PDA

View Full Version : OS 4.2 Firewall/IT policy? Help!


Sk8Surfr
04-19-2007, 10:27 AM
Installed 4.2

Now i cant disable firewall!!! It's locked!

And when I try and run jivetalk it says "program trying to open connection inside/outside firewall which is not allowed by your IT policy"

I dont have an IT policy! I'm on a BIS... what gives!? It didnt do this on 4.1

swellest
04-19-2007, 12:52 PM
I got the same error on my 8100 and I have no IT policy. I'm pretty sure I've used it successfully since the last upgrade so I presumed it was a problem with Jive Talk, not my device.

CBR900RR
04-19-2007, 05:39 PM
Installed 4.2

Now i cant disable firewall!!! It's locked!

And when I try and run jivetalk it says "program trying to open connection inside/outside firewall which is not allowed by your IT policy"

I dont have an IT policy! I'm on a BIS... what gives!? It didnt do this on 4.1

Did you bought you phone used?
Sounds like it has the IT policy before and somebody wipe the policy with the instruction post here, and the firewall is lock to enable.
Are you sure you can disable firewall before the upgrade?
Try edit the application permission to allow jivetalk.

acnst
04-19-2007, 06:30 PM
Did you try to configure the Application permissions for your apps under Options->Advanced Options->Applications. Just select the application and open the menu - you should see an entry called "Application Permissions" (or similar)

Sk8Surfr
04-19-2007, 08:11 PM
Did you bought you phone used?
Sounds like it has the IT policy before and somebody wipe the policy with the instruction post here, and the firewall is lock to enable.
Are you sure you can disable firewall before the upgrade?
Try edit the application permission to allow jivetalk.

No, phone has always been mine. It WAS on a BES... but i got the phone swapped through warranty.

I've been using it forever with 4.1 and i never had an issue.. and my firewall wasnt enabled before i upgraded.

I'll try and put a blank one on it.

John Clark
04-19-2007, 08:13 PM
If you can't change the firewall now, the blank IT policy won't help. I've tried. The policy is different from the firewall.

kbetzing
06-12-2007, 12:59 PM
If you can't change the firewall now, the blank IT policy won't help. I've tried. The policy is different from the firewall.

Did you ever get this fixed. I am having the same problem.

abbstrack
06-20-2007, 08:35 PM
i too am having this problem, but it is with YakOn, not jivetalk. This occured after updating my YakOn from 1.10 to 1.22. I never had any problems before.

I just sent a note to YakOn's support team.

juwaack68
06-20-2007, 08:45 PM
Have you tried resetting the firewall? I had a user today who couldn't access a 3rd party app and after restarting the firewall it worked fine.

abbstrack
06-20-2007, 10:50 PM
if by resetting the firewall you mean going into options, security options, firewall, and then reset settings or reset all counts, than yes i have tried that.

if there is another way to reset the firewall please let me know.

thanks.

AXS
06-21-2007, 11:15 PM
I had a similar problem. My BB once had an IT policy, which I replaced by a blank one after leaving my employer. I experienced the same error message that you describe. The idea is that an application is trying to open a connection internal to the firewall while simultaneously opening another one reaching outside the firewall. This is a referred to as a "split pipe" and since it is a security risk, it is disabled by the IT policy. Therefore it actually has to do with split pipes but involves the firewall, hence the confusing reference to a firewall issue.

I fixed the problem by editing the blank policy to allow split pipes:

; Policies that control the behaviour of third party applications
; on Java-based handhelds.
AllowThirdPartyUseSerialPort {policy} = true
AllowExternalConnections {policy} = true
AllowInternalConnections {policy} = true
AllowSplitPipeConnections {policy} = true
DisallowThirdPartyAppDownloads {policy} = false


and by reloading the bew blank policy onto my BB.

See also the following faq: Shark Modem Blackberry Modem: Shark Modem FAQS (http://www.mobishark.com/faqs.htm) almost at the end of the list for an alternative approach.

Hope this helps,
-axs

John Clark
06-21-2007, 11:21 PM
I believe the policy.bin posted in the Remove IT Policy sticky has the split pipe connection set to true.

@<hidden>,
Any idea how to re enable keystroke injection when it's been previously disabled by a previous IT policy?

jetspeedz
06-22-2007, 10:01 AM
John you sure about the blank IT policy not working.. when i was on BES and still am now i tested the blank policy and was allowed to disable firewall and as soon as i got on it pushed the company IT policy back on which was enabled... the blank IT policy should allow you to disable it if im not mistaking.

John Clark
06-22-2007, 11:26 AM
I haven't treid the IT policy.bin file on anything with 4.2 OS on it. It may allow you to "enable" the firewall. What it won't do is allow Application Permissions that have been restricted by the previous BES such as "keystroke injection" and "Browser Filter." Those are the only two items that my company's BES disallows (I don't even need a password.) Nobody that I know of has been able to unlock keystroke injection if it's been locked by a previous BES. With Keystroke injection disallowed it prevents use of a Bluetooth Keyboard.

ajv
07-17-2007, 03:35 PM
So I assume that there is a possibility that the firewall could be "disabled" using the blank policy with the 4.2+ OS? Could someone confirm this? John, even with the firewall disabled, I presume you are referring to the application permissions section under "security options" and not necessarily the firewall? Has anyone loaded the blank policy on a 8830 with any success at changing keystroke injection settings?

John Clark
07-17-2007, 03:37 PM
There is NO way to open the keystroke injection settings without reconnecting to a BES.

ajv
07-17-2007, 04:51 PM
Are there manuals that would show a BES admin how to do this? Available online? My BES admin does not know how. I have seen some application permission specific instructions for certain keyboard apps, but have not seen any reference to the global firewall settings.

vothelo
11-16-2007, 04:36 PM
So, does this mean that the blank IT policy on 4.2 WILL allow the firewall to be "disabled"??? Has anyone tried this? I am one of those who has the firewall locked and can't get jivetalk to work, keep getting the 2x firewall error message...really frustrating.

If anyone has tried it, appreciate a comment...don't feel like going through the hassle of wiping only to find out it didn't work...actually now that I think about it, my 8830 was on BES for a short time and then I removed my companies policies when I took it off BES back to BIS, and I'm pretty sure the firewall was still locked...hmmm, but then again jivetalk worked so who knows...do I sound frustrated? LOL

Vilmar.Ghizelini@comcast.
11-16-2007, 04:43 PM
Hello! I just faced this problem today. I have a 8700c 4.2 and I could not disable the password or disable the firewall. I used the blank IT policy and it allowed me to disable the password but not the firewall.

vothelo
11-16-2007, 10:23 PM
Thanks for the info...on one hand you saved me alot of time, on the other you just destroyed my last final hope! LOL...how the heck can I get jivetalk to run on an new, unlocked, never been on BES 8320???

Julio

CBR900RR
11-16-2007, 11:39 PM
OS 4.3 should be out before end of this year and you can put you BB back to the orginal state.

Just uploaded a new version of JL_Cmder!

Now includes the resettofactory command. This command removes the IT policy from the device (OS 4.3+ required). Also note that after the resettofactory command has been run the device must be wiped. Backup your data first!

tgray
01-21-2008, 01:47 PM
As FYI.

I pushed a blank ITPOLICY to my BlackBerry 8310 and was UNABLE to change the Firewall setting to Disabled.

I have a new BlackBerry 8310 that has never been on the BES. The device is new and direct from AT&T (not a warranty replacement). The firewall is set to Enabled and I am unable to change it to Disabled.

John Clark
01-21-2008, 01:58 PM
Just an IT policy will not change the firewall settings once it's been connected to a BES.

Did you connect your 8310 to the same Desktop Manager that you connect your other 8310 to? If so, it's likely you have the same policy on the new 8310 now.

tgray
01-21-2008, 02:41 PM
*Removed my comments because they didn't make any sense.*

Sometimes I just get too excited when I post on here!

John Clark
01-21-2008, 03:09 PM
Huh? You lost me.

toemaytoe
01-23-2008, 02:41 AM
I've had the same error message for months now but I get it with mobipocket. I haven't been able to use mobipocket for some time. I'm also on their forum but they haven't been able to come up with a solution. I personally think that the problem started with my upgrading of my OS to 4.2 I've noticed problems with several other programs as well. I'm hoping that 4.3 comes out soon and solves these issues. Is there any word on when it will be released?

tgray
02-06-2008, 12:27 PM
Well crap.

I ended up replacing my BB because I couldn't get the firewall issue to resolve itself and JiveTalk wouldn't work.

So today I plugged in my BB to my laptop where I had already configured the registry to point to the blank policy.bin file. And what happens?....

It forces the new BB to have an enabled firewall with no way to remove it! GRRRRRR. I should have removed the blank policy.bin! Now I'm screwed again!

tgray
02-06-2008, 12:40 PM
Okay...

I downloaded a new copy of the policy.bin file (the one John Clark is hosting). It seemed to be less restrictive than the one that was originally hosted on ig3.net. I followed the instructions John provided and now, thankfully, the split pipe connection value seemed to have fixed my JiveTalk issue for now at least.

Thanks for providing the policy John. I still cannot change my firewall back to disabled yet, but maybe by the time I find the next app that requires it to be enabled, I will have a new device.

spiggy
02-15-2008, 06:07 AM
Hi all

Got myself a Jivetalk license afterall, but after some minutes of inactivity, I get an 401 Unauthorised message. Suppose it is related to the proxy, cause when I browse to a new webpage wit the BB browser, all is ok for some minutes again.

I'm after a BES. Can I solve this in the proxy policy ?

Thx. Have a nice weekend...

Peter