I am attempting to prepare a solution for a level 3 merchant that needs to have the ability to capture payment card data remotely at workshops. They are working on a web portal that will have a transaction service perform all of their payment processing. Basically, I am thinking about setting up their firewall to use RSA SecurID tokens to provide a second authentication layer to create a secure VPN tunnel into their network, which will allow them to access their internal payment processing portal. I just need to know if this will meet PCI DSS.
Thanks,
Chad