Setting Up a Domain or IP Address Allowlist

Configure your network firewall or WAF to allowlist PayNearMe domains and IP addresses, including production and sandbox endpoints, Fastly CDN ranges, SFTP access, and TLS 1.2+ cipher suite requirements.

Before you begin integrating with the PayNearMe platform, you will need to add paynearme.com on the appropriate port or add PayNearMe's static server IP addresses to your system's allowlist . Additionally, you'll want to add the IP addresses for PayNearMe's enhanced Content Delivery Network (CDN) solution using Fastly. As a best practice, we recommend one of the following solutions:

A. If you have a web application layer firewall (WAF) (e.g., AWS WAF, F5 WAF, and Cloudflare WAF) you should allowlist via domain (preferred)

B. If you have a network firewall (IP address only), update the allowlist to include the PNM static server IP addresses and the Fastly IP addresses listed below.

📘

PayNearMe Allowlist

PayNearMe's preferred allowlist configuration is via the paynearme.com and paynearme-sandbox.com domains. PayNearMe does NOT restrict inbound or response IPs.

Production IPs

ProductDomain + PortIP Addresses
API CallsAllow HTTPS Port 443 from Your Server to api.paynearme.com
API Callback WebhooksAllow HTTPS Port 443 from paynearme.com to Your Server Endpoint
  • 52.73.199.135
  • 18.236.19.74
  • 52.73.193.175
  • 52.27.253.6
Business PortalAllow HTTPS Port 443 from Your Workstations to paynearme.comAgent workstations need to be able to communicate over HTTPS Port 443 to paynearme.com and access the Fastly IP Addresses.
SFTP AccessAllow SFTP Port 22 from Your Server to files.paynearme.com

Sandbox IPs

ProductPortIP Addresses
API CallsAllow HTTPS Port 443 from Your Server to api.paynearme-sandbox.com
API Callback WebhooksAllow HTTPS Port 443 from paynearme-sandbox.com to Your Server Endpoint
  • 52.200.146.188
  • 44.194.145.78
  • 34.200.202.164
  • 52.86.94.202
  • 52.73.80.135
  • 52.4.121.158
  • 52.86.169.172
  • 52.5.196.244
Business PortalAllow HTTPS Port 443 from Your Workstations to paynearme-sandbox.comAgent workstations need to be able to communicate over HTTPS Port 443 to paynearme-sandbox.com and access the Fastly IP Addresses.

SFTP-Supported Configuration

Decryption MethodData
Ciphersaes256-ctr
Kex Algorithmscurve25519-sha256,[email protected],ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
MACs[email protected],[email protected],hmac-sha2-512,hmac-sha2-256

Fastly IPs

🚧

Updated IP List

To ensure you have the most updated list of Fastly IP addresses, please copy and paste the list provided by Fastly here to your network and firewall rules. While we make every effort to ensure the list displayed below is kept updated, using the dynamic list provided directly from Fastly will ensure your service remains uninterrupted.

{
  "addresses": [
    "23.235.32.0/20",
    "43.249.72.0/22",
    "103.244.50.0/24",
    "103.245.222.0/23",
    "103.245.224.0/24",
    "104.156.80.0/20",
    "140.248.64.0/18",
    "140.248.128.0/17",
    "146.75.0.0/17",
    "151.101.0.0/16",
    "157.52.64.0/18",
    "167.82.0.0/17",
    "167.82.128.0/20",
    "167.82.160.0/20",
    "167.82.224.0/20",
    "172.111.64.0/18",
    "185.31.16.0/22",
    "199.27.72.0/21",
    "199.232.0.0/16"
  ],
  "ipv6_addresses": [
    "2a04:4e40::/32",
    "2a04:4e42::/32"
  ]
}

Required TLS Settings

👍

Security Checkup

For a step-by-step guide on how to check your site's TLS version and cipher suites, see Reviewing Your TLS Version and Cipher Suites.

To ensure secure communication and protect data in transit, all clients connecting to our APIs must meet the following Transport Layer Security (TLS) requirements:

Minimum TLS Version

  • TLS 1.2 or higher is required
  • TLS 1.0 and 1.1 are not supported

Deprecated Cipher Suites

Connections using the following will be rejected:

  • SSL/TLS protocols below TLS 1.2
  • Cipher suites using:
    • RSA key exchange without PFS
    • SHA-1 or MD5 hashes
    • Block ciphers without AEAD (e.g., CBC without GCM)

Supported Cipher Suites

TLS 1.3

TLS 1.3 cipher suites are defined by the protocol and are AEAD-only. Key exchange and authentication are negotiated separately from the cipher suite, so suite names do not specify ECDHE, RSA, or ECDSA.

RFC Cipher Nameopenssl Cipher Name
TLS_AES_128_GCM_SHA256TLS_AES_128_GCM_SHA256
TLS_AES_256_GCM_SHA384TLS_AES_256_GCM_SHA384
TLS_CHACHA20_POLY1305_SHA256TLS_CHACHA20_POLY1305_SHA256
⚠️

Naming Conventions

OpenSSL 1.1.1 and later report TLS 1.3 suites using the RFC names shown above. Older releases may use the TLS13- prefixed form, for example TLS13-AES-256-GCM-SHA384.

TLS 1.2

All supported TLS 1.2 cipher suites use ECDHE key exchange for forward secrecy with an AEAD cipher.

RFC Cipher Nameopenssl Cipher Name
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256ECDHE-RSA-AES128-GCM-SHA256
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256ECDHE-ECDSA-AES128-GCM-SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384ECDHE-RSA-AES256-GCM-SHA384
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384ECDHE-ECDSA-AES256-GCM-SHA384
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256ECDHE-RSA-CHACHA20-POLY1305
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256ECDHE-ECDSA-CHACHA20-POLY1305

Unsupported Protocols and Cipher Suites

Connections using any of the following will be rejected with a TLS handshake failure:

  • TLS protocol versions below TLS 1.2, including SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1
  • Cipher suites using RSA key exchange without forward secrecy
  • Cipher suites using SHA-1 or MD5 hashes
  • Block ciphers without AEAD, including all CBC-mode cipher suites
  • 3DES cipher suites

Commonly encountered examples:

RFC Cipher Nameopenssl Cipher Name
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256ECDHE-RSA-AES128-SHA256
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256ECDHE-ECDSA-AES128-SHA256
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHAECDHE-RSA-AES128-SHA
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHAECDHE-RSA-AES256-SHA
TLS_RSA_WITH_AES_128_GCM_SHA256AES128-GCM-SHA256
TLS_RSA_WITH_AES_128_CBC_SHAAES128-SHA
TLS_RSA_WITH_AES_256_CBC_SHAAES256-SHA
TLS_RSA_WITH_3DES_EDE_CBC_SHADES-CBC3-SHA

Client Configuration Requirements

  • Support TLS 1.2 or higher with ECDHE key exchange and an AES-GCM or ChaCha20-Poly1305 cipher suite.
  • Keep client libraries current (OpenSSL, Java, .NET, curl, and similar). OpenSSL 1.0.1 or later, Java 8 or later, and current .NET, Go, Python, and Node.js runtimes meet these requirements by default.
  • Do not hardcode specific cipher suites or TLS versions. Allow your TLS library to negotiate the strongest mutually supported option.

For full compatibility details, refer to Fastly’s TLS configuration guide.


Did this page help you?