BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 10-23-2007, 08:19 AM   #1
Wiseass
Talking BlackBerry Encyclopedia
 
Join Date: Sep 2005
Location: Illinois
Model: 9850
PIN: k Floyd \m/ ROCK!
Carrier: VZW
Posts: 249
Default BES/Notes admins...Comcast blocking port 1352?

Please Login to Remove!

I just saw this article.

Link to Infoweek

Quote:
Originally Posted by article
As if the AP's report last week wasn't enough, it looks like Comcast is blocking other online services, including Gnutella, FTP, and even Lotus Notes. I guess Comcast doesn't respect the needs of telecommuters or net neutrality.
Quote:
Originally Posted by article
And let's drill down to Kevin Karnarski's post on Notes and Comcast:

I finally have an end-to-end trace to share which shows that Comcast is filtering the port 1352 traffic. The images below show that Comcast is impersonating and using man-in-the-middle tactics to filter the traffic as stated in the CNet post. The images show a network packet trace from the client side and from the server side during the same session. This was a new memo composed within Notes with a 6-Mbyte attachment and then saved as a draft to the server database. The transfer did not succeed.

So I guess Comcast subscribers can't work from home now either?
My question is to those of you who are Lotus Notes admins, is this severely going to affect you if it's true? I haven't encountered this yet, however we have about 1300 sales people across the country that use their personal internet connection (Comcast/ATT/etc) to connect to our email server. Mainly because we push custom databases down to them, also the web interface is just flat out clunky if you ask me.

I don't know if this belongs in this section, but I am the email/blackberry admin for my company, and I can see this greatly affecting us.

Anyone else got thoughts on this?
__________________
"I dont feel I need to explain my art to you Warren"
Offline  
Old 10-23-2007, 09:20 AM   #2
Jadey
BBF War Game Mod
 
Jadey's Avatar
 
Join Date: Oct 2006
Location: Denver CO
Model: Z10
OS: 10010614
PIN: SEEKRIT innit
Carrier: AT&T
Posts: 4,294
Default

Thank goodness they're not a UK ISP
__________________
Jadey : Infrastructure Architect, Denver CO
Offline  
Old 10-23-2007, 11:37 AM   #3
Ugg
Thumbs Must Hurt
 
Join Date: Dec 2006
Model: 8310
OS: 4.5
Carrier: O2
Posts: 197
Default

My first thought was "wouldn't you want to be doing this sort of thing over a VPN connection anyway?". Of course, the ISP can still block that (I've had "discussions" with an ISP where VPN traffic was put in the slow lane with all the P2P traffic).
Offline  
Old 10-23-2007, 11:42 AM   #4
penguin3107
BlackBerry God
 
penguin3107's Avatar
 
Join Date: Jan 2005
Model: iOS 5
Carrier: VZW
Posts: 11,701
Default

Quote:
Originally Posted by Wiseass View Post
My question is to those of you who are Lotus Notes admins, is this severely going to affect you if it's true? I haven't encountered this yet, however we have about 1300 sales people across the country that use their personal internet connection (Comcast/ATT/etc) to connect to our email server. Mainly because we push custom databases down to them, also the web interface is just flat out clunky if you ask me.

I don't know if this belongs in this section, but I am the email/blackberry admin for my company, and I can see this greatly affecting us.

Anyone else got thoughts on this?
Why would you have port 1352 open to the public?
You don't require a secure connection to your Domino server for remote users?

Our remote users are required to use a VPN to connect to Domino.
__________________
BCSA
BES 5.0.3 MR4 :-: Exchange 2007 SP3 RU3
http://port3101.org
Offline  
Old 10-23-2007, 11:46 AM   #5
x14
BlackBerry Extraordinaire
 
Join Date: Jul 2005
Location: NYC
Model: 9800
OS: 6.0.0.546
Carrier: AT&T
Posts: 2,344
Default

I'm with penguin3107.
__________________
Exchange 2007/BES 5.0.2 MR2
Offline  
Old 10-24-2007, 01:41 PM   #6
Aroc
CrackBerry Addict
 
Join Date: Jul 2005
Location: Solon, OH, USA
Model: 9000
OS: 4.6.0.167
PIN: 20878533
Carrier: ATT
Posts: 708
Default

The Notes client and Domino server support encrypted communications. That along with enabling "Compare Notes public keys against those stored in Directory" should keep you mostly protected. I have no qualms about leaving 1352 open to the outside world in that case since the attacker would need a valid, certified user ID file (and a valid password for that file).

As for the original post, yes, we too are starting to see port TCP 1352 being blocked more and more these days. Strangely some hotels (outside north america) may block TCP 1352 from guest rooms, but that port may be wide-open in the common lobby areas. We're also seeing the same thing (TCP 1494, TCP 2598 etc for Citrix) on other ports. It seems that in some cases a lot of traffic other than the known web ports are starting to be blocked with increasing frequency. Add to that some places that appear to drop IPsec traffic, effectively killing VPN. So sometimes even opening a VPN tunnel back to the office does not work.

But in all fairness, the frequency of seeing IPsec traffic (VPN) dropped is much less often today than it was say 4-5 years ago, when it seemed that several consumer broadband providers were dropping IPsec, suggesting instead, our telecommuters should opt for >$100/mo "business class" packages.
__________________
--
Domino 7.0.4FP1 | BES 4.1.6 MR-7 | 42 handhelds
Offline  
Old 10-24-2007, 02:22 PM   #7
pierrebnh
New Member
 
Join Date: Oct 2007
Model: 8830
PIN: N/A
Carrier: Sprint
Posts: 14
Default

Quote:
Originally Posted by penguin3107 View Post
Why would you have port 1352 open to the public?
You don't require a secure connection to your Domino server for remote users?

Our remote users are required to use a VPN to connect to Domino.
Aroc is right, you don't need VPN to have a secure connection to Domino. And we've run into the same issues with IPSec blocking at hotels.

Thankfully, it looks like Comcast has resolved this issue.
Offline  
Old 10-24-2007, 04:02 PM   #8
mahoward
CrackBerry Addict
 
mahoward's Avatar
 
Join Date: May 2005
Model: 8900
Carrier: T-Mobile
Posts: 560
Default

I work with Kevin, and Comcast finally caved and admitted this was a "bug" (probably associated with their P2P filtering) and has resolved it.
__________________
BESX 4.1.7 on Exchange 2003: 65 Devices
BESX 5.0.3 on Exchange 2003: 2007 Devices
Offline  
Old 10-24-2007, 04:02 PM   #9
penguin3107
BlackBerry God
 
penguin3107's Avatar
 
Join Date: Jan 2005
Model: iOS 5
Carrier: VZW
Posts: 11,701
Default

Quote:
Originally Posted by pierrebnh View Post
Aroc is right, you don't need VPN to have a secure connection to Domino. And we've run into the same issues with IPSec blocking at hotels.

Thankfully, it looks like Comcast has resolved this issue.
I totally understand that... and I agree to some extent.
The problem with this model is that you're requiring the Notes Client to be properly configured to encrypt the traffic.
You're also exposing your Domino server to the public internet. Albeit, it's one port, but that's still a hole that can potentially be breached.

For me, the Comcast thing isn't an issue. It might be fore some people and I hope that gets fully worked out.
__________________
BCSA
BES 5.0.3 MR4 :-: Exchange 2007 SP3 RU3
http://port3101.org
Offline  
Old 10-25-2007, 06:18 AM   #10
m4ilm4n
Thumbs Must Hurt
 
m4ilm4n's Avatar
 
Join Date: Oct 2006
Location: Loony bin
Model: 8800
Carrier: T-Mobile
Posts: 111
Default

My first response was "who in their right mind is putting their Domino server out in the wild like that?", but after further thought, I can see proxying port 80 thru a firewall to get to web apps, but anything else is just asking for trouble. I require my users to have an encrypted VPN tunnel running before they start their remote Notes client, and the VPN gateway's policy disallows split tunneling. Maybe I'm just being paranoid, but I've been burned before....
Offline  
Old 10-26-2007, 11:40 AM   #11
Wiseass
Talking BlackBerry Encyclopedia
 
Join Date: Sep 2005
Location: Illinois
Model: 9850
PIN: k Floyd \m/ ROCK!
Carrier: VZW
Posts: 249
Default

Thanks for the replies all, for those of you saying it's "resolved" and a "bug" do you have any article links? I looked at the original and it's not updated, and can't seem to find anything else referring it.
__________________
"I dont feel I need to explain my art to you Warren"
Offline  
Old 10-26-2007, 12:00 PM   #12
mahoward
CrackBerry Addict
 
mahoward's Avatar
 
Join Date: May 2005
Model: 8900
Carrier: T-Mobile
Posts: 560
Default

From the AP article:

Kevin Kanarski, a network engineer for a major law firm, noticed the disruption in August and eventually traced the problem to Comcast. But he got the cold shoulder from the company's customer support department.

On Tuesday, Bowling acknowledged the problem, saying it was unintentional and due to a software bug that has been fixed. Kanarski said transfers started working again last week.
__________________
BESX 4.1.7 on Exchange 2003: 65 Devices
BESX 5.0.3 on Exchange 2003: 2007 Devices
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Unifi Talk UVP Touch Max VOIP IP Phone Unlocked picture

Unifi Talk UVP Touch Max VOIP IP Phone Unlocked

$149.99



Unifi Talk UVP Touch VOIP IP Phone Unlocked picture

Unifi Talk UVP Touch VOIP IP Phone Unlocked

$125.00



Nextiva X-835 SIP Color Deskset VoIP Phone Black New In Box picture

Nextiva X-835 SIP Color Deskset VoIP Phone Black New In Box

$54.99



Vtech ErisTerminal VSP861 Touchscreen Color Desktop - Voice-Over-IP VOIP Phone picture

Vtech ErisTerminal VSP861 Touchscreen Color Desktop - Voice-Over-IP VOIP Phone

$14.99



PANASONIC KX-NT553 Business IP Handset VoIP Office Phone picture

PANASONIC KX-NT553 Business IP Handset VoIP Office Phone

$49.99



Grandstream GXP2130 IP Wall Phone Color Gigabit Enterprise HD VoIP PoE Black picture

Grandstream GXP2130 IP Wall Phone Color Gigabit Enterprise HD VoIP PoE Black

$27.98







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.