Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Are ACL's good enough for PCI

Hi there,

Our PCI auditor has said that ACL's and vlaning between test/office/production (cardholder) etc networks are not sufficient, and that we will need firewalls. However at a PCI conference we were advised that ACL's and vlaning were sufficient.

Can anyone advise me what the truth is?

Thanks!

6 REPLIES
Cisco Employee

Re: Are ACL's good enough for PCI

Hi Astro,

ACLs are not enough protection from our experience with auditors and compensating controls.

VLANs are a sufficient method of segmentation at layer two. You do not require physical separation of your POS network at this layer.

However, at layer 3, you do need a stateful firewall. ACLs do not suffice.

On a side note, Truth is a interesting word, from a compliance perspective. I have heard from retailers that, in general, Audits can vary from QSA to QSA. So, ultimately, I would advise you to work with your auditor to know their version of "truth" and if you believe that they are not being realistic, consider speaking with another QSA. In this particular case, I think you will find that the answer will be consistent across QSAs that you will require a true firewall.

Does this help?

Christian

Cisco Employee

Re: Are ACL's good enough for PCI

You may also need to be concerned with where you are using VLAN's as wheather they are sufficient. If the vlan seperates a public internet segment and a segment with POS, that will probibly not be sufficient. If the MAC table gets overloaded the switch may go into full forwarding mode merging the internet and POS traffic compromising your systems. An overload loke this is not as likely when VLAN'ing private segments. And in any event the Internet traffic would not be merged with private traffic.

New Member

Re: Are ACL's good enough for PCI

Thanks for your posts.

New Member

Re: Are ACL's good enough for PCI

The PCI spec does specifically mention stateful "firewalls". We were successful in presenting a 6509 with VLANs for layer 2 segmentation, with the firewall feature set on the MSFC providing stateful capability. It took a bit of discussion, though. I think the auditors in general expect, and are more comfortable with, physical separation.

New Member

Re: Are ACL's good enough for PCI

We have had 2 different PCI audits and neither organization would accept ACLs.

New Member

Re: Are ACL's good enough for PCI

interesting, we are successful with ACL's for internal segmentation and Firewalls for internet and wireless connectivuty

984
Views
0
Helpful
6
Replies