Your firewall is one of the most critical protection mechanisms for your network, so choosing the right firewall is an important step in establishing a secure network and maintaining PCI DSS compliance. The PCI Council does not maintain a list of approved firewall brands or models. However, The PCI DSS does have specific requirements that your firewall must support. If you are preparing to purchase a firewall to protect the perimeter of your cardholder data environment, keep the following feature requirements in mind:

Network Security Control - A New PCI DSS 4 Term
As of version 4.0 of the PCI DSS, the Requirements now apply more broadly to Network Security Controls (NSCs).

Stateful Packet Inspection
For compliance with requirement 1.4.2 of the PCI DSS, a firewall must support stateful packet inspection (SPI). Stateful packet inspection allows “established” connections to communicate back into your cardholder data environment (CDE), and blocks unsolicited traffic. SPI works like a phone that only allows outbound calls. You can call other people, but they can’t call you. The only way they can talk to you is if you call them first. SPI protects your network from prying eyes and uninvited traffic. Don’t use a firewall to protect your CDE unless you can confirm that it supports SPI.

Firewall Zones
If you have any services that require outside access (Email server, VPN server, or web server) then these servers must be placed in a DMZ, consistent with the traffic-restriction requirements in 1.4.1-1.4.2 (components that store cardholder data not being directly accessible from untrusted networks is covered separately under 1.4.4). In addition, all devices that store cardholder data must be located in an internal network zone segregated from the DMZ and other untrusted networks. Firewalls that can segregate and protect multiple inside networks using a customizable access control list give you the best flexibility to meet these requirements.

Logging
Logs from your firewall need to be sent to a centralized, log server (Requirement 10.3.3). The easiest way to meet this requirement is to use a firewall that can send logs to a syslog server for aggregation and analysis.

Intrusion Prevention/Intrusion Detection
Keep in mind that your CDE must be protected with IPS or IDS (PCI DSS Requirement 11.5.1). It is not required that the IPS/IDS be integrated in your firewall, but it can be, and many business-grade firewalls include it. Firewalls that include IPS or IDS protection can be used to meet this requirement in a simple and cost-effective way. If your IPS/IDS is not integrated into your firewall, make sure that you are able to mirror port traffic on your network switch so that your IDS can monitor traffic into and out of your CDE.

Ongoing Support from the Vendor
All devices used in your CDE must be updated and patched (PCI DSS Requirement 6.3.3). Choose a firewall vendor that provides regular firmware updates and timely security patches to keep your firewall protected against newly discovered vulnerabilities.