We have a recorded instance of a Sophos XG (v17+) failing a PCI compliance scan (by a major provider) because they use RED appliances. I asked if Sophos could provide me with mitigation policy or something I could give the PCI compliance vendor an exception basis.
Support eventually came back with:
Sophos RED communication is designed to use self-signed certificates between the XG and RED devices. Self-signed certificates will fail/warn on PCI scans as they are not trusted.
We do not have a document to mitigate this design as there is no vulnerability with using self-signed certificates.
Now, the last sentence is laughable, but the concept that a firewall vendor can't make a PCI compliant hardware-accelerated VPN tunnel is mind boggling.
This thread was automatically locked due to age.