TLS, WAN Failover & Validation
15. TLS Inspection Guidance
TLS inspection can interfere with certificate pinning, authentication flows, payment communications, and cloud service trust. Customers should evaluate inspection exemptions for PAR, Brink, AWS, payment, Remote Care, and approved integration destinations.
| Destination category | TLS inspection posture | Reason |
|---|---|---|
| PAR cloud | Exempt unless approved | Avoid certificate validation and service trust failures. |
| Payment endpoints | Exempt unless compliance owner approves | Payment traffic may have strict trust requirements. |
| Remote Care | Review by support/security | Support tooling may require stable TLS behavior. |
| General internet | Customer policy | Outside PAR POS requirement scope. |
16. WAN Failover and Business Continuity
Business continuity depends on policy symmetry. A backup circuit that carries traffic but fails DNS, NTP, FQDN policy, or TLS validation is not a complete failover design.
| Failover item | Pass condition | Evidence |
|---|---|---|
| Route change | POS traffic exits backup path | Traceroute or firewall session sample |
| DNS | Required FQDNs resolve | Lookup output |
| NTP | Approved time source reachable | NTP query output |
| Cloud access | PAR/Brink endpoints reachable | HTTPS test |
| Payment path | Payment endpoint test passes where applicable | Processor or PAR Pay validation |
| Rollback | Primary restored without stale sessions or DNS failures | Change ticket notes |
17. Validation and Acceptance Testing
-
Confirm VLAN assignments, DHCP scopes, reservations, and routing tables.
-
Validate DNS resolution for PAR, AWS, Remote Care, PAR Pay, and approved integration FQDNs.
-
Validate NTP reachability and endpoint time accuracy.
-
Confirm firewall rule hits for required destinations during a live connectivity test.
-
Run primary WAN and backup WAN validation using the same test checklist.
-
Capture screenshots, exports, logs, and timestamps for the acceptance package.
| Test | Pass criteria | Artifact |
|---|---|---|
| DNS lookup | All required names resolve | Command output or resolver log |
| NTP query | Accurate response from approved source | Command output |
| HTTPS reachability | Successful TLS connection | Browser/curl/test output |
| Firewall policy | Expected rule hit observed | Firewall log export |
| Failover | Same outcomes on backup WAN | Change ticket and test evidence |