Using linux firewalls for PCI compliant infrastructure
Siim Põder <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Hi We are using linux-based servers as firewalls for PCI compliant infrastructure. During audits it has been OK so far but security people internally have suggested that maybe a commercial product would be better suited for PCI infrastructure (as it is pretty critical). I'm personally very happy with the iptables firewalls - we can use all the standard components for firewalls that we use for everything else (including standard administration methods, patching and so forth). What do you think, would a commercial firewall provide a tangible improvement in security? Is anyone else using linux-based firewalls for PCI (or otherwise sensitive) infrastructure? Thanks, Siim