Pesapal.com

Forum

Welcome, Guest
Username
Password:
 

IP Whitelisting
(1 viewing) (1) Guest
This is the optional category header for the Suggestion Box.
  • Page:
  • 1

TOPIC: IP Whitelisting

IP Whitelisting 5 years, 5 months ago #1538

To add further security and also to enable dev-testing, it would be great to get a list of IPs that can be whitelisted on a firewall.

Similar to what Paypal is offering: www.paypal-knowledge.com/infocenter/inde...=en_US&direct=en

Re: IP Whitelisting 5 years, 4 months ago #1541

  • Ayesh
  • OFFLINE
  • Senior Boarder
  • Everythings works for good.
  • Posts: 53
Not sure exactly what you're concerned with on the issue of security as according to PesaPal there are no real transactions since one is using a demo account and you don't actually not need an actual merchant account to test your code.
Don't let what shows up for a moment become our eternity.

Re: IP Whitelisting 5 years, 4 months ago #1546

@Ayesh: so our dev/qa/staging environment are of course not publicly reachable. We could whitelist incoming IPN requests from Pesapal if we had a list of IPs to whitelist.

Without this we actually have to make our dev/qa/staging environment publicly available.

Re: IP Whitelisting 5 years, 4 months ago #1547

  • lazro
  • OFFLINE
  • Administrator
  • Pesapal
  • Posts: 404
Greetings lifeofguenter,

For IPN to work it's a requirement that your server be publicly available. Unfortunately we do not have a list of IPs you can whitelist. It's easier if you have the server publicly available or else see how you can do a whitelist using the domain name rather than an IP.
Regards,

Lazaro Ong'ele
Web Developer

Skype: Lazrotep
+254-020-249-5438 ; +254-706-191-729
Dagoretti Lane, Off Naivasha Road.

Facebook: www.facebook.com/pesapal
Twitter: twitter.com/PesaPal
Helpdesk: support.pesapal.com
This e-mail address is being protected from spambots. You need JavaScript enabled to view it.

Re: IP Whitelisting 5 years, 4 months ago #1548

lazro wrote:
(...) see how you can do a whitelist using the domain name rather than an IP.


That would only work if you send-out the IPN requests from the same IP as what www.pesapal.com is pointing to - or can you please elaborate what you mean by domain whitelist?

Re: IP Whitelisting 5 years, 4 months ago #1549

  • Ayesh
  • OFFLINE
  • Senior Boarder
  • Everythings works for good.
  • Posts: 53
Another option if you are not able to white the sandbox domain would be to post to post test transactions from your system and the initiate a get by posting the following as params for your test url to imply an IPN call bearing in mind that....

PesaPal will call the URL you entered above with the following query parameters:

pesapal_notification_type=CHANGE

pesapal_transaction_tracking_id=<the unique tracking id of the transaction>

pesapal_merchant_reference=<the merchant reference>

You must respond to the HTTP request with the same data that you received from PesaPal. For example:

pesapal_notification_type=CHANGE&pesapal_transaction_tracking_id=XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX&pesapal_merchant_reference=12345

........ for example if your box is localhost you can do

localhost/devbox/index.php?pesapal_notif...hant_reference=12345

from there on the IPN code will complete the rest of the curl call and return data with the status and you be able to examine the returned object and ascertain if your code works as it should or if has any errors.
Don't let what shows up for a moment become our eternity.

Re: IP Whitelisting 5 years, 4 months ago #1550

  • lazro
  • OFFLINE
  • Administrator
  • Pesapal
  • Posts: 404
Instead of whitelisting the IP, whitelist wwww.pesapal.com and demo.pesapal.com. Is that possible?
Regards,

Lazaro Ong'ele
Web Developer

Skype: Lazrotep
+254-020-249-5438 ; +254-706-191-729
Dagoretti Lane, Off Naivasha Road.

Facebook: www.facebook.com/pesapal
Twitter: twitter.com/PesaPal
Helpdesk: support.pesapal.com
This e-mail address is being protected from spambots. You need JavaScript enabled to view it.

Re: IP Whitelisting 5 years, 4 months ago #1565

lazro wrote:
Instead of whitelisting the IP, whitelist wwww.pesapal.com and demo.pesapal.com. Is that possible?


That only makes sense if pespal is only sending requests from the IPs that those hosts are pointing to, so currently:


  • 173.244.176.226
  • 46.4.104.209


But that is most likely not the case?

Is there any specific reason why you can't release the IPs just as PayPal does?

Re: IP Whitelisting 5 years, 4 months ago #1566

  • lazro
  • OFFLINE
  • Administrator
  • Pesapal
  • Posts: 404
Hello lifeofguenter,

We do not have a list of IPs as PayPal does. We also can't guarantee that the current IPs will not change in the near future.

Kindly do have your server publicly available for this to work.
Regards,

Lazaro Ong'ele
Web Developer

Skype: Lazrotep
+254-020-249-5438 ; +254-706-191-729
Dagoretti Lane, Off Naivasha Road.

Facebook: www.facebook.com/pesapal
Twitter: twitter.com/PesaPal
Helpdesk: support.pesapal.com
This e-mail address is being protected from spambots. You need JavaScript enabled to view it.
  • Page:
  • 1