<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hardening guidance for pfSense (PCI DSS)]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">We use the official pfSense AMI in AWS environments that need to comply with PCI DSS.</p>
<p dir="auto">One of the requirements I have to meet requires me to develop a configuration standard for pfSense (a document which describes how it should be configured), and this standard must be based on industry accepted sources. The source can be the vendor.</p>
<p dir="auto">Are there any official security best practice guides or hardening guides from Netgate I can use to help?</p>
<p dir="auto">Lots of solid community guides out there but unfortunately they won't be accepted by the auditors as a source.</p>
<p dir="auto">Thank you</p>
<p dir="auto">Hayden</p>
]]></description><link>https://forum.netgate.com/topic/172169/hardening-guidance-for-pfsense-pci-dss</link><generator>RSS for Node</generator><lastBuildDate>Fri, 14 Aug 2026 08:50:01 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/172169.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 13 May 2022 23:29:23 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Hardening guidance for pfSense (PCI DSS) on Tue, 24 May 2022 22:33:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robh-0">@<bdi>robh-0</bdi></a> Hi Rob, requirement 2.2 in PCI DSS v3.2.1 is to create configuration standards for all in-scope system components. Here is the requirement text:</p>
<p dir="auto"><em>2.2 Develop configuration standards for all system components. Assure that these standards address all known security vulnerabilities and are consistent with industry-accepted system hardening standards. Sources of industry-accepted system hardening standards may include, but are not limited to:</em></p>
<p dir="auto">• <em>Center for Internet Security (CIS)</em><br />
• <em>International Organization for Standardization (ISO)</em><br />
• <em>SysAdmin Audit Network Security (SANS) Institute</em><br />
• <em>National Institute of Standards Technology (NIST).</em></p>
<p dir="auto">As an update, I've now been advised that I can use the firewall STIG to create my configuration standard (Firewall SRG - Ver 2, Rel 2  https://public.cyber.mil/stigs/downloads). It's not pfSense specific so it will be a case of going through and applying the recommendations to pfSense where applicable.</p>
<p dir="auto">So for me this is sorted out - thanks for your responses.</p>
]]></description><link>https://forum.netgate.com/post/1043561</link><guid isPermaLink="true">https://forum.netgate.com/post/1043561</guid><dc:creator><![CDATA[haydenj]]></dc:creator><pubDate>Tue, 24 May 2022 22:33:39 GMT</pubDate></item><item><title><![CDATA[Reply to Hardening guidance for pfSense (PCI DSS) on Mon, 16 May 2022 18:54:10 GMT]]></title><description><![CDATA[<p dir="auto">following</p>
]]></description><link>https://forum.netgate.com/post/1042428</link><guid isPermaLink="true">https://forum.netgate.com/post/1042428</guid><dc:creator><![CDATA[flat4]]></dc:creator><pubDate>Mon, 16 May 2022 18:54:10 GMT</pubDate></item><item><title><![CDATA[Reply to Hardening guidance for pfSense (PCI DSS) on Mon, 16 May 2022 18:32:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/haydenj">@<bdi>haydenj</bdi></a> said in <a href="/post/1042175">Hardening guidance for pfSense (PCI DSS)</a>:</p>
<blockquote>
<p dir="auto">Hi,</p>
<p dir="auto">We use the official pfSense AMI in AWS environments that need to comply with PCI DSS.</p>
<p dir="auto">One of the requirements I have to meet requires me to develop a configuration standard for pfSense (a document which describes how it should be configured), and this standard must be based on industry accepted sources. The source can be the vendor.</p>
<p dir="auto">Are there any official security best practice guides or hardening guides from Netgate I can use to help?</p>
<p dir="auto">Lots of solid community guides out there but unfortunately they won't be accepted by the auditors as a source.</p>
<p dir="auto">Thank you</p>
<p dir="auto">Hayden</p>
</blockquote>
<p dir="auto">Hayden,</p>
<p dir="auto">I am very familiar with PCI DSS 3.2.1 and prior, and although I have not had a chance to dig deep into 4.0, I did a quick scan through the new DSS and I do not see any requirement for the use of industry standard firewall hardening. Can you point me to where you got this information?</p>
]]></description><link>https://forum.netgate.com/post/1042425</link><guid isPermaLink="true">https://forum.netgate.com/post/1042425</guid><dc:creator><![CDATA[RobH 0]]></dc:creator><pubDate>Mon, 16 May 2022 18:32:52 GMT</pubDate></item><item><title><![CDATA[Reply to Hardening guidance for pfSense (PCI DSS) on Sat, 14 May 2022 00:18:56 GMT]]></title><description><![CDATA[<p dir="auto">This is probably the closest thing we have to that:<br />
<a href="https://docs.netgate.com/pfsense/en/latest/firewall/best-practices.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/firewall/best-practices.html</a></p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/1042180</link><guid isPermaLink="true">https://forum.netgate.com/post/1042180</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sat, 14 May 2022 00:18:56 GMT</pubDate></item></channel></rss>