We are using Verifone Omni 3750 credit card terminals over the internet. They are behind a PIX 501 firewall at each location that we have them. Two of the locations have random terminals kicking over to the dial-up backup. We have nine locations total that are set up this way, and the other seven are having no problems. When the terminals kick over to dial-up, it may be only one that does it, or as many as two or three at a time, while all of the other lanes continue to work correctly (we have five lanes at both of the stores having the problem).
The Omni terminals have a diagnostic / troubleshooting option that pings the gateway, DNS server, and then tries to resolve a DNS name, followed by connecting to SSL by a DNS name. When one or more of the terminals switches to dial-up, the machine is able to ping IP addresses all over the internet, but it times out when connecting to something using a DNS name.
I thought perhaps it was a problem with our internal DNS server, so I tried the ISP DNS as well as a public DNS server, none of which fixed the problem. It is occurring on two separate service providers, so I don't think it is a matter of the ISP blocking anything (why they would block DNS anyway, I don't know).
I have compared the PIX firewall configurations and the only difference that I can see is that the two having the problem do not have the line
pdm logging informational 100
I don't know how PDM logging would have any effect on the problem, but I went ahead and added the line a few minutes ago, just to rule it out 100%.
Both of the stores that are having this problem are on cable internet, but on two different providers.
All of the LAN cabling is brand new, installed specifically for this purpose. The cabling has been tested and shows no problems. (I also don't think the cabling has anything to do with the issue because even when they are having the problem, a constant, uninterrupted ping can be done both from and to the terminals).
According to the company that we purchased the terminals from, all of the programming is identical, aside from the terminal ID.
I can not think of anything else to rule out. Does anyone know of something within a PIX that might be causing this that would not be evident when comparing configurations using the SHOW RUN command?
Does anyone have any ideas as to where I should look next?
Thanks,
Ben
Forth Foods, Inc.
The Omni terminals have a diagnostic / troubleshooting option that pings the gateway, DNS server, and then tries to resolve a DNS name, followed by connecting to SSL by a DNS name. When one or more of the terminals switches to dial-up, the machine is able to ping IP addresses all over the internet, but it times out when connecting to something using a DNS name.
I thought perhaps it was a problem with our internal DNS server, so I tried the ISP DNS as well as a public DNS server, none of which fixed the problem. It is occurring on two separate service providers, so I don't think it is a matter of the ISP blocking anything (why they would block DNS anyway, I don't know).
I have compared the PIX firewall configurations and the only difference that I can see is that the two having the problem do not have the line
pdm logging informational 100
I don't know how PDM logging would have any effect on the problem, but I went ahead and added the line a few minutes ago, just to rule it out 100%.
Both of the stores that are having this problem are on cable internet, but on two different providers.
All of the LAN cabling is brand new, installed specifically for this purpose. The cabling has been tested and shows no problems. (I also don't think the cabling has anything to do with the issue because even when they are having the problem, a constant, uninterrupted ping can be done both from and to the terminals).
According to the company that we purchased the terminals from, all of the programming is identical, aside from the terminal ID.
I can not think of anything else to rule out. Does anyone know of something within a PIX that might be causing this that would not be evident when comparing configurations using the SHOW RUN command?
Does anyone have any ideas as to where I should look next?
Thanks,
Ben
Forth Foods, Inc.