Guide to Operation Copyright © Fire4 Systems, Inc., 2013. All Rights Reserved www . guest - internet . com 44
The next figure shows a business network with full PCI-DSS compliance: a single firewall
isolates the business network and public network (DMZ). With this configuration it is
possible for one of the business computers to generate and manage access codes using the
GIS-gateway providing that the computer has been authorized to do so within the firewall.
DSL/T1
circuit
Internet
Public user access is blocked to the business
network that includes a point of sale terminal
Set private IP range 192.168.xx.xx or 10.xx.xx.xx
to prevent access from the public network
Public network (DMZ): wireless
hotspot, kiosks, business center
PoS
Inventory
Gateway Firewall
Switch
GIS-R6+
Internet
Kiosk
Switch
Business
center
computer
Wireless Internet
DSL/T1
circuit
Internet
Public network (DMZ): The gateway
cannot be accessed from a business
network computer
PoS
Inventory
Gateway Connected via a Firewall
Switch
Firewall: isolates the public and private
networks. Protects the private network
from attack via the Internet
GIS-R6+
Internet
Kiosk
Switch
Business
center
computer
Wireless Internet