Advertisement

07.05.2008 at 06:51PM PDT, ID: 23541185
[x]
Attachment Details

Private LAN / DMZ Question / PCI compliance

Asked by novaworks in Network Security, Virtual Private Networking (VPN), WebApplications

Tags:

Hi
I am in need of some education - I've searched google & can't quite find the answer that asking a knowledgable person would be able to answer in 5 seconds.

I am setting up a network that must be PCI compliant.  So - the db must be in a zone not accessable to the internet.  

For the sake of simplicity - lets say there are 2 servers behind a firewall (Cisco ASA)

Server1 - Public IP --> Maps to Internal IP 192.168..30.1  - Ports 80, 443 open (Web Server)
Server 2 - Public IP --> Maps to Internal IP 192.168.30.2 - All ports closed (Db Server)

Both servers also have software firewall - where Remote Desktop port (3389) is open and server 2 has SQL port open 1433

Both servers are accessible by remote desktop if connected to VPN first.

So - my question is - is the above a DMZ zone (server1) and Server2 is in a private LAN.  Is that a typical PCI compliant setup? or is it way off base?  Server2 is still technically connected to the internet but the FW blocks any traffic, but after VPN connection you are behind the FW and can connect so long as the software FW doesn't block it.

Thanks!Start Free Trial
[+][-]07.06.2008 at 07:16PM PDT, ID: 21942445

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 07:34PM PDT, ID: 21942489

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 07:37PM PDT, ID: 21942493

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 07:42PM PDT, ID: 21942505

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 07:52PM PDT, ID: 21942531

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 07:59PM PDT, ID: 21942554

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:13PM PDT, ID: 21942584

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:30PM PDT, ID: 21942621

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:32PM PDT, ID: 21942633

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:44PM PDT, ID: 21942656

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:48PM PDT, ID: 21942667

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Network Security, Virtual Private Networking (VPN), WebApplications
Tags: Network DMZ LAN PCI
Sign Up Now!
Solution Provided By: rslqld
Participating Experts: 1
Solution Grade: A
 
 
[+][-]07.06.2008 at 08:53PM PDT, ID: 21942678

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:55PM PDT, ID: 21942682

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.06.2008 at 08:58PM PDT, ID: 21942689

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628