Firewall & Cloud Dependencies

10. Firewall Connectivity Requirements

The following matrix is the customer-facing baseline. Final production rules should be reviewed against the customer's assigned stack, payment configuration, Remote Care scope, integrations, and firewall platform capabilities.

Service Destination Port Direction Source Status
PAR core services *.parpos.com TCP 443 Outbound POS VLAN Required
Brink services *.brinkpos.net TCP 443 Outbound POS VLAN Required
AWS dependencies AWS service endpoints used by PAR TCP 443 Outbound POS VLAN Required
Remote Care Approved Remote Care FQDNs TCP 443 Outbound POS/support As contracted
DNS Customer DNS resolvers TCP/UDP 53 Outbound POS VLAN Required
NTP Approved NTP sources UDP 123 Outbound POS VLAN or relay Required
MQTT/Orbit Approved PAR messaging endpoints TCP 443 or approved MQTT path Outbound POS/local services Where deployed
PAR Pay Approved payment endpoints TCP 443 Outbound Payment/POS Where deployed
Integrations Approved third-party FQDNs TCP 443 Outbound As needed By integration

10.1 Firewall Engineering Notes

  • Default deny should apply between VLANs unless an explicit business requirement exists.

  • Log rule hits during implementation and acceptance testing to prove policies are exercised.

  • Avoid TLS decryption for PAR and payment endpoints unless PAR and the compliance owner explicitly approve it.

  • Backup WAN policy must be tested, not assumed.

11. AWS and Cloud Dependencies

PAR services may use AWS-hosted components and cloud service dependencies. Customers should allow the required PAR-published FQDNs rather than attempting to maintain unofficial static IP lists.

Dependency area Policy approach Customer action
PAR cloud Allow approved PAR and Brink FQDNs Confirm assigned stack and required domains.
AWS-hosted services Allow PAR-published service paths Do not block AWS endpoints used by PAR services.
Support tools Allow contracted Remote Care endpoints Scope access to approved devices and support owners.
Third-party integrations Allow only active integration destinations Retire unused rules during change review.