Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Does Aloha "phone home" ?

Status
Not open for further replies.

partpricer

IS-IT--Management
Mar 20, 2009
13
US
I just happened upon this forum. There is a wealth of information here regarding Aloha. Perhaps someone here can answer some questions for me as our dealer is not able. Here is our scenario:


We take PCI compliance very seriously and have our environments tightly locked down. Our Aloha systems run in their own firewalled security zones with the only allowed connection outbound to our payment processor via a SSL connection to a specific IP. This is done through a proxy. There are no inbound connections allowed.

Now, the other day all of our credit and debit card transactions were failing. We went in and looked at the firewalls and saw that the connection to the processor was initiating correctly whenever a payment card transaction was attempted, but there was nothing being sent. We then turned to look at Aloha since nothing had changed in our security environment for about a week.

To make a long story short, after some extensive investigation we have found that Aloha appears to initiate an outbound connection on port 80 to webfarm.alohaenterprise.com periodically. Since we block all connections out of this zone other than the one mentioned above, the connection was failing and after a period of time, the application crippled itself. In an effort to maintain a revenue stream for our business and keep our customers happy, we briefly allowed outbound connections on port 80 from this zone. We saw a quick connection to alohaenterprise.com, then our payment card transactions started processing. We blocked port 80 again and the transactions continue to process. But, we don't know for how long.

So, I have a few questions.

1. What is the purpose of this connection to alohaenterprise.com?
2. How often does it attempt to establish this connection?
3. If this connection is actually needed for the application to function properly, should we allow connections to a specific IP address, a range of IP addresses, or a DNS name?
 
1. To download updated or missing files related to Radiant Hearbeat Service.
2. Every time CTLSVR is started and periodically (Not sure of time frame, I'm guessing between once every 15 mintues to an hour)
3. It is not needed, I have this blocked and credit cards work fine.
 
I am PCI level 1 compliant, and I understand where you are coming from.

Blocking this connection is fine. I am not using anything that is trying to connect there on any of my 500+ sites, but we use Enterprise, but unlike the majority of people, we actually own our own Aloha Enterprise servers in-house and don't use the alohaenterprise.com one.

It might be the Radiant Heartbeat service trying to connect to see if you are an Aloha Command Center user, or report statistic usage information about your Radiant POS terminals if you have them (How long the LCD bulb has been on, Number of MSR swipes, etc). They use this information to be pro-active to know when you may be about to have a POS terminal problem. It's all good and does not violate any PCI issues.


---
MegabyteCoffee.com
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top