Executive Summary & Scope
1. Executive Summary
PAR POS environments require a segmented, resilient, and observable network design. The network must support reliable cloud communications, accurate time synchronization, DNS resolution, controlled firewall egress, and consistent failover behavior across primary and backup WAN paths.
Key Takeaway
Design the POS network as a controlled business-critical segment. The most common launch risks are missing FQDN rules, incorrect DNS behavior, blocked NTP, TLS inspection failures, and backup WAN paths that do not mirror primary policy.
-
Use dedicated VLANs for POS, guest, office, IoT, and network management traffic.
-
Allow outbound access using FQDN-based policy objects wherever the firewall platform supports them.
-
Keep time services accurate for TLS validation, authentication, logging, auditing, and transaction processing.
-
Size switching, cabling, DHCP scopes, wireless coverage, and WAN capacity for peak store operations.
-
Document site-specific IP ranges, device owners, change windows, and rollback plans before go-live.
1.1 Publication Assumptions
| Assumption | Customer-specific validation required |
|---|---|
| FQDN policy | Confirm the firewall supports wildcard and dynamic FQDN objects. |
| Stack assignment | Confirm each store's assigned stack before implementing stack-specific rules. |
| Payments | Confirm the PAR Pay and processor architecture for each merchant environment. |
| WAN failover | Test DNS, NTP, TLS, and firewall behavior on the secondary circuit. |
2. Audience and Scope
This guide is written for technical teams responsible for designing, approving, implementing, and validating store network connectivity for PAR POS deployments.
| Audience | How to use this guide |
|---|---|
| MSPs | Build repeatable firewall, VLAN, DNS, NTP, monitoring, and evidence collection standards. |
| Security auditors | Review segmentation, PCI adjacency, logging, least privilege, and change control expectations. |
| Firewall engineers | Translate FQDN, port, protocol, TLS, and failover requirements into platform-specific policy. |
| Franchise IT directors | Validate store readiness and coordinate carrier, hardware, and implementation timelines. |
| Enterprise customers | Standardize site design across brands, regions, and support models. |
2.1 In Scope
-
Store LAN segmentation, switching, wireless isolation, DNS, NTP, firewall egress, cloud access, WAN resiliency, and validation evidence.
-
PAR POS, Brink POS, Remote Care, Orbit/local store communications, PAR Pay considerations, AWS dependencies, and approved third-party integrations.
2.2 Out of Scope
-
Customer-specific IP addressing plans unless supplied by the customer or implementation team.
-
Firewall vendor click-path instructions, which should be maintained by each customer's firewall operations team.
-
Processor-specific PCI attestation language, which should be validated by the merchant's QSA or compliance owner.