BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 02-02-2009, 11:51 AM   #1
bdj6020
Knows Where the Search Button Is
 
Join Date: Apr 2005
Model: 9000
Carrier: AT&T
Posts: 32
Default Potential BES circumvention

Please Login to Remove!

I'm moving this thread over here. This is the referenced post:

http://www.blackberryforums.com/gene...ml#post1268336

Essentially it describes how to enter your Exchange OWA credentials into the BIS server and thus circumventing having to attach your BB to a BES.

Does anyone know of a way to block this sort of activity? We don't want our BB users accessing exchange anyway other than via the BES connectivity. We certainly don't want them storing their passwords and userIDs at a 3rd party site like this.

Thanks
Offline  
Old 02-02-2009, 11:55 AM   #2
TargetIT
CrackBerry Addict
 
Join Date: Jan 2008
Model: 9700
PIN: N/A
Carrier: Rogers
Posts: 709
Default

You have to block the IP's of the carriers at your firewall. I believe there's a list of them somewhere on this site.
Offline  
Old 03-10-2009, 08:24 AM   #3
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default

here is list of IP's and servers used by BIS, you block them on your firewall or use ISA to publish OWA, BIS wont pssthrough ISA (known RIM issue)

View Document

Last edited by SoUnCool; 03-10-2009 at 09:48 AM..
Offline  
Old 03-10-2009, 09:15 AM   #4
dpeters11
Talking BlackBerry Encyclopedia
 
Join Date: Oct 2004
Model: 9530
Carrier: Verizon
Posts: 302
Default

If these are blocked at the firewall, users would still be able to use BIS on their device for personal email accounts right?
Offline  
Old 03-10-2009, 09:54 AM   #5
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default

Quote:
Originally Posted by dpeters11 View Post
If these are blocked at the firewall, users would still be able to use BIS on their device for personal email accounts right?

yes right, you cannot stop them from getting personal emails

if their devices are on your BES< you can setup IT policy to use only your email service, in this way they wont be able to reply using BIS provided email service, i think the policy is in service exclusivity group > other message services, once this is set to false they can only use your BES provided email server to send outgoing emails,

no stopping for BIS incoming emails from gmail, hotmail or any other web mail
Offline  
Old 03-10-2009, 10:06 AM   #6
DavidAdams
Talking BlackBerry Encyclopedia
 
DavidAdams's Avatar
 
Join Date: Sep 2007
Location: Belfast
Model: NotYe
PIN: N/A
Carrier: O2
Posts: 470
Default

Unfortunately I suspect the OP's end users aren't on the BES in the first place and so a policy can't be sent. If they are on the BES why connect via OWA/BIS as well? Sorry we are Domino here, so my OWA knowledge is limited, and also we have absolutely no access into our mail from outside that is not through a VPN, an account for which requires several signatures.
__________________
BES, 4.1.7, was SBE now full BES
Domino v7.0.2
Windows Server 2003, standalone
Offline  
Old 03-10-2009, 10:09 AM   #7
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default

Lucky you that you have a controlled envoirnment

we have OWA , and VPN and Citrix gateway too many ways for a user to get access

few of our users started to use their personal BB device on BIS via OWA and we had to stop them using firewall block
Offline  
Old 03-10-2009, 10:44 AM   #8
WMedley
Thumbs Must Hurt
 
WMedley's Avatar
 
Join Date: Feb 2005
Location: Boston, MA
Model: 9530
OS: 4.0.7.114
Carrier: Verizon
Posts: 126
Default

Quote:
Originally Posted by SoUnCool View Post
Lucky you that you have a controlled envoirnment

we have OWA , and VPN and Citrix gateway too many ways for a user to get access

few of our users started to use their personal BB device on BIS via OWA and we had to stop them using firewall block
You know. If it wasn't for those pesky end users our jobs would be easy!!!
__________________
William Medley
Messaging Engineer
IBM/Lotus Collaboration Technologies
Offline  
Old 03-10-2009, 12:03 PM   #9
knottyrope
BlackBerry Elite
 
knottyrope's Avatar
 
Join Date: Jan 2008
Location: Massachusetts
Model: DT60
OS: 123456789
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Posts: 7,325
Default

Quote:
Originally Posted by WMedley View Post
You know. If it wasn't for those pesky end users our jobs would be easy!!!

you would have no job if that were true
__________________
I had to fall
To lose it all
But in the end
It doesn't even matter

Rocking the Motion with out lotion.
Offline  
Old 03-10-2009, 12:59 PM   #10
WMedley
Thumbs Must Hurt
 
WMedley's Avatar
 
Join Date: Feb 2005
Location: Boston, MA
Model: 9530
OS: 4.0.7.114
Carrier: Verizon
Posts: 126
Default

Quote:
Originally Posted by knottyrope View Post
you would have no job if that were true
True.
__________________
William Medley
Messaging Engineer
IBM/Lotus Collaboration Technologies
Offline  
Old 03-10-2009, 01:14 PM   #11
knottyrope
BlackBerry Elite
 
knottyrope's Avatar
 
Join Date: Jan 2008
Location: Massachusetts
Model: DT60
OS: 123456789
PIN: t of blood has been taken
Carrier: AT&T-US with I dee ten tee errors
Posts: 7,325
Default

WORD

Peace out
__________________
I had to fall
To lose it all
But in the end
It doesn't even matter

Rocking the Motion with out lotion.
Offline  
Old 03-12-2009, 10:57 AM   #12
jyindc
Knows Where the Search Button Is
 
Join Date: Aug 2007
Model: 8800
PIN: N/A
Carrier: t-mobile
Posts: 18
Default

Just out of curiosity, why do you want to block OWA on staff personal blackberries. In your firm, is OWA not normally available to regular staff, or is there an additional security concern for OWA on handhelds?
Offline  
Old 03-12-2009, 11:03 AM   #13
TargetIT
CrackBerry Addict
 
Join Date: Jan 2008
Model: 9700
PIN: N/A
Carrier: Rogers
Posts: 709
Default

Well one reason is that if the personal BB is compromised, and it's not on BES, you can't wipe it, you can't lock it. You have no control over it.
Offline  
Old 03-12-2009, 11:05 AM   #14
Frank Castle
BlackBerry Extraordinaire
 
Frank Castle's Avatar
 
Join Date: Jul 2005
Location: MA
Model: 9930
PIN: PM Me!
Carrier: VZW
Posts: 1,073
Default

it's not persay OWA access via the browser. BIS uses OWA as a means to pull email to the device.
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Johnson Controls MS-VMA1630-1 VMA ProgrammableVAV Box Controller picture

Johnson Controls MS-VMA1630-1 VMA ProgrammableVAV Box Controller

$145.00



USED Johnson Controls P66BAB-1C Condenser Fan Speed Control  picture

USED Johnson Controls P66BAB-1C Condenser Fan Speed Control

$134.99



Johnson Controls M300MJ picture

Johnson Controls M300MJ

$45.00



JOHNSON CONTROLS  PNEUMATIC ADJUSTMENT FLEX SCREW DRIVER JC 5309 JC-5309 JC5309 picture

JOHNSON CONTROLS PNEUMATIC ADJUSTMENT FLEX SCREW DRIVER JC 5309 JC-5309 JC5309

$24.00



Johnson Controls P32AC-2C Sensitive Differential Pressure Switch NIB New picture

Johnson Controls P32AC-2C Sensitive Differential Pressure Switch NIB New

$39.99



JOHNSON CONTROLS 2951J PHOTOELECTRIC SMOKE DETECTOR USA STOCK picture

JOHNSON CONTROLS 2951J PHOTOELECTRIC SMOKE DETECTOR USA STOCK

$34.75







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.