Solved

Problem configuring ISA for Blackberry Enterprise Server connection

Posted on 2008-06-13
8
1,452 Views
Last Modified: 2012-06-27
Hi everyone,

I've been looking at a solution for a couple of days now and i'm not able to find an answer, so i hope you guys can help me.

My Blackberry server is in my internal network behind the ISA server 2004.

I created an access rule :
Allow Port 3101 from my BES server to *.blackberry.net (srp address) for all users.

I saw a couple of discussions saying that it only needs that to work.  However, it doesnt.

I received the following error :
Denied Connection - A non-SYN packet was dropped because it was sent by a source that does not have an established connection with the ISA Server computer.

So, my Bes server is able to send the 1st request to the srp.na.blackberry.net but not the second or third...

Initiated Connection at 23:05:18
Log type : Firewall service
Status : The operation completed successfully
Rule : Allow Blackberry
Source : Internal (x.x.x.x:2300)
Destination : External (srp.na.blackberry.com 204.187.87.33:3101)
Protocol : Blackberry

Denied Connection at 23:05:26
Log type : Firewall service
Status : A non-SYN packet was dropped because it was sent by a source that does not have an established connection with the ISA Server computer.
Rule : -
Source : Internal (x.x.x.x:4982)
Destination : External (srp.na.blackberry.com 204.187.87.33:3101)
Protocol : Blackberry

I know it's not an issue on my blackberry server because it works if it's not behind the ISA.

Thank you to help me with this huge problem!
0
Comment
Question by:Vision_Globale
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 6

Expert Comment

by:Nyah247
ID: 21782042
I have the following firewall rule:

Allow > Blackberry In (3101 TCP Inbound)/Blackberry Out (3101 TCP Outbound) > BES IP/External to BES IP/External > All users.

It works for me.
0
 
LVL 6

Expert Comment

by:Nyah247
ID: 21782077
Worst comes to absolute worst you can run the firewall client on the BES Server but that is not recommended.  The firewall client should stay off the servers.  So...with that in mine, I would only try that if you are under serious fire to get it working and need a little time to troubleshoot.
0
 

Author Comment

by:Vision_Globale
ID: 21802924
Ok, i'll try that.

For the firewall client, i already tried that, but no success so i uninstall it.
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 

Author Comment

by:Vision_Globale
ID: 21848951
I made the following rule :

Allow > Blackberry IN (3101 Inbound)/Blackberry OUT (3101 Outbound) > Anywhere to Anywhere > All users.

It still doesnt work...
0
 
LVL 6

Expert Comment

by:Nyah247
ID: 21902929
Anything in the monitor when you try to make a connection?  Are they still the same as before?  
0
 

Author Comment

by:Vision_Globale
ID: 21916960
Still the same...

A non-SYN packet was dropped because it was sent by a source that does not have an established connection with the ISA Server computer.
0
 

Author Comment

by:Vision_Globale
ID: 22259167
I upgraded our BES server to 4.1.6 in case that was the cause of the problem... but still the same.
0
 

Accepted Solution

by:
Vision_Globale earned 0 total points
ID: 22450622
Weird problem... but solved!
It was the default protocol FTP that was changed and probably port configured were probably in conflict with the port 3101.  I remove the change made to the default protocol FTP and create another and now it works...
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have been asked to explain on many, many occasions the correct way to setup network cards and DNS settings on ISA Server 2004, 2006 and forefront Threat management gateway (FTMG) and have willing done so. I have also promised my self everytime tha…
On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question