ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    WTF is a Managed Firewall?

    Water Closet
    firewalls managedfirewall wtf
    8
    65
    3.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @WrCombs
      last edited by

      @WrCombs said in WTF is a Managed Firewall?:

      @Dashrender said in WTF is a Managed Firewall?:

      @WrCombs said in WTF is a Managed Firewall?:

      well now that I know more about it, I can shake my head when they hire a company to manage the firewall..
      I spoke up earlier and said I'd do it but they'd have to pay me to do it.. that was shut down quickly.

      Why would they have to pay you differently than they are now? You are already being paid. You're hourly, if you are working on the firewall, you're just getting your normal hourly rate. Just like the rest of us here.

      That's outside of my Job as a Point of Sale tech.
      We dont even sell firewalls anymore.

      That's never a valid answer. You are paid by the hour, there is no "scope" of work like that because doing extra work automatically means extra pay. That you don't sell firewalls isn't here nor there.

      That there is no training or expertise or resources makes it unreasonable for them to expect you to have skills that they didn't ask you for or provide you a way to obtain, but you are already properly compensated for this. It's handled by the scope of the hourly work.

      1 Reply Last reply Reply Quote 1
      • WrCombsW
        WrCombs
        last edited by

        from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

        https://i.imgur.com/T6cPJdN.png

        scottalanmillerS WrCombsW 2 Replies Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @WrCombs
          last edited by

          @WrCombs said in WTF is a Managed Firewall?:

          @scottalanmiller said in WTF is a Managed Firewall?:

          @WrCombs said in WTF is a Managed Firewall?:

          and this one says:
          https://www.pcidss.com/listing-category/managed-firewall-services/

          A managed firewall service provides an outsourced, specialist function that configures and maintains firewalls. This provider ensures correct and secure functionality of firewalls, typically on a 24/7 basis from a PCI DSS compliant Secure Operations Centre (SOC).

          That site is full of cookies, but doesnt' ask permissions... and their SSL cert doesn't cover the whole site!

          This was before I went to the PCI Site.

          Gotcha. Just a heads up that you had a browser full of red flags as to that site not being legit. Their glossary of a random term was accurate. But other than that, it's just a random site advertising to people looking for PCI info. Nothing on the site is useful to you, regardless of having been to the PCI site or not. It's an invalid resource just in general.

          WrCombsW 1 Reply Last reply Reply Quote 0
          • WrCombsW
            WrCombs @scottalanmiller
            last edited by

            @scottalanmiller said in WTF is a Managed Firewall?:

            @WrCombs said in WTF is a Managed Firewall?:

            @scottalanmiller said in WTF is a Managed Firewall?:

            @WrCombs said in WTF is a Managed Firewall?:

            and this one says:
            https://www.pcidss.com/listing-category/managed-firewall-services/

            A managed firewall service provides an outsourced, specialist function that configures and maintains firewalls. This provider ensures correct and secure functionality of firewalls, typically on a 24/7 basis from a PCI DSS compliant Secure Operations Centre (SOC).

            That site is full of cookies, but doesnt' ask permissions... and their SSL cert doesn't cover the whole site!

            This was before I went to the PCI Site.

            Gotcha. Just a heads up that you had a browser full of red flags as to that site not being legit. Their glossary of a random term was accurate. But other than that, it's just a random site advertising to people looking for PCI info. Nothing on the site is useful to you, regardless of having been to the PCI site or not. It's an invalid resource just in general.

            Thanks for the heads up.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @WrCombs
              last edited by

              @WrCombs said in WTF is a Managed Firewall?:

              from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

              https://i.imgur.com/T6cPJdN.png

              Yeah... all straightforward, common sense, appropriate stuff that would qualify as serious negligence regardless of PCI.

              WrCombsW 1 Reply Last reply Reply Quote 0
              • WrCombsW
                WrCombs @WrCombs
                last edited by

                @WrCombs said in WTF is a Managed Firewall?:

                from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                https://i.imgur.com/T6cPJdN.png

                Install and maintain a firewall

                That's the requirement

                DashrenderD 1 Reply Last reply Reply Quote 1
                • WrCombsW
                  WrCombs @scottalanmiller
                  last edited by

                  @scottalanmiller said in WTF is a Managed Firewall?:

                  @WrCombs said in WTF is a Managed Firewall?:

                  from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                  https://i.imgur.com/T6cPJdN.png

                  Yeah... all straightforward, common sense, appropriate stuff that would qualify as serious negligence regardless of PCI.

                  how?

                  DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @WrCombs
                    last edited by

                    @WrCombs said in WTF is a Managed Firewall?:

                    @scottalanmiller said in WTF is a Managed Firewall?:

                    @WrCombs said in WTF is a Managed Firewall?:

                    from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                    https://i.imgur.com/T6cPJdN.png

                    Yeah... all straightforward, common sense, appropriate stuff that would qualify as serious negligence regardless of PCI.

                    how?

                    Well - according to Scott - these are pretty much common sense things, and not doing them while claiming to be an IT professional would be professional negligence.

                    WrCombsW 1 Reply Last reply Reply Quote 0
                    • WrCombsW
                      WrCombs @Dashrender
                      last edited by

                      @Dashrender said in WTF is a Managed Firewall?:

                      @WrCombs said in WTF is a Managed Firewall?:

                      @scottalanmiller said in WTF is a Managed Firewall?:

                      @WrCombs said in WTF is a Managed Firewall?:

                      from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                      https://i.imgur.com/T6cPJdN.png

                      Yeah... all straightforward, common sense, appropriate stuff that would qualify as serious negligence regardless of PCI.

                      how?

                      Well - according to Scott - these are pretty much common sense things, and not doing them while claiming to be an IT professional would be professional negligence.

                      oh, I understand that.
                      It's common sense ;

                      1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @WrCombs
                        last edited by

                        @WrCombs said in WTF is a Managed Firewall?:

                        @WrCombs said in WTF is a Managed Firewall?:

                        from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                        https://i.imgur.com/T6cPJdN.png

                        Install and maintain a firewall

                        That's the requirement

                        Exactly as you would expect it to say... nothing stupid like "Managed Firewall".

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @WrCombs
                          last edited by

                          @WrCombs said in WTF is a Managed Firewall?:

                          @scottalanmiller said in WTF is a Managed Firewall?:

                          @WrCombs said in WTF is a Managed Firewall?:

                          from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                          https://i.imgur.com/T6cPJdN.png

                          Yeah... all straightforward, common sense, appropriate stuff that would qualify as serious negligence regardless of PCI.

                          how?

                          All of the requirements, the real ones, are low effort, easily accomplished, and have no political agenda. They result in straight security practices, not in pushing you to specific vendors, products, etc. Nor do they encourage odd or bad behaviour. They are simple, and basic allowing you room to interpret based on what would actually be good security for your specific environment.

                          WrCombsW 1 Reply Last reply Reply Quote 0
                          • WrCombsW
                            WrCombs @scottalanmiller
                            last edited by

                            @scottalanmiller said in WTF is a Managed Firewall?:

                            @WrCombs said in WTF is a Managed Firewall?:

                            @scottalanmiller said in WTF is a Managed Firewall?:

                            @WrCombs said in WTF is a Managed Firewall?:

                            from https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

                            https://i.imgur.com/T6cPJdN.png

                            Yeah... all straightforward, common sense, appropriate stuff that would qualify as serious negligence regardless of PCI.

                            how?

                            All of the requirements, the real ones, are low effort, easily accomplished, and have no political agenda. They result in straight security practices, not in pushing you to specific vendors, products, etc. Nor do they encourage odd or bad behaviour. They are simple, and basic allowing you room to interpret based on what would actually be good security for your specific environment.

                            Oh yeah, that makes sense.

                            1 Reply Last reply Reply Quote 0
                            • jt1001001J
                              jt1001001
                              last edited by

                              Check out Fortigate product. FortiNet offers documentation on setup of their firewalls for PCI DSS compliance:
                              https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-compliance/PCI-DSS.htm?Highlight=PCI
                              They office a subscription service whereby they manage patches/updates for their firewalls as well as monitoring (specifically, Logging, to me it really isn't monitoring) in order to match the "managed firewall" checkbox. Now, I only have a little experience with Fortigate's as we just installed one in our data center as we have a customer requesting us to be compliant (for no apparent reason other than they want us to be, we do not store credit card data and do any processing via https web site)

                              1 Reply Last reply Reply Quote 0
                              • 1
                              • 2
                              • 3
                              • 4
                              • 3 / 4
                              • First post
                                Last post