Payment traffic had to leave through a managed security appliance while the site already operated on a different gateway platform.
A new payment path. The existing network.
Point-of-sale migration behind a security appliance
Implemented the point-of-sale routing path and documented an alternative migration design for the client.
Compare the implemented path with the documented future option.
Payment traffic passes through the required security appliance. The existing gateway and the rest of the site network remain in place.
Use 1:1 NAT and a transit handoff from the existing gateway to route payment traffic through the required appliance, preserving the rest of the site network.
A deployed payment-traffic path meeting the specified vendor routing requirement, plus a written alternative using WAN2, policy-based routing, NAT masquerade, and firewall rules.
The additional-appliance path was implemented. The single-gateway path is a documented future option, not a deployed configuration. The public topology uses recreated devices and example addressing.
Technical diagramView the full overview
What needs
to work better?
Tell me where things stand, what’s getting in the way, and what you need to happen next.
Discuss your project Ontario, Canada · English & Spanish