This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

PCI Compliance with connected REDs. Auto-fail. Sophos gave up.

We have a recorded instance of a Sophos XG (v17+) failing a PCI compliance scan (by a major provider) because they use RED appliances.   I asked if Sophos could provide me with mitigation policy or something I could give the PCI compliance vendor an exception basis.

Support eventually came back with:

Sophos RED communication is designed to use self-signed certificates between the XG and RED devices.  Self-signed certificates will fail/warn on PCI scans as they are not trusted.

We do not have a document to mitigate this design as there is no vulnerability with using self-signed certificates.

Now, the last sentence is laughable, but the concept that a firewall vendor can't make a PCI compliant hardware-accelerated VPN tunnel is mind boggling.



This thread was automatically locked due to age.
Parents Reply Children
No Data