Blackberry PRD-10459-003 Administration Guide - Page 264

Create a pull rule, Restrict or permit web addresses and Intranet addresses using a pull rule

Page 264 highlights

Administration Guide Restricting user access to content on web servers A web site that uses DNS load balancing returns a single IP address to the BlackBerry MDS Connection Service but might use multiple IP addresses to provide access to the web site. As a result, the BlackBerry MDS Connection Service might not be able to restrict BlackBerry devices from accessing the web site. 1. In the BlackBerry Administration Service, in the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view. 2. Click MDS Connection Service. 3. Click Edit component. 4. On the Pull URL patterns tab, in the appropriate protocol section, type the web address pattern of a web server that you want to control access to. The web address patterns are based on Java® regular expressions (for example, .*\..*domain.*). 5. Click the Add icon. 6. Click Save all. After you finish: Create web address patterns for each web server that you want to permit users to access. Create a pull rule that permits users to access the web servers that match the web address patterns. Create a pull rule 1. In the BlackBerry® Administration Service, in the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view. 2. Click MDS Connection Service. 3. Click Edit component. 4. On the Access control rules tab, in the Rule name field, type a name for the pull rule. 5. In the Control type drop-down list, click Pull. 6. Click the Add icon. 7. Click Save all. After you finish: Restrict or permit web address patterns using a pull rule. Restrict or permit web addresses and Intranet addresses using a pull rule A web site that uses DNS load balancing returns a single IP address to the BlackBerry® MDS Connection Service but might use multiple IP addresses to provide access to the web site. As a result, the BlackBerry MDS Connection Service might not be able to restrict BlackBerry devices from accessing the web site. Before you begin: • Create a pull rule. • If you want BlackBerry device users to use RSA® authentication to access web servers, configure the BlackBerry MDS Connection Service to authenticate BlackBerry devices to the RSA® Authentication Manager. • If you want users to use integrated Windows® authentication when they access the web servers, configure the BlackBerry MDS Connection Service to authenticate devices to Microsoft® Active Directory®. 262

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

A web site that uses DNS load balancing returns a single IP address to the BlackBerry MDS Connection Service but
might use multiple IP addresses to provide access to the web site. As a result, the BlackBerry MDS Connection Service
might not be able to restrict BlackBerry devices from accessing the web site.
1.
In the BlackBerry Administration Service, in the
Servers and components
menu, expand
BlackBerry Solution
topology > BlackBerry Domain > Component view
.
2.
Click
MDS Connection Service
.
3.
Click
Edit component
.
4.
On the
Pull URL patterns
tab, in the appropriate protocol section, type the web address pattern of a web server
that you want to control access to. The web address patterns are based on Java® regular expressions (for
example,
.*\..*domain.*
).
5.
Click the
Add
icon.
6.
Click
Save all
.
After you finish:
Create web address patterns for each web server that you want to permit users to access. Create
a pull rule that permits users to access the web servers that match the web address patterns.
Create a pull rule
1.
In the BlackBerry® Administration Service, in the
Servers and components
menu, expand
BlackBerry Solution
topology > BlackBerry Domain > Component view
.
2.
Click
MDS Connection Service
.
3.
Click
Edit component
.
4.
On the
Access control rules
tab, in the
Rule name
field, type a name for the pull rule.
5.
In the
Control type
drop-down list, click
Pull
.
6.
Click the
Add
icon.
7.
Click
Save all
.
After you finish:
Restrict or permit web address patterns using a pull rule.
Restrict or permit web addresses and Intranet addresses using a pull rule
A web site that uses DNS load balancing returns a single IP address to the BlackBerry® MDS Connection Service but
might use multiple IP addresses to provide access to the web site. As a result, the BlackBerry MDS Connection Service
might not be able to restrict BlackBerry devices from accessing the web site.
Before you begin:
Create a pull rule.
If you want BlackBerry device users to use RSA® authentication to access web servers, configure the BlackBerry
MDS Connection Service to authenticate BlackBerry devices to the RSA® Authentication Manager.
If you want users to use integrated Windows® authentication when they access the web servers, configure the
BlackBerry MDS Connection Service to authenticate devices to Microsoft® Active Directory®.
Administration Guide
Restricting user access to content on web servers
262