some questions regarding firewall design.
for meeting the PCI DSS requirement, can i use the same vendor for 1st tier and 2nd tier firewall?
eg. 1st tier firewall is fortigate, can i use fortigate again for 2nd tier firewall?
or I need to use another vendor?
You can have a third party scan your device and tell you if your external IP space (or the external IP tied to the PCI portion) is compliant. You will want to enable strong crypto.
I haven't been forced to provide multiple vendors for anything as long as the vendor in use is compliant to their requirements.
Mike Pruett
You can use whatever you want fortinet checkpoint cisco jumper paloalto etc......
PCNSE
NSE
StrongSwan
thanks for the clarification.
i went through the PCI specs but it didnt mentioned abt FW vendor. just want to make sure.
Just study the appropriate sections like sec #1-10 for the most part. Push back if you get a pain-in-as auditor. The PCI-DSS versions are not specific in instructing and as long as you can prove that you meet the "minimum requirement" than you have meet compliancy
PCNSE
NSE
StrongSwan
User | Count |
---|---|
2636 | |
1400 | |
810 | |
677 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.