
74 | Configuring AirWave Dell Networking W-AirWave 8.0 | User Guide
Requirement Description
1.1
Monitoring configuration standards for network firewall devices
When Enabled: PCI Requirement 1.1 establishes firewall and router configuration
standards.
A device fails Requirement 1.1 if there are mismatches between the desired
configuration and the configuration on the device.
When Disabled: firewall router and device configurations are not checked for PCI
compliance, and Pass or Fail status is not reported or monitored.
1.2.3
Monitoring firewall installation between any wireless networks and the cardholder data
environment
When Enabled: A device passes requirement 1.2.3 if it can function as a stateful
firewall.
When Disabled: firewall router and device installation are not checked for PCI
compliance.
2.1
Monitoring the presence of vendor-supplied default security settings
When Enabled: PCI Requirement 2 establishes the standard in which all vendor-
supplied default passwords are changed prior to a device’s presence and operation in
the network.
A device fails requirement 2.1 if the username, passwords or SNMP credentials being
used by AirWave to communicate with the device are on a list of forbidden default
credentials. The list includes common vendor default passwords, for example.
When Disabled: device passwords and other vendor default settings are not checked
for PCI compliance.
2.1.1
Changing vendor-supplied defaults for wireless environments
When Enabled: A device fails requirement 2.1.1 if the passwords, SSIDs, or other
security-related settings are on a list of forbidden values that AirWave establishes and
tracks. The list includes common vendor default passwords. The user can input new
values to achieve compliance.
When Disabled: network devices are not checked for forbidden information and PCI
Compliance is not established.
4.1.1
Using strong encryption in wireless networks
When Enabled: PCI Requirement 4 establishes the standard by which payment
cardholder data is encrypted prior to transmission across open public networks. PCI
disallows WEP encryption as an approved encryption method after June 20, 2010. A
device fails requirement 4.1.1 if the desired or actual configuration reflect that WEP is
enabled on the network, or if associated users can connect with WEP.
When Disabled: AirWave cannot establish a pass or fail status with regard to PCI
encryption requirements on the network.
11.1
Identifying unauthorized wireless devices.
When enabled, a report will indicate a failure if there are unacknowledged rogue APs
present in RAPIDS or there are no wireless rogues discovered in the last three months.
Table 38:
PCI Requirements and Support in AirWave
Kommentare zu diesen Handbüchern