Details
HTTP and Telnet options should not be enabled for device management.
Rationale:
Management access over cleartext services such as HTTP or Telnet could result in a compromise of administrator credentials and other sensitive information related to device management.
Solution
Navigate to Device > Setup > Management > Management Interface Settings.
Set the HTTP and Telnet boxes to unchecked.
Default Value:
Not set.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Palo_Alto.