Firewall & Cloud Dependencies
10. Firewall Connectivity Requirements
The following matrix is the customer-facing baseline. Final production rules should be reviewed against the customer's assigned stack, payment configuration, Remote Care scope, integrations, and firewall platform capabilities.
| Service | Destination | Port | Direction | Source | Status |
|---|---|---|---|---|---|
| PAR core services | *.parpos.com | TCP 443 | Outbound | POS VLAN | Required |
| Brink services | *.brinkpos.net | TCP 443 | Outbound | POS VLAN | Required |
| AWS dependencies | AWS service endpoints used by PAR | TCP 443 | Outbound | POS VLAN | Required |
| Remote Care | Approved Remote Care FQDNs | TCP 443 | Outbound | POS/support | As contracted |
| DNS | Customer DNS resolvers | TCP/UDP 53 | Outbound | POS VLAN | Required |
| NTP | Approved NTP sources | UDP 123 | Outbound | POS VLAN or relay | Required |
| MQTT/Orbit | Approved PAR messaging endpoints | TCP 443 or approved MQTT path | Outbound | POS/local services | Where deployed |
| PAR Pay | Approved payment endpoints | TCP 443 | Outbound | Payment/POS | Where deployed |
| Integrations | Approved third-party FQDNs | TCP 443 | Outbound | As needed | By integration |
10.1 Firewall Engineering Notes
-
Default deny should apply between VLANs unless an explicit business requirement exists.
-
Log rule hits during implementation and acceptance testing to prove policies are exercised.
-
Avoid TLS decryption for PAR and payment endpoints unless PAR and the compliance owner explicitly approve it.
-
Backup WAN policy must be tested, not assumed.
11. AWS and Cloud Dependencies
PAR services may use AWS-hosted components and cloud service dependencies. Customers should allow the required PAR-published FQDNs rather than attempting to maintain unofficial static IP lists.
| Dependency area | Policy approach | Customer action |
|---|---|---|
| PAR cloud | Allow approved PAR and Brink FQDNs | Confirm assigned stack and required domains. |
| AWS-hosted services | Allow PAR-published service paths | Do not block AWS endpoints used by PAR services. |
| Support tools | Allow contracted Remote Care endpoints | Scope access to approved devices and support owners. |
| Third-party integrations | Allow only active integration destinations | Retire unused rules during change review. |