)
-   BES Admin Corner (http://www.blackberryforums.com/forumdisplay.php?f=21)
-   -   BES Router in DMZ configuration (http://www.blackberryforums.com/showthread.php?t=161962)

Bryan Peas 11-27-2008 12:23 PM

BES Router in DMZ configuration
 
I currently have a BES V4.1.6 installed on my internal network with all the components sitting on one server. After reading further into the RIM documentation i realized that placing the router in a DMZ was far more secure.

i intend to install the router between two firewalls.

Currently port 3101 is opened for SRP outbound and BB service connection Inbound, what changes of ports are required to allow the BB router to communicate with the BES. Take into account i want to change the port number between the router and BES.

Thanks .....Bryan

Jadey 11-27-2008 12:27 PM

Moved to BES Admin Corner, better chance of replies there...

Bryan Peas 11-27-2008 01:18 PM

Thanks Jadey.

CanuckBB 11-27-2008 02:29 PM

Quote:

Originally Posted by Bryan Peas (Post 1186013)
Currently port 3101 is opened for SRP outbound and BB service connection Inbound, what changes of ports are required to allow the BB router to communicate with the BES. Take into account i want to change the port number between the router and BES.

Thanks .....Bryan

What is that BB service connection that you speak of????

All you need for BES is 3101 outbound. BES initiates contact, only and always.
Never did figure out how the router in the DMZ made it more secure.

Actually, I never did figure how the whole DMZ was more secure unless the server in the DMZ ahs no NIC pointing towards the inside firewall. I figured that if the hacker was good enough to breach the first firewall, he'll propably be good enough to breach the second one...

x14 11-27-2008 02:44 PM

Quote:

Originally Posted by CanuckBB (Post 1186170)
Actually, I never did figure how the whole DMZ was more secure unless the server in the DMZ ahs no NIC pointing towards the inside firewall. I figured that if the hacker was good enough to breach the first firewall, he'll propably be good enough to breach the second one...

It's not penetrating the firewall it's hacking the BlackBerry Router component.

The idea is if the BlackBerry Router was on the LAN and someone hacks it they would have access to the resources on the LAN.

If the BlackBerry Router was in a DMZ and someone hacks it they have access to nothing.


All times are GMT -5. The time now is 01:37 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.