ServicesIndustriesSecurity & ComplianceCase StudiesPricingCompanyContact
Fintech

PCI-DSS Audit-Ready Network Infrastructure

A ground-up compliant infrastructure for a card payment processor, passed on first audit submission with zero findings.

EU ENGINEERED INFRASTRUCTURE GDPR & NIS2 ALIGNED EU DATA RESIDENCY PCI-DSS PROJECT EXPERIENCE US / UK HOURS COVERAGE
Overview

Ground-up design and deployment of a fully PCI-DSS compliant network infrastructure for an organization processing credit card payments. The solution spans hyperconverged compute, a structured switching fabric, and a dual-stage firewall architecture with ISP redundancy. Every design decision treated PCI-DSS requirements as a hard architectural constraint rather than an afterthought.

First submissionAudit passed
ZeroCompliance findings
Dual ISPAutomatic BGP failover
12 monthsLog retention
The Problem

What the client was facing

The client needed to pass an upcoming PCI-DSS audit but lacked infrastructure capable of satisfying the requirements.

No Network Isolation

There was no defined Cardholder Data Environment. Critical payment systems shared flat network space alongside general IT and corporate traffic.

Deficient Perimeter Security

No perimeter segmentation. A single firewall with no DMZ tier allowed internet-facing systems direct lateral access into internal networks.

Single Point of Failure

A single ISP connection provided zero redundancy for a business model where payment processing downtime causes immediate financial loss.

Lack of Visibility

No structured logging, no centralized audit trail, and no documented firewall ruleset to present to auditors.

Unsegmented Compute

Compute was not segmented at hypervisor level, so scoped PCI workloads mixed with non-PCI virtual machines on shared physical hosts.

The Solution

What we built

A layered architecture addressing every relevant PCI-DSS requirement across segmentation, access control, path redundancy, and auditability.

Compute, Dell VxRail

A VxRail cluster provides compute and storage, with vSphere managing virtual machines and vSAN providing distributed resilient storage. All PCI-scope VMs are isolated into a dedicated cluster and resource pool, with VM-level segmentation enforced via distributed port groups so CDE workloads operate on dedicated VLANs with zero shared port groups. VxRail management interfaces sit on a dedicated out-of-band VLAN inaccessible from production.

Switching, Dell Access + Cisco Nexus Core

Dell access switches in top-of-rack configuration handle VxRail node connectivity with dedicated uplinks per node and LACP bonding. These uplink to a Cisco Nexus pair in vPC topology, eliminating STP-blocked uplinks and allowing full active/active bandwidth from access to core. VLANs are trunked selectively across CDE, DMZ, Management, and Corporate segments, with the Nexus pair acting as Layer 3 boundary and inter-VLAN routing blocked unless explicitly permitted by firewall policy.

Stage 1, Perimeter Firewall

Faces both ISPs as first line of defense, terminating ISP connections and handling all inbound and outbound NAT. Only internet-to-DMZ traffic is permitted inbound, so no direct path exists from public internet to internal or CDE networks. Strict egress filtering allows only defined outbound services, and all denied traffic is logged.

Stage 2, Core Firewall

Positioned between the DMZ and all internal networks including CDE, Corporate, and Management. The CDE access policy uses a strict default-deny, whitelist-only model with explicit permit rules documented per PCI-DSS Requirement 1. No direct routing path exists between corporate network and CDE at any architectural layer. All rules are explicitly named, described, and tied to an approved business justification.

DMZ Tier

Sits between the two firewall stages hosting internet-facing services such as reverse proxies and payment gateways, isolated from both public internet and internal CDE. No DMZ service holds or processes raw cardholder data, and any DMZ-to-CDE traffic requires explicit authorization from the Stage 2 firewall.

ISP Redundancy, Dual WAN

Two independent ISP connections terminate on the perimeter firewall, with BGP running to both ISP routers in active/active configuration using local preference and AS-path prepending to balance load. Loss of a carrier triggers immediate BGP route withdrawal, shifting traffic to the surviving path within seconds. Dedicated ISP routers per provider ensure one carrier's CPE failure has zero impact on the alternate path.

Logging & Auditability

A centralized syslog server in the secure management VLAN collects events from all firewall stages, Nexus switches, and VxRail management platforms, with retention configured to PCI-DSS Requirement 10: 12 months total history and 3 months immediately available. NTP synchronizes every device to a single authoritative clock source for consistent audit timestamps. All administrative access funnels through a secure jump host with full session logging, and direct management access from the corporate network is blocked.

Compliance Mapping

PCI-DSS Requirements Addressed

Requirement 1

Firewall policies fully documented with default-deny on the CDE, with regular ruleset reviews enforced.

Requirement 2

Vendor-default configurations and passwords removed, with all physical and virtual devices hardened before production.

Requirement 6

A dedicated DMZ tier isolates internet-facing systems from the secure CDE.

Requirement 7

CDE access restricted to explicit need-to-know basis via granular firewall whitelist rules.

Requirement 10

Centralized logging, 12-month retention policy, and unified NTP synchronization.

Requirement 11

Network segmentation validated and the management network fully isolated.

Requirement 12

Comprehensive network diagrams and data flow documentation produced for ongoing audit cycles.

Outcome

Results delivered

Next Step

Let us design the infrastructure your growth depends on

Thirty minutes with a senior engineer, covering your current environment and the gaps worth addressing first. No obligation, no sales handoff.

CORE HOURS 09:00–19:00 CET · EXTENDED COVERAGE FOR US & UK TIME ZONES