Server 2012 R2 Essentials - PCI DSS Compliance.
hi,
a customer server administer carries out credit card transactions , has asked carry out necessary changes on server ensure pci dss compliant. have reached point there few vulnerabilities left , hoping advice other users may have dealt similar scenarios. client has single server running windows server 2012 r2 essentials, may factor affecting of changes?
the client has engaged 2 difference pci scanning companies, first has identified port vulnerabilities when address example tls 1.0 issue disables remote access several other critical services.
the other identifies port 80 traffic , port 443 , suggests forwarding port 80 traffic through port 443. although i have read through numerous articles cannot find step-by-step instructional how implement this.
any pointers have had experience in dealing pci compliance appreciated.
thanks in advance,
>a tls 1.0 issue disables remote access several other critical services.
far know, rdp supports tls 1.1 , 1.2.
such kb 3080079 - update add rds support tls 1.1 , tls 1.2 in windows 7 or windows server 2008 r2:
https://support.microsoft.com/en-us/help/3080079/update-to-add-rds-support-for-tls-1.1-and-tls-1.2-in-windows-7-or-windows-server-2008-r2
also, may need change rdp security layer settings:
https://technet.microsoft.com/en-us/library/ff458357.aspx
>the other identifies port 80 traffic , port 443 , suggests forwarding port 80 traffic through port 443.
http - tcp 80, , https - tcp 443 port forwarding on router necessary rwa on windows server essentials, if have configured/enabled anywhere access/rwa, not recommended change default ports configuration.
detail steps port forwarding configuring, please reference hardware manufacturer’s documentation.
besides, below articles pci dss compliance, reference.
payment card industry data security standard compliance planning guide:
https://technet.microsoft.com/en-us/library/ee623029.aspx
payment card industry data security standard compliance planning guide:
https://blogs.msdn.microsoft.com/shishirs/2009/10/08/payment-card-industry-data-security-standard-compliance-planning-guide/
best regards,
eve wang
please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Windows Server 2012 Essentials
Comments
Post a Comment