DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Pitney Bowes Franking Machine

  • jp1977
  • Topic Author
  • User
  • User
More
11 Dec 2017 15:05 #1 by jp1977
Pitney Bowes Franking Machine was created by jp1977
Hi,
I am trying to get a Pitney Bowes (PB) Franking machine to obtain it's updates over the internet but it doesn't work. I am looking for some advice on how best to configure the firewall and/or somehow gain access to logs that would show me what is being blocked, either in or out.

We are running through a Draytek Vigor 3900 and for this test, there are currently no (as in zero) rules set up in the firewall to block connections. The default is to allow and internet access generally with this set up is working fine.

If I connect the PB machine at home (a Virgin Media Fibre Connection) it works immediately. In work however, it times out after about 10 minutes.

I have looked at the Network Config Instructions here (summarised further on in this post):

https://www.pitneybowes.com/ca/en/support/topics/connection/network-settings-to-connect-to-the-pb-data-center.html

In addition to running the firewall clean, I have applied the above instruction as best I can (some things, such as file extensions don't seem applicable?), but it still doesn't work. Furthermore, I cannot see any specific event messages in the Web UI saying something is being blocked.

Has anyone else had experience with this?

Note I have previously raised a ticket with Pitney Bowes (they've basically said that if it works at home, then it's not their problem) and with Draytek, who, beyond asking for IP Address Info, they've yet to come back to me (3 weeks counting).

Here is the additional info provided to Draytek:

• I can Ping the Franking Machine and the Draytek - IP of Draytek is 192.168.20.1, IP of Franking machine is 192.168.20.224 (with 192.168.20.1 set as Gateway)
• Franking Machine is connected to a dumb Dlink Gigabit Switch, which in turn is plugged into LAN 1 on the Draytek

For reference, the above link leads to the following instructions (amongst others):

Firewall Settings
Protect your network by connecting your meter through a firewall. If unrestricted outbound access is not allowed, network access can be made by allowing these domains. Use domain names instead of IP addresses since IP addresses will change.
The following file extensions must be allowed through your network and firewall:
File Type
File Extension
DEC
.dcz
EMD
.zmd
Graphics
.gar
Rate Manager
.rmz
CCD
.bin
Snippet File
.GAU
Data Capture
.Kj1
Rate File
.Rte
The following domains must also be accessible through your network and firewall; accessible without any obstructions – ANY URL containing:
pb.com
dlsdlp1T.pb.com
distservp1.pb.com
dlsdlp1z.pb.com
cometservp1.pb.com
dlsdlp1.pb.com
acctservp1.pb.com
dlsdlp1b.pb.com
pbdlsp1.pb.com
pbdlst1.pb.com
pbdlsp1t.pb.com
dlsdlp1.pb.com
s3.amazonnaws.com (PC Meter Connect)
pbsmartpostage.pb.com
pbgdspdlp1a.pb.com

Character limit reached. Continued in next post...

Please Log in or Create an account to join the conversation.

  • jp1977
  • Topic Author
  • User
  • User
More
11 Dec 2017 15:06 #2 by jp1977
Replied by jp1977 on topic Re: Pitney Bowes Franking Machine
...Continued:

NOTE: URLs accessed by your Pitney Bowes system may contain the above strings anywhere within the URL. Your firewall may need to be configured using “wildcards”, for example *pb.com* (using an asterisk).
If IP Addresses must be used, Pitney Bowes recommends the firewall be set to allow unrestricted access to the full blocks of Pitney Bowes IP Address Ranges listed:
152.144.128.0 - 152.144.128.255
172.28.106.0 - 172.28.107.255
172.31.224.0 - 172.31.224.255
199.231.32.0 - 199.231.47.255
209.85.128.0 - 209.85.255.255
Alternatives for restricted FTP Protocols
Some meters support using HTTPS as an alternative to FTP. If you are using PC Meter Connect, access the “Internet Settings” menu from the application and select HTTPS mode. If your meter does not support HTTPS, the option will be greyed out.
The System will communicate to PB secure server(s) via HTTPS over port 443
Use Port 53 for DNS lookup
The System will communicate to PB data server via FTP, reference port details as shown:
Ports and Protocols required
Type Protocol Port Function
DNS USP 53 Postage by Phone & Web Services
HTTP TCP 80 Postage by Phone & Web Services
HTTPS TCP 443 Postage by Phone
Software & Rate Updates
Graphics Uploads
Firewall must be set to ACTIVE mode and allow ephemeral ports.

Please Log in or Create an account to join the conversation.

  • silverstreak_2006
  • User
  • User
More
20 Dec 2017 16:23 #3 by silverstreak_2006
Replied by silverstreak_2006 on topic Re: Pitney Bowes Franking Machine
uPNP?

Please Log in or Create an account to join the conversation.