[PCI DSS 3.0] 1.1 Establish and implement firewall and router configuration standards that include the following

1.1 Establish and implement firewall and
router configuration standards that
include the following:

1.1 Inspect the firewall and router configuration standards and
other documentation specified below and verify that standards
are complete and implemented as follows:

Firewalls and routers are key components of the
architecture that controls entry to and exit from the
network. These devices are software or hardware
devices that block unwanted access and manage
authorized access into and out of the network.
Configuration standards and procedures will help
to ensure that the organization’s first line of
defense in the protection of its data remains
strong

Does this mean that if we have GNU/Linux web server in DMZ, it’s enough to configure IPtables on that that server? Or we need to have separate device (hardware firewall or GNU/Linux server with iptables configured)?