Mgmt_Profile_L3
).
192.168.1.0/24
).
These interfaces are intended exclusively for firewall administration.
HTTPS
and
SSH
for secure access. Avoid enabling
HTTP
or
Telnet
, as they transmit data in plaintext.
[Reference]
These interfaces handle regular user traffic and should have minimal management exposure.
HTTPS
,
SSH
) on these interfaces. If necessary, enable only essential services like
Ping
for connectivity checks.
[Reference]
Response Pages
for Captive Portal.
User-ID
services for user identification.
[Reference]
HTTP
or
Telnet
on user-facing interfaces, as they are insecure.
[Reference]
Setting | Administrative Interfaces | User-Facing Interfaces |
---|---|---|
Permitted IP Addresses | Trusted Admin IPs | Specific User Subnets |
HTTPS/SSH | Enable | Disable |
HTTP/Telnet | Disable | Disable |
Ping | Optional | Optional |
Response Pages | Optional | Enable if needed |
User-ID Services | Optional | Enable if needed |
SNMP | Optional | Optional |
Role-Based Access | Implement | Not Applicable |
Session Security Settings | Configure | Not Applicable |
References: