Port 3101 must be open for outbound initiated, bidirectional traffic to your SRP-Gateway. Thats the easy part. And because the BES is working, everbody is happy.
But, as described in the article here, the IP address of your SRP-Gateway could change. If you haven't properly configured your firewall, your Blackberry Enterprise Server will stop working because the firewall will block the traffic to the new IP-Address.
To avoid this, RIM has published a List of IP-Ranges, which could be used as SRP-Gateway IP in future. To avoid the list getting outdated, I provide a link to the related BTSC-article, hoping it will be updated when necessary.
So, if you configure your firewall, be sure to implement these IP addresses.


Somewhere in the past, there were only 3 possible addresses for the SRP-Gateway (NOC): srp.na.blackberry.net (North America) srp.eu.blackberry.net (Europe) srp.ap.blackberry.net (AsiaPacific) I'm not sure, but I think it was with Blackberry Enterp
Tracked: May 28, 20:42