Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jeff363
New Contributor

PCI Non Compliance HTTP/1.0 Protocol Downgrade Detected

How do I Configure server to reject HTTP/1.0 requests with "505 HTTP Version Not Supported" status and enforce minimum HTTP/1.1 protocol version?  I am using Fortigate 60f and I need to make necessary changes so that my Merchant Service PCI Compliance passes.  This is the last setup that I need and would like to make the fix with GUI, not CLI.  Any help would be great appreciated.

12 REPLIES 12
gt57
New Contributor

If PCI compliance is your only pentest, could you NAT your PCI device(s) to another, external IP address that is not used by SSL/WEB VPN and have your PCI compliance only check that address?

jeff363
New Contributor

Logically that sounds like an alternative action but as far as I can tell, I only have one external IP address, which comes from the modem. I’m not overly savvy with network connection so if there’s another way of creating a alternate external IP address to use, I’d love to learn

gt57
New Contributor

Check with your ISP regarding getting a second IP address.  You can map this IP address to the internal IP address of the PCI device(s).

 

If you are unsure how to configure NAT in the Fortigate, I would recommend enlisting a FortiGate consultant to do this for you.

 

Additionally, you could put your PCI device(s) on a separate, isolated VLAN if not already.  I am not a PCI expert but exposing your PCI devices to your LAN probably violates something.

 

Another solution, which would require a 2nd IP address is to put another, low-end firewall dedicated for PCI that would not have the SSL/WEB VPN.  Essentialy build a separate network for PCI.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors