Actually, unless you have a very restrictive firewall, you only need outgoing initiated connection on RIM's port (I forget what it is off the top of my head... 3500-something maybe?). But you usually won't need to make any firewall modifications unless your BES is using NAT or something.
|