<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic please help me configure TFTP access-list on ASA for device management in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194335#M1115766</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I need help configuring a TFTP server access list to prevent attackers who acquire SNMP write privileges for obtaining device configuration information. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have SNMP access list configured already. So it is not a problem. But I need to deal with TFTP. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Please guide me how to configure TFTP access-list on ASA for device management purpose. (not passing traffic) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. I believe that ASA has only TFTP client function, not server. Is TFTP server functioning by default? If yes, how can I disable it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am using&amp;nbsp;FPR2110, I'm bit new on this technology please help&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Sep 2024 13:26:54 GMT</pubDate>
    <dc:creator>suruchigupta555</dc:creator>
    <dc:date>2024-09-13T13:26:54Z</dc:date>
    <item>
      <title>please help me configure TFTP access-list on ASA for device management</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194335#M1115766</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I need help configuring a TFTP server access list to prevent attackers who acquire SNMP write privileges for obtaining device configuration information. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have SNMP access list configured already. So it is not a problem. But I need to deal with TFTP. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Please guide me how to configure TFTP access-list on ASA for device management purpose. (not passing traffic) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. I believe that ASA has only TFTP client function, not server. Is TFTP server functioning by default? If yes, how can I disable it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am using&amp;nbsp;FPR2110, I'm bit new on this technology please help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 13:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194335#M1115766</guid>
      <dc:creator>suruchigupta555</dc:creator>
      <dc:date>2024-09-13T13:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: please help me configure TFTP access-list on ASA for device manage</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194363#M1115770</link>
      <description>&lt;P&gt;control-plane ACL&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list TFTP deny tcp any any eq 69&lt;/P&gt;
&lt;P&gt;direction IN&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;this make ASA can connect to server but deny any attempt to connect tftp using tcp port 69&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221457-configure-control-plane-access-control-p.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221457-configure-control-plane-access-control-p.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 14:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194363#M1115770</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-13T14:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: please help me configure TFTP access-list on ASA for device manage</title>
      <link>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194415#M1115773</link>
      <description>&lt;P&gt;Cisco ASA does not support TFTP server functionality, it can only act as a TFTP client, so I can't see the concern of having someone trying to connect to the ASA and download any data from it. If someone tries the ASA won't respond to the TFTP request as it doesn't have TFTP server capabilities.&lt;/P&gt;
&lt;P&gt;A better general recommendation with SNMP would be to use SNMPv3 with both authentication and encryption rather than using v2.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 15:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/please-help-me-configure-tftp-access-list-on-asa-for-device/m-p/5194415#M1115773</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-09-13T15:56:23Z</dc:date>
    </item>
  </channel>
</rss>

