Restrict or permit web addresses and Intranet addresses using a pull rule
A web site that uses DNS load balancing returns a single IP address to the BlackBerry MDS Connection Service but might use multiple IP addresses to provide access to the web site. As a result, the BlackBerry MDS Connection Service might not be able to restrict BlackBerry devices from accessing the web site.
- In the BlackBerry Administration Service, on the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view.
- Click MDS Connection Service.
- Click Edit component.
- On the Access control rules tab, click the Edit icon for a pull rule.
- In the URL pattern group drop-down list, click the protocol for the address that you want to assign to the pull rule.
- In the URL pattern drop-down list, click the address that you want to assign to the pull rule.
- In the Allowed drop-down list, perform one of the following actions:
- To prevent users from accessing web servers that match the address, click Deny.
- To permit users to access web servers that match a specific address, click Allow.
-
If necessary, in the Authentication drop-down list, perform one of the following actions:
- To require that a user enter authentication credentials to access content on a web site, click Access control rules only. The device user is not prompted to enter authentication credentials if they are not required by the web site.
- To require that the BlackBerry MDS Connection Service authenticates a user using integrated Windows authentication, click Integrated.
- To require that a user authenticates to the RSA Authentication Manager using RSA authentication, click RSA.
- To require that the BlackBerry MDS Connection Service authenticates the user using integrated Windows authentication and that a user authenticates to the RSA Authentication Manager using RSA authentication, click Integrated and RSA.
- Click the Add icon.
- Repeat steps 5 to 8 for each address that you want to assign to the pull rule.
- Click Save all.
After you finish: Assign the pull rule to a group or user account.