1.2.3 Ensure HTTP and Telnet options are disabled for the management interface

Information

HTTP and Telnet options should not be enabled for device management.

Rationale:

Management access over cleartext services such as HTTP or Telnet could result in a compromise of administrator credentials and other sensitive information related to device management. Theft of either administrative credentials or session data is easily accomplished with a 'Man in the Middle' attack.

Solution

Navigate to Device > Setup > Interfaces > Management.
Set the HTTP and Telnet boxes to unchecked.

Default Value:

Not set. (HTTP and Telnet are disabled by default)

See Also

https://workbench.cisecurity.org/benchmarks/17915

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2, CSCv7|14.4, CSCv7|16.5

Plugin: Palo_Alto

Control ID: e07e38bdf36f3ae27643141a428bef75c47b1a482c6ca86571552c4639cce994