T.M.A.S. Hosted SaaS: firewall and whitelist guide for security teams
Discover essential firewall and whitelist strategies to enhance your security measures for T.M.A.S. Hosted SaaS environments.
Table of Contents
This article lists all domains, IP addresses, ports, and email sender addresses that security teams need to whitelist for Storetraffic T.M.A.S. hosted SaaS infrastructure. If your firewall filters by IP rather than DNS, use the addresses below.
Domains and IPs to Whitelist
| Service | DNS Name | IP Address | Port |
|---|---|---|---|
| T.M.A.S. Web Portal, Pearl traffic push | www.smssoftware.net | 70.38.0.251 | 443 (HTTPS) |
| Pearl device communication endpoint | pep.smssoftware.net | 70.38.0.248 | 443 (HTTPS) |
| Retail Genie Web Portal | www.retail-genie.com | 70.38.0.252 | 443 (HTTPS) |
| STC and 3D Scope traffic polling | polling.smssoftware.net | 70.38.0.253 | 443 (HTTPS) |
| 3D Scope I & II, Irisys, and Brickstream traffic push | push.smssoftware.net | 70.38.0.254 | 443 (HTTPS) |
| 2D Easy (Optex) traffic push | altpush.smssoftware.net | 70.38.0.244 | 443 (HTTPS) |
Recommended approach: Whitelist by DNS name wherever possible. Storetraffic may update IP addresses during infrastructure maintenance; DNS-based whitelisting ensures uninterrupted communication. If your firewall requires IP-based rules, all addresses above are on the 70.38.0.x subnet.
Email Sender Addresses
Scheduled report emails and system notifications are sent from the following address. Whitelist it in your email SMTP/spam filter to ensure delivery:
| Service | Sender Address |
|---|---|
| T.M.A.S. scheduled reports | NOTICE@smssoftware.net |
The sender address was changed from noreply@smsmsoftware.net to NOTICE@smssoftware.net on August 5, 2025. Update any legacy SMTP rules accordingly.
How Storetraffic Devices Communicate
All Storetraffic devices communicate outbound to the SaaS platform over HTTPS (port 443). No inbound firewall ports need to be opened on your network — the devices initiate the connection.
-
Pearl sensors push traffic data to
pep.smssoftware.net:443via HTTPS. No custom router or firewall rules are needed unless your network blocks outbound HTTPS. -
3D Scope II pushes to
push.smssoftware.net:443via HTTPS SOAP. -
3D Scope (1st Gen) and STC devices are polled by the SaaS platform from
polling.smssoftware.net:443. -
2D Easy (Optex) pushes to
altpush.smssoftware.net:443.
Verifying Device Communication Settings
To confirm that devices are configured with the DNS name rather than a static IP, refer to the device-specific articles below:
- Pearl — No action required. DNS is configured automatically by the Storetraffic app.
- 3D Scope II — 3D Scope II communication with T.M.A.S.
- 3D Scope (1st Gen) — 3D Scope push mode settings
- 2D Easy (Optex) — 2D Easy device info
- V4D — V4D device offline troubleshooting
- Gazelle — Gazelle device offline troubleshooting
Testing Connectivity
To verify that your network allows communication with the SaaS platform, open a browser on the same network as the device and navigate to:
https://pep.smssoftware.net/tmas/rest/dbrfAPI/
If the page loads successfully, your network settings are correct. If the page does not load, consult your network or firewall team to confirm the domains above are whitelisted.
Notes
- Storetraffic recommends whitelisting by DNS name rather than IP address. DNS-based rules continue to work if IPs change during maintenance.
- All communication uses HTTPS (port 443) — no custom ports are required.
- No inbound ports need to be opened on your firewall. All device communication is outbound-initiated.
- The former IP addresses (209.29.131.x range) were retired in 2020 and are no longer in service.
Related Questions
- How does the Pearl device communicate with the SaaS platform?
- How do I configure 3D Scope II push settings for T.M.A.S. hosted SaaS?
- Why am I not receiving my scheduled report emails?
- How do I troubleshoot a Pearl device that is offline?