These services provide management access to the firewall, so only
select the services that correspond to the management activities
you want to allow on this interface. For example, don’t enable
HTTP or Telnet because those protocols transmit in plaintext and
therefore aren’t secure. Or if you plan to use the MGT interface
for firewall configuration tasks through the web interface or
CLI, you don’t enable HTTP, HTTPS, SSH, or Telnet so that you
prevent unauthorized access through the interface (if you must
allow HTTPS or SSH in this scenario, limit access to a specific
set of
Permitted IP Addresses). For
details, see
Use Interface Management
Profiles to Restrict Access.