Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kinmun
New Contributor II

firewall design for PCI DSS requirement

some questions regarding firewall design.

for meeting the PCI DSS  requirement, can i use the same vendor for 1st tier and 2nd tier firewall?

eg. 1st tier firewall is fortigate, can i use fortigate again for 2nd tier firewall?

or I need to use another vendor?

4 REPLIES 4
MikePruett
Valued Contributor

You can have a third party scan your device and tell you if your external IP space (or the external IP tied to the PCI portion) is compliant. You will want to enable strong crypto.

 

I haven't been forced to provide multiple vendors for anything as long as the vendor in use is compliant to their requirements.

Mike Pruett Fortinet GURU | Fortinet Training Videos
emnoc
Esteemed Contributor III

You can use whatever you want  fortinet checkpoint  cisco jumper paloalto etc......

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kinmun
New Contributor II

thanks for the clarification.

i went through the PCI specs but it didnt mentioned abt FW vendor. just want to make sure.

emnoc
Esteemed Contributor III

Just study the appropriate sections like sec #1-10 for the most part. Push back if you get a pain-in-as auditor. The PCI-DSS versions are not specific in  instructing and as long as you can prove that you meet the "minimum  requirement" than you have meet compliancy

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors