Server configuration

The recommended and least restrictive firewall configuration is to enable the listed TCP ports to carry outbound-initiated bidirectional communications to the bbsecure.com subdomains.

<region> represents a unique region code depending on the EULA selected during installation. For example, if Canada was selected, then <region> is ca. To find a specific country code, see the ISO Standard.

Usage

TCP port

Protocol

Domain

BlackBerry UEM Core

BlackBerry Proxy

BlackBerry Dynamics services

BlackBerry Connectivity Node

UEM Cloud BlackBerry Connectivity Node

BlackBerry Enterprise Mobility Server1

App servers

443

TCP

gdmdc.good.com

gdweb.good.com

For UEM 12.23 and later and UEM Cloud November 2025 and later:

prod.dynamics.blackberry.com

prod-mdc.dynamics.blackberry.com

BlackBerry Proxy

443

TCP

gdentgw.good.com

For UEM 12.23 and later and UEM Cloud November 2025 and later:

prod-mdc.dynamics.blackberry.com

BlackBerry Enterprise Mobility Server

443

TCP

gdweb.good.com1

fcm.googleapis.com

www.googleapis.com

oauth2.googleapis.com

accounts.google.com

BlackBerry UEM Core

BlackBerry Proxy

3101

TCP

<region>.bbsecure.com

BlackBerry Connectivity Node

3101

443

TCP

<region>.bbsecure.com

BlackBerry Secure Connect Plus

3101

TCP

<region>.turnb.bbsecure.com

BlackBerry Secure Connect Plus

443

HTTPS

<region>.bbsecure.com

BlackBerry Secure Connect Plus with Knox Workspace

443

HTTPS

api.samsungapps.com

1 The BlackBerry Enterprise Mobility Server currently requires an outbound connection to gdweb.good.com, but in an upcoming BlackBerry Enterprise Mobility Server release it will be updated to connect to prod.dynamics.blackberry.com and prod-mdc.dynamics.blackberry.com (at that time connections to gdweb.good.com will be redirected to the new domains). To prepare for this update, allow connections for both gdweb.good.com and the new prod.dynamics.blackberry.com and prod-mdc.dynamics.blackberry.com domains.