Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Firewalls
virtual firewalls -- compliance May 08 2008 07:37PM
Terry (td3201 gmail com) (10 replies)
Re: virtual firewalls -- compliance Jun 11 2008 12:40PM
styler (styler1974 gmail com) (1 replies)
RE: virtual firewalls -- compliance Jun 12 2008 03:29AM
Craig Wright (Craig Wright bdo com au)

See "Santa Claus, Unicorns, and PCI Compliant Products"

There's no such thing as a "PCI Compliant" product (excepting PEDs).

Note: There is a "Listing of PCI Security Standards Council Approved PIN Entry Devices" at: https://www.pcisecuritystandards.org/pin/pedapprovallist.html_. The PED's are the only products to have PCI SSC approval.

Strange... A google search on " site:www.icsalabs.com PCI Stonesoft" gets nothing.

Stonesoft is ICSA labs certified - it is not a PCI compliant product as there is no such thing. ICSA is testing Web Application Firewalls for PCI-DSS standards compatibility - this is not the same thing.
http://www.icsalabs.com/icsa/topic.php?tid=8913$2e2258c8-68384de7$d1d5-0
2872c54

Notice that Stonesoft is not a WAF.

I do not even know of a PCI "Product capability assurance report" for stonesoft. If there is it is really new - that is after this email.

Next, Stonbesoft is ONLY ICSA certified in NAT mode and NOT bridge mode. If you read the report you will see: "The StoneGate was a router-based product that packet filtered network services inbound and outbound. While the Stonegate does supports an IP only bridging mode, the product was configured in NAT mode for inbound and outbound services "

On top of this, there are issues that have to be addressed when installing it to make it pass a PCI audit. In the ICSA test there where a number of issues that Stonesoft needed to fix:
"The following logging criteria violations were found by the Network Security Lab team during testing and addressed by Stonesoft Inc:
. The product did not log certain ICMP messages sent directly to or through it.
. The product did not log certain raw IP Protocols directed to or through it.
. The product allowed TCP packets inbound and outbound without a properly established TCP
. session for RSSP services.
. The product was susceptible to a variety of trivial Denial-of-Service attacks.
. The product incorrectly terminated TCP connections when sent spoofed/invalid RST packets."

So it is NOT PCI compliant. It may be setup within a control framework that could be PCI compliant, this is NOT the same thing.

Regards,
Craig Wright GSE

Craig Wright
Manager, Risk Advisory Services

Direct : +61 2 9286 5497
Craig.Wright (at) bdo.com (dot) au [email concealed]
+61 417 683 914

BDO Kendalls (NSW-VIC) Pty. Ltd.
Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497
http://www.bdo.com.au/

The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.

Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at http://www.bdo.com.au/ or by emailing mailto:administrator (at) bdo.com (dot) au. [email concealed]

BDO Kendalls is a national association of separate partnerships and entities. Liability limited by a scheme approved under Professional Standards Legislation.
-----Original Message-----

From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On Behalf Of styler
Sent: Wednesday, 11 June 2008 10:40 PM
To: firewalls (at) securityfocus (dot) com [email concealed]
Subject: Re: virtual firewalls -- compliance

All,

Just wanted to throw this in - we're using a virtual firewall from Stonesoft
(see link) in our environment:

http://www.stonesoft.com/en/products_and_solutions/solutions/technology_
solutions/virtual_environments/

It's been certified by ICSA labs as PCI compliant and multiple virtual
firewalls can be centrally managed. I've also heard that they're IPS
product will certified for use soon.

Sam
Firewall Administrator

Terry-7 wrote:
>
> Hello all,
>
> I am throwing around the idea of using linux firewalls in vmware for
> customer environments. The customers may or may not have
> HIPAA/PCI/sOX/etc requirements. This is in the planning stages. Any
> of you have experience heading down this route? PCIDSS doesn't
> explicitly state problems with virtual firewalls, it seems to focus on
> the logic of the rules.
>
> Thanks!
>
>

--
View this message in context: http://www.nabble.com/virtual-firewalls----compliance-tp17157866p1777659
3.html
Sent from the Firewall (securityfocus.com) mailing list archive at Nabble.com.

[ reply ]
Re: virtual firewalls -- compliance May 12 2008 07:37AM
Babu.N (babun intoto com)
Re: virtual firewalls -- compliance May 11 2008 01:35AM
David M. Zendzian (dmz dmzs com)
Re: virtual firewalls -- compliance May 10 2008 11:18PM
Erik Harrison (eharrison gmail com) (1 replies)
Re: virtual firewalls -- compliance May 13 2008 05:25AM
Chris Brenton (cbrenton chrisbrenton org)
Re: virtual firewalls -- compliance May 10 2008 02:08PM
Ron Brown (brownr mmc org)
Re: virtual firewalls -- compliance May 10 2008 02:02PM
Chris Clymer (chris chrisclymer com)
Re: virtual firewalls -- compliance May 10 2008 12:00AM
Joseph Jenkins (maillist breathe-underwater com)
RE: virtual firewalls -- compliance May 09 2008 11:51PM
Craig Wright (Craig Wright bdo com au) (1 replies)
RE: virtual firewalls -- compliance May 12 2008 04:53PM
Dan Lynch (DLynch placer ca gov) (1 replies)
RE: virtual firewalls -- compliance May 12 2008 09:24PM
Craig Wright (Craig Wright bdo com au) (1 replies)
Re: virtual firewalls -- compliance May 20 2008 01:23PM
David M. Zendzian (dmz dmzs com) (1 replies)
Re: virtual firewalls -- compliance May 20 2008 10:19PM
David M. Zendzian (dmz dmzs com)
RE: virtual firewalls -- compliance May 09 2008 11:34PM
Srinivasa Addepalli (srao intoto com)
Re: virtual firewalls -- compliance May 09 2008 11:30PM
Jeremiah Cornelius (jeremiah nur net)







 

Privacy Statement
Copyright 2009, SecurityFocus