I have a 1811 router on which I am using the firewall feature set. We currently have one blackberry enterprise server (server1=192.168.0.2 LAN, xx.yy.zz.230 WAN) in the LAN behind this firewall which is functioning well.
We would like to add a 2nd blackberry server (server2=192.168.0.3 LAN, xx.yy.zz.231 WAN) for a separate domain.
The blackberry Enterprise server docs indicate that port 3101 TCP is the one that needs to be open between the BES and the WAN. The BES opens this port outbound and maintains the TCP connection.
Here is the current relevant ACL line:
access-list 102 permit tcp any host xx.yy.zz.230 eq 3101
I am thinking I need to change this to:
access-list 102 permit tcp any any eq 3101
I am also NATting that port to the existing BES machine, so I believe I will have to remove this nat statement as well
What I am expecting is that these changes will permit both of these Blackberry Enterprise Servers to communicate with the blackbryy infrastructure in order to push email to devices in their respective domains.
Could anyone confirm that the changes I am proposing are correct given the intended goal?
This document gives several answers on frequently asked questions for PFRv3 channel state behavior.
Q1: What are all the channel operational states from a BR (border role) perspective and what are the rules/conditions to be in each st...
The need was to reach an host inside a LAN through a VPN connection managed by the LAN gateway (Cisco 1921).
The LAN gateway performs NAT and there was a dedicate nat rule for the host i wanted to reach through VPN.
I couldn't connect to the hos...
We have 3 identical switches configured by someone else and would like to claim some of the Gigabit ports(G1/G2/G3/G4) for use on servers. When we try to change the wiring and configuration, we run in to connectivity issues. Attached is a des...