Time Services & FQDN/IP Policy

8. Time Services and NTP Requirements

Accurate time synchronization is critical for TLS validation, authentication, logging, cloud communications, transaction processing, operational support, and auditability.

Critical Dependency

Blocked or inaccurate NTP can cause certificate validation errors, misleading event timelines, failed authentication, and difficult support investigations.

NTP area Requirement Validation evidence
Source Use approved internal or external NTP sources NTP server list
Reachability Allow NTP from POS systems or approved local relay NTP query result
Drift Maintain accurate time across POS and local services Endpoint time sample
Failover NTP remains available on backup WAN Failover test evidence

9. FQDN and IP Policy

Firewall policies should use FQDN objects wherever possible because PAR and cloud service dependencies can resolve to dynamic IP addresses. Static IP allowlists should be used only when PAR or the third-party provider explicitly publishes and maintains them for that service.

Policy type Use when Operational requirement
Wildcard FQDN Service publishes stable domain patterns Firewall refreshes dynamic resolutions automatically.
Exact FQDN Service endpoint is specific and stable Use for integrations with named hostnames.
IP allowlist Provider publishes fixed ranges Assign an owner for range update review.
Category allow Never as the only control for POS Use only as a supporting control, not a substitute for service policy.