1.2.4 Ensure HTTP and Telnet options are disabled for all management profiles - HTTP

Information

HTTP and Telnet options should not be enabled for device management.

Rationale:

Management access over cleartext services such as HTTP or Telnet could result in a compromise of administrator credentials and other sensitive information related to device management.

Solution

Navigate to Network > Network Profiles > Interface Management.
For each Profile, set the HTTP and Telnet boxes to unchecked.

References:

'PAN-OS Administrator's Guide 9.0 (English) - Best Practices for Securing Administrative Access': https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/getting-started/best-practices-for-securing-administrative-access.html#

'PAN-OS Administrator's Guide 9.0 (English) - Use Interface Management Profiles to Restrict Access': https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access.html#

See Also

https://workbench.cisecurity.org/files/2692