1. Home
  2. Security Hardening
  3. CIS Palo Alto Firewall 8 Benchmark L1 V1.0.0
  4. Ensure ‘Permitted IP Addresses’ is set for all management profiles where SSH, HTTPS, or SNMP is enabled – HTTPS

Ensure ‘Permitted IP Addresses’ is set for all management profiles where SSH, HTTPS, or SNMP is enabled – HTTPS

Details

For all management profiles, only the IP addresses required for device management should be specified.

Rationale:

If a Permitted IP Addresses list is either not specified or is too broad, an attacker may gain the ability to attempt management access from unintended locations, such as the Internet. The Ensure ‘Security Policy’ denying any/all traffic exists at the bottom of the security policies ruleset recommendation in this benchmark can provide additional protection by requiring a security policy specifically allowing device management access.

Solution

Navigate to Network > Network Profiles > Interface Management.
Set Permitted IP Addresses to only include those necessary for device management.
Default Value:
Not enabled

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Palo_Alto.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles