Server 2012 R2 Essentials - PCI DSS Compliance.


hi,

a customer server administer carries out credit card transactions , has asked carry out necessary changes on server ensure pci dss compliant. have reached point there few vulnerabilities left , hoping advice other users may have dealt similar scenarios. client has single server running windows server 2012 r2 essentials, may factor affecting of changes?

the client has engaged 2 difference pci scanning companies, first has identified port vulnerabilities when address example tls 1.0 issue disables remote access several other critical services.

the other identifies port 80 traffic , port 443 , suggests forwarding port 80 traffic through port 443. although i have read through numerous articles cannot find step-by-step instructional how implement this.

any pointers have had experience in dealing pci compliance appreciated.

thanks in advance,

hi,

>a tls 1.0 issue disables remote access several other critical services.
far know, rdp supports tls 1.1 , 1.2. 

such kb 3080079 - update add rds support tls 1.1 , tls 1.2 in windows 7 or windows server 2008 r2:
https://support.microsoft.com/en-us/help/3080079/update-to-add-rds-support-for-tls-1.1-and-tls-1.2-in-windows-7-or-windows-server-2008-r2

also, may need change rdp security layer settings:
https://technet.microsoft.com/en-us/library/ff458357.aspx

>the other identifies port 80 traffic , port 443 , suggests forwarding port 80 traffic through port 443.
http - tcp 80, , https - tcp 443 port forwarding on router necessary rwa on windows server essentials, if have configured/enabled anywhere access/rwa, not recommended change default ports configuration.

detail steps port forwarding configuring, please reference hardware manufacturer’s documentation.

besides, below articles pci dss compliance, reference.

payment card industry data security standard compliance planning guide:
https://technet.microsoft.com/en-us/library/ee623029.aspx

payment card industry data security standard compliance planning guide:
https://blogs.msdn.microsoft.com/shishirs/2009/10/08/payment-card-industry-data-security-standard-compliance-planning-guide/

best regards,
eve wang

please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Windows Server 2012 Essentials



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file