Security Basics mailing list archives

Re: Re: Firewalls and PCI


From: "Josh Haft" <pacmansyu () gmail com>
Date: Fri, 18 Jan 2008 15:31:23 -0600

On Jan 18, 2008 3:16 PM, Honer, Lance <lhoner () smartgrp com> wrote:
I can't speak for other QSA's but I would have no problem with just one
physical device for all segments.

Grant it the safest solution is would be a separate physical device for
each where it's a different make and model so that a compromise of the
internet facing device would not compromise every other firewall. But
this can open up a whole mess of other problems that is beyond the scope
of this discussion.

Who is this "client" your referring to, I'm not asking for names just
for the relationship here?

Lance


We will be hosting some of their data and they want our environment to
be 'as secure as possible', or at least up to their standards. The
data may or may not fall under PCI requirements, but that's something
we have to do anyway.


Current thread: