Quoting from the actual PCI DSS 1.2 ...
PCI DSS REQUIREMENTS (1.3.8):
"Implement IP masquerading to prevent internal addresses from being translated and revealed on the Internet, using RFC 1918 address space. Use network address translation (NAT) technologies—for example, port address translation (PAT)."
PCI TESTING PROCEDURES (1.3.8):
"For the sample of firewall and router components, verify that NAT or other technology using RFC 1918 address space is used to restrict broadcast of IP addresses from the internal network to the Internet (IP masquerading)."
As they continue to enforce PCI I guess there will be more and more people, companies and organisations moving to become compliant - if you want to accept credit cards legally under PCI and not risk heavy fines and penalties then you just have to be PCI DSS compliant.
I have to admit, I find it very hard to fathom that cPanel have not yet got this very important part covered (NAT), considering it is a very clear and important requirement of PCI DSS.
In the interim I'm still hoping to stay using cPanel but it seems if I want to be PCI DSS and install a hardware firewall and NAT so I'm not risking it, then cPanel is not looking all that good. Please, please prove me wrong
Again, any help or advice would be much appreciated.
Cheers