1. Home
  2. Security Hardening
  3. CIS Palo Alto Firewall 9 Benchmark V1.0.0 L1
  4. Ensure HTTP and Telnet options are disabled for all management profiles – HTTP

Ensure HTTP and Telnet options are disabled for all management profiles – HTTP

Details

HTTP and Telnet options should not be enabled for device management.

Rationale:

Management access over cleartext services such as HTTP or Telnet could result in a compromise of administrator credentials and other sensitive information related to device management.

Solution

Navigate to Network > Network Profiles > Interface Management.
For each Profile, set the HTTP and Telnet boxes to unchecked.

References:

‘PAN-OS Administrator’s Guide 9.0 (English) – Best Practices for Securing Administrative Access’: https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/getting-started/best-practices-for-securing-administrative-access.html#

‘PAN-OS Administrator’s Guide 9.0 (English) – Use Interface Management Profiles to Restrict Access’: https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-interfaces/use-interface-management-profiles-to-restrict-access.html#

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Identification and Authentication, System and Communications Protection, System and Information Integrity.This control applies to the following type of system Palo_Alto.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles