T.M.A.S. Hosted SaaS: firewall and whitelist guide for security teams

Discover essential firewall and whitelist strategies to enhance your security measures for T.M.A.S. Hosted SaaS environments.

Table of Contents

    This article lists all domains, IP addresses, ports, and email sender addresses that security teams need to whitelist for Storetraffic T.M.A.S. hosted SaaS infrastructure. If your firewall filters by IP rather than DNS, use the addresses below.

    Domains and IPs to Whitelist

    Service DNS Name IP Address Port
    T.M.A.S. Web Portal, Pearl traffic push www.smssoftware.net 70.38.0.251 443 (HTTPS)
    Pearl device communication endpoint pep.smssoftware.net 70.38.0.248 443 (HTTPS)
    Retail Genie Web Portal www.retail-genie.com 70.38.0.252 443 (HTTPS)
    STC and 3D Scope traffic polling polling.smssoftware.net 70.38.0.253 443 (HTTPS)
    3D Scope I & II, Irisys, and Brickstream traffic push push.smssoftware.net 70.38.0.254 443 (HTTPS)
    2D Easy (Optex) traffic push altpush.smssoftware.net 70.38.0.244 443 (HTTPS)

    Recommended approach: Whitelist by DNS name wherever possible. Storetraffic may update IP addresses during infrastructure maintenance; DNS-based whitelisting ensures uninterrupted communication. If your firewall requires IP-based rules, all addresses above are on the 70.38.0.x subnet.

    Email Sender Addresses

    Scheduled report emails and system notifications are sent from the following address. Whitelist it in your email SMTP/spam filter to ensure delivery:

    Service Sender Address
    T.M.A.S. scheduled reports NOTICE@smssoftware.net

    The sender address was changed from noreply@smsmsoftware.net to NOTICE@smssoftware.net on August 5, 2025. Update any legacy SMTP rules accordingly.

    How Storetraffic Devices Communicate

    All Storetraffic devices communicate outbound to the SaaS platform over HTTPS (port 443). No inbound firewall ports need to be opened on your network — the devices initiate the connection.

    • Pearl sensors push traffic data to pep.smssoftware.net:443 via HTTPS. No custom router or firewall rules are needed unless your network blocks outbound HTTPS.
    • 3D Scope II pushes to push.smssoftware.net:443 via HTTPS SOAP.
    • 3D Scope (1st Gen) and STC devices are polled by the SaaS platform from polling.smssoftware.net:443.
    • 2D Easy (Optex) pushes to altpush.smssoftware.net:443.

    Verifying Device Communication Settings

    To confirm that devices are configured with the DNS name rather than a static IP, refer to the device-specific articles below:

    Testing Connectivity

    To verify that your network allows communication with the SaaS platform, open a browser on the same network as the device and navigate to:

    https://pep.smssoftware.net/tmas/rest/dbrfAPI/

    If the page loads successfully, your network settings are correct. If the page does not load, consult your network or firewall team to confirm the domains above are whitelisted.

    Notes

    • Storetraffic recommends whitelisting by DNS name rather than IP address. DNS-based rules continue to work if IPs change during maintenance.
    • All communication uses HTTPS (port 443) — no custom ports are required.
    • No inbound ports need to be opened on your firewall. All device communication is outbound-initiated.
    • The former IP addresses (209.29.131.x range) were retired in 2020 and are no longer in service.
    • How does the Pearl device communicate with the SaaS platform?
    • How do I configure 3D Scope II push settings for T.M.A.S. hosted SaaS?
    • Why am I not receiving my scheduled report emails?
    • How do I troubleshoot a Pearl device that is offline?
    header-top-left-border Created with Sketch.
    header-top-right-border Created with Sketch.