PCI Compliance Certification and FortiManager
Posted on 2014-11-20
My company is in the final stages of acquiring a PCI Compliance certification. We're one scanned tested away from obtaining this however the scans that are failing has traffic being directed to a FortiManager appliance. The appliance is a VM, running on a Gen8 HP BL460 blade server with ESXi 5.0 as the Hypervisor. Per Fortinet, the ports that are required to run are 22, 443, 6022, 6023, 53, 123, 514, 541, and 161. Initially we had a full PAT from our external IP address to the internal IP address and so the vulnerability scan was picking up other vulnerabilities. I setup firewall objects for each port and rewrote the policy to pass traffic on those ports only. The scan comes back and and says that we're still failing on 22 and 443, which are secure, right? Our FortiManager appliance is running at 5.0.6 currently. There ARE newer versions of firmware which I'm not going to ignore as an option, but I want to be certain this is going to resolve my issue before spending the time to update the appliance. Fortinet's technical support hasn't been much help, ironically, although I suspect the issue their is a matter of customer service, not intelligence.
Has anyone had to deal with PCI compliance and Fortinet Appliances? Can someone tell me that fix for this is just to upgrade the appliance's firmware? Any help would be appreciated.