A PCI firewall review should not begin when the assessor sends the evidence request. By that point, broad rules, unclear segmentation, and missing ownership can turn a routine review into an urgent cleanup project.
The useful question is not simply, “Do we have a firewall?” It is whether the current configuration supports the intended protection of the cardholder data environment.
Review the paths into and out of sensitive zones
- Which networks and systems can reach the cardholder data environment?
- Are the sources and destinations specific and justified?
- Are only required services allowed?
- Are Internet-facing paths tightly controlled?
- Are management services separated from ordinary user access?
Check whether segmentation is real
Diagrams and policy documents may describe clean zones, but the firewall rules, address groups, interfaces, and routing assumptions determine whether the boundary is actually enforced.
- Look for broad inter-zone policies.
- Review object groups that contain more systems than expected.
- Check for temporary migration or troubleshooting rules.
- Confirm that alternate paths do not bypass the intended control point.
Prepare evidence that is easy to follow
Record the rule identifier, purpose, owner, source, destination, service, logging state, and review outcome. Where an exception exists, make the approval and expiry clear.
ConfigSentry can help turn the FortiGate configuration into structured findings and standards-aligned evidence. It supports the technical review but does not replace PCI scope decisions or assessor judgement.
Next step: run a configsentry audit before the formal review and use the findings to resolve broad access, weak evidence, and hidden exceptions while there is still time.