If you want an internal web server for information or diagnostics, require a magic key sequence on the front panel to enable it and automatically disable it after one hour.

That's almost exactly what my SIP phone does - there is web interface for configuration which has to be enabled by combination of buttons on a handset, and then it disables itself after configurable timeout. But then the thing was made by people who actually knew what they are doing, with this thing function being entirely dependent on actually being connected to the Internet ...

