A ground-up compliant infrastructure for a card payment processor, passed on first audit submission with zero findings.
Ground-up design and deployment of a fully PCI-DSS compliant network infrastructure for an organization processing credit card payments. The solution spans hyperconverged compute, a structured switching fabric, and a dual-stage firewall architecture with ISP redundancy. Every design decision treated PCI-DSS requirements as a hard architectural constraint rather than an afterthought.
The client needed to pass an upcoming PCI-DSS audit but lacked infrastructure capable of satisfying the requirements.
There was no defined Cardholder Data Environment. Critical payment systems shared flat network space alongside general IT and corporate traffic.
No perimeter segmentation. A single firewall with no DMZ tier allowed internet-facing systems direct lateral access into internal networks.
A single ISP connection provided zero redundancy for a business model where payment processing downtime causes immediate financial loss.
No structured logging, no centralized audit trail, and no documented firewall ruleset to present to auditors.
Compute was not segmented at hypervisor level, so scoped PCI workloads mixed with non-PCI virtual machines on shared physical hosts.
A layered architecture addressing every relevant PCI-DSS requirement across segmentation, access control, path redundancy, and auditability.
A VxRail cluster provides compute and storage, with vSphere managing virtual machines and vSAN providing distributed resilient storage. All PCI-scope VMs are isolated into a dedicated cluster and resource pool, with VM-level segmentation enforced via distributed port groups so CDE workloads operate on dedicated VLANs with zero shared port groups. VxRail management interfaces sit on a dedicated out-of-band VLAN inaccessible from production.
Dell access switches in top-of-rack configuration handle VxRail node connectivity with dedicated uplinks per node and LACP bonding. These uplink to a Cisco Nexus pair in vPC topology, eliminating STP-blocked uplinks and allowing full active/active bandwidth from access to core. VLANs are trunked selectively across CDE, DMZ, Management, and Corporate segments, with the Nexus pair acting as Layer 3 boundary and inter-VLAN routing blocked unless explicitly permitted by firewall policy.
Faces both ISPs as first line of defense, terminating ISP connections and handling all inbound and outbound NAT. Only internet-to-DMZ traffic is permitted inbound, so no direct path exists from public internet to internal or CDE networks. Strict egress filtering allows only defined outbound services, and all denied traffic is logged.
Positioned between the DMZ and all internal networks including CDE, Corporate, and Management. The CDE access policy uses a strict default-deny, whitelist-only model with explicit permit rules documented per PCI-DSS Requirement 1. No direct routing path exists between corporate network and CDE at any architectural layer. All rules are explicitly named, described, and tied to an approved business justification.
Sits between the two firewall stages hosting internet-facing services such as reverse proxies and payment gateways, isolated from both public internet and internal CDE. No DMZ service holds or processes raw cardholder data, and any DMZ-to-CDE traffic requires explicit authorization from the Stage 2 firewall.
Two independent ISP connections terminate on the perimeter firewall, with BGP running to both ISP routers in active/active configuration using local preference and AS-path prepending to balance load. Loss of a carrier triggers immediate BGP route withdrawal, shifting traffic to the surviving path within seconds. Dedicated ISP routers per provider ensure one carrier's CPE failure has zero impact on the alternate path.
A centralized syslog server in the secure management VLAN collects events from all firewall stages, Nexus switches, and VxRail management platforms, with retention configured to PCI-DSS Requirement 10: 12 months total history and 3 months immediately available. NTP synchronizes every device to a single authoritative clock source for consistent audit timestamps. All administrative access funnels through a secure jump host with full session logging, and direct management access from the corporate network is blocked.
Firewall policies fully documented with default-deny on the CDE, with regular ruleset reviews enforced.
Vendor-default configurations and passwords removed, with all physical and virtual devices hardened before production.
A dedicated DMZ tier isolates internet-facing systems from the secure CDE.
CDE access restricted to explicit need-to-know basis via granular firewall whitelist rules.
Centralized logging, 12-month retention policy, and unified NTP synchronization.
Network segmentation validated and the management network fully isolated.
Comprehensive network diagrams and data flow documentation produced for ongoing audit cycles.
Thirty minutes with a senior engineer, covering your current environment and the gaps worth addressing first. No obligation, no sales handoff.