1.2.3 Ensure HTTP and Telnet options are disabled for the management interface

Information

HTTP and Telnet options should not be enabled for device management.

Rationale:

Management access over cleartext services such as HTTP or Telnet could result in a compromise of administrator credentials and other sensitive information related to device management. Theft of either administrative credentials or session data is easily accomplished with a 'Man in the Middle' attack.

Solution

Navigate to Device > Setup > Interfaces > Management.
Set the HTTP and Telnet boxes to unchecked.

Default Value:

Not set. (HTTP and Telnet are disabled by default)

References:

'How to Configure a Layer 3 Interface to act as a Management Port' - https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Layer-3-Interface-to-act-as-a-Management-Port/ta-p/59024

'PAN-OS Administrator's Guide 9.0 (English) - Best Practices for Securing Administrative Access': https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/getting-started/best-practices-for-securing-administrative-access.html#

See Also

https://workbench.cisecurity.org/files/2692