Chapter 5 Compliance : Configuring FortiGate units for PCI DSS compliance : Network topology
  
Network topology
The cardholder data environment must be protected against unauthorized access from the Internet and from other networks in your organization. FortiGate unit firewall functionality provides tight control over the traffic that can pass between the following network interfaces:
Internet
CDE wired LAN
CDE wireless LAN
Other internal networks
Figure 154 shows how the Customer Data Environment can be delineated in a typical network.
Figure 154: Enterprise network with a customer data environment