Which ports must remain open for the Integration Agent, NCR Secure Pay and ADT to function?
Article Number: 549 | Rating: Unrated | Last Updated: Mon, Nov 17, 2014 at 8:38 AM
The Integration Agent provides item, customer and order information to NCR Retail Online. It also transfers orders from NCR Retail Online to NCR Counterpoint's CPOnline directory. NCR Secure Pay is the payment gateway for ecommerce transactions. This article will detail how to configure your Counterpoint server's firewall ports to allow bi-directional communication between Counterpoint and our Retail Hosted Applications.
This configuration is specific to NCR Secure Pay:
*NOTE: This information was last verified, on 11/17/2014. The most recent information about the port configurations for NCR Secure Pay can be found by visiting the following link:
To allow NCR Counterpoint to send transactions to and receive responses from the NCR Secure Pay Transaction server, you must configure your network firewall(s) to allow outbound TCP/IP traffic to ps.ncrsecurepay.com (153.69.208.11) over port 8444.
The primary IP address for the NCR Secure Pay Transaction server is 153.69.208.11. The disaster recovery IP address for the NCR Secure Pay Transaction server is 153.69.131.11. As these IP addresses may change periodically, we recommend using DNS to resolve connections to NCR Secure Pay servers, if possible.
To allow for the activation and deactivation of encrypted MSRs and payment terminals for use with point-to-point encryption (P2PE), you must configure your network firewall(s) to allow outbound HTTPS traffic to ws.ncrsecurepay.com (153.69.208.13) over port 443.
The primary IP address for the NCR Secure Pay Device Service server is 153.69.208.13. The disaster recovery IP address for the NCR Secure Pay Device Service server is 153.69.131.13. As these IP addresses may change periodically, we recommend using DNS to resolve connections to NCR Secure Pay servers, if possible.
Also, any computer that will be used to access the NCR Secure Pay Credit Settlement portal (https://portal.ncrsecurepay.com) must allow outbound HTTPS traffic over port 443.
To summarize, below are the port configurations for NCR Secure Pay:
NCR Secure Pay Transaction
ps.ncrsecurepay.com
primary IP 153.69.208.11
DR IP 153.69.131.11
Direction: outbound
Port: 8444
Protocol: TCP
NCR Secure Pay Device Service and future
ws.ncrsecurepay.com
primary IP 153.69.208.13
DR IP 153.69.131.13
Direction: outbound
Port: 443
Protocol: https
NCR Secure Pay Merchant Portal
portal.ncrsecurepay.com
IP 153.69.215.16
Direction: outbound
Port: 443
Protocol: https
This is the necessary port configuration to allow the Integration Agent to securely send customer and item information to NCR Retail Online:
IP: this will be the NRO store IP address that is provided to the merchant by the RHA Support team
Direction: outbound
Port: 443
protocol: https
This is the necessary port configuration so you can browse your site and see it as shoppers:
IP: the IP address of your NRO store
Direction: outbound
Port: 80
Protocol: http
In regards to the security of the customer information being passed both ways, we do send customer records to NRO via the standard Magento API via SSL. Therefore, as long as SSL is used, the traffic is encrypted even if the records themselves are not.
Finally, both port 80 and 443 need to be open to radiantretailapps.com. This is necessary so that the Integration Agent installed on your Counterpoint server can receive updates that we release. Additionally, the IA must be able to verify that the Counterpoint serial number is actively subscribed to NCR Retail Online, each time that it runs. If it can't, the IA service won't run.