I would like to use Cisco's Network Assistant to manage my Cisco routers (I know there are other solutions for this, but for now I've decided to use CNA). It requires the HTTP or HTTPS service to be running on routers being managed. Where I work I have already been told I probably won't be allowed to implement this because enabling HTTP/HTTPS on the routers is a security risk.
But is it really a security hole as long as I enable HTTPS and change the default port number? I want to be able to say with confidence that doing it this way is completely secure. Of course nothing is "completely" secure and a port scanner could find any open ports, but the HTTP service running in the IOS isn't that hackable is it?
Lastly, should I have asked this question in the security forum?