<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello, thank you for your in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452147#M267678</link>
    <description>&lt;P&gt;Hello, thank you for your answer.&lt;/P&gt;&lt;P&gt;I have enough space on my CME to download this file.&lt;/P&gt;&lt;P&gt;FTP transfers don't work. On the ASA monitoring, I see Deny TCP (no connection) when I do FTP transfer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Apr 2014 11:14:15 GMT</pubDate>
    <dc:creator>Thomas P</dc:creator>
    <dc:date>2014-04-09T11:14:15Z</dc:date>
    <item>
      <title>Problem transfer TFTP through ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452145#M267676</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12px"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px"&gt;I have a problem with my ASA 5505, I am not able to transfer files bigger than 100ko&amp;nbsp;using TFTP. Below my archiecture:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px"&gt;CME&amp;lt;-&amp;gt;ASA5505&amp;lt;-&amp;gt;SW3650&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px"&gt;Here is what I get when I try to download a file located on the 3650 on my CME:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;CME#copy tftp flash&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;Address or name of remote host [X.X.X.X]?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;Source filename [cmterm-7942_7962-sccp.9-3-1SR4-1[1].tar]?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;Destination filename [cmterm-7942_7962-sccp.9-3-1SR4-1[1].tar]? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;Accessing tftp://X.X.X.X/cmterm-7942_7962-sccp.9-3-1SR4-1[1].tar...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;Loading cmterm-7942_7962-sccp.9-3-1SR4-1[1].tar from 10.52.199.126 (via GigabitEthernet0/0): !... [timed out]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;Error reading tftp://10.52.199.126/cmterm-7942_7962-sccp.9-3-1SR4-1[1].tar (Connection timed out)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;&lt;SPAN style="font-size: 12px"&gt;When I look on the ASA monitoring page, I see that a UDP connection is built between the ASA and the SW3650 but 2 minutes later there are "Teardown UDP connection" messages.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;&lt;SPAN style="font-size: 12px"&gt;Can you please help me? Due to this transfer issue, I am not able to upgrade my IP Phones (the phones only download the first 2 files because there are smaller than 100ko).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;&lt;SPAN style="font-size: 12px"&gt;Thank you in advance for your help.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;&lt;SPAN style="font-size: 12px"&gt;Regards.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10px"&gt;&lt;SPAN style="font-size: 12px"&gt;Thomas.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452145#M267676</guid>
      <dc:creator>Thomas P</dc:creator>
      <dc:date>2019-03-12T04:03:13Z</dc:date>
    </item>
    <item>
      <title>Thomas,Check whether your CME</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452146#M267677</link>
      <description>&lt;P&gt;Thomas,&lt;/P&gt;&lt;P&gt;Check whether your CME router flash memory have enough space for this file to be copied, or you can try to do ftp transfer if your company policy allow that.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 11:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452146#M267677</guid>
      <dc:creator>Poonam Garg</dc:creator>
      <dc:date>2014-04-09T11:06:47Z</dc:date>
    </item>
    <item>
      <title>Hello, thank you for your</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452147#M267678</link>
      <description>&lt;P&gt;Hello, thank you for your answer.&lt;/P&gt;&lt;P&gt;I have enough space on my CME to download this file.&lt;/P&gt;&lt;P&gt;FTP transfers don't work. On the ASA monitoring, I see Deny TCP (no connection) when I do FTP transfer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 11:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452147#M267678</guid>
      <dc:creator>Thomas P</dc:creator>
      <dc:date>2014-04-09T11:14:15Z</dc:date>
    </item>
    <item>
      <title>Default UDP connection time</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452148#M267679</link>
      <description>&lt;P&gt;Default UDP connection time out is 2 minutes through the ASA.&lt;/P&gt;
&lt;P&gt;You can modify the timeout values for the specific flow from a particular source to destination . Try changing the default connection timeout of UDP&lt;/P&gt;

&lt;PRE&gt;
ASA(config)# &lt;B&gt;access-list CONNS permit udp host  &lt;EM&gt;&lt;U&gt;CME ip&lt;/U&gt; &lt;U&gt;tftp serverip&lt;/U&gt;&lt;/EM&gt; port&lt;/B&gt;&lt;/PRE&gt;

&lt;DIV class="pEx1_Example1"&gt;
&lt;PRE&gt;
ASA(config)# &lt;B class="cBold"&gt;class-map CONNS
&lt;/B&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;
&lt;PRE&gt;
ASA(config-cmap)#&lt;STRONG&gt;match access-list CONNS&lt;/STRONG&gt;&lt;B class="cBold"&gt;
&lt;/B&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;
&lt;PRE&gt;
ASA(config)# &lt;B class="cBold"&gt;policy-map&lt;/B&gt; &lt;EM class="cEmphasis"&gt;&lt;STRONG&gt;CONNS&lt;/STRONG&gt;&lt;/EM&gt;&lt;EM class="cEmphasis"&gt;
&lt;/EM&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV class="pEx1_Example1"&gt;
&lt;PRE&gt;
ASA(config-pmap)# &lt;B class="cBold"&gt;class&lt;/B&gt; &lt;STRONG&gt;CONNS&lt;/STRONG&gt;&lt;B class="cBold"&gt;
&lt;/B&gt;&lt;/PRE&gt;
&lt;/DIV&gt;

&lt;PRE&gt;
ASA(config-pmap-c)# &lt;B class="cBold"&gt;set connection &lt;/B&gt;timeout idle 00:30:00&lt;/PRE&gt;

&lt;PRE&gt;
ASA(config)# &lt;SPAN style="color: Black; font-style: normal; font-weight: bold"&gt;service-policy CONNS&lt;/SPAN&gt;&lt;SPAN style="color: Black; font-style: oblique; font-weight: normal"&gt; &lt;/SPAN&gt;{&lt;SPAN style="color: Black; font-style: normal; font-weight: bold"&gt;global &lt;/SPAN&gt;| &lt;SPAN style="color: Black; font-style: normal; font-weight: bold"&gt;interface &lt;/SPAN&gt;&lt;SPAN style="color: Black; font-style: italic; font-weight: normal"&gt;interface_name&lt;/SPAN&gt;}&lt;/PRE&gt;

&lt;P&gt;you can also globally change the timeout value of UDP using:&lt;/P&gt;
&lt;P&gt;ASA(config)# timeout udp 00:30:00&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference: http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_connlimits.html#wp1080774&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"Please rate helpful posts"&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 12:19:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452148#M267679</guid>
      <dc:creator>Poonam Garg</dc:creator>
      <dc:date>2014-04-09T12:19:37Z</dc:date>
    </item>
    <item>
      <title>Is port 69 allowed through</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452149#M267680</link>
      <description>&lt;P&gt;Is port 69 allowed through your ASA?&amp;nbsp; If not then add it in...and ofcourse remove it after the transfer if required&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 12:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452149#M267680</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-09T12:23:33Z</dc:date>
    </item>
    <item>
      <title>Yes, the UDP port is open</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452150#M267681</link>
      <description>&lt;P&gt;Yes, the UDP port is open (UDP transfers work with small file).&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 12:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452150#M267681</guid>
      <dc:creator>Thomas P</dc:creator>
      <dc:date>2014-04-09T12:40:45Z</dc:date>
    </item>
    <item>
      <title>Hello,Why do you want to</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452151#M267682</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Why do you want to change the UDP timeout value?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 12:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452151#M267682</guid>
      <dc:creator>Thomas P</dc:creator>
      <dc:date>2014-04-09T12:44:30Z</dc:date>
    </item>
    <item>
      <title>I see, Which TFTP server are</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452152#M267683</link>
      <description>&lt;P&gt;I see, Which TFTP server are you using?&amp;nbsp; I have heard that there are some TFTP servers which do not support larger files, some that require you to adjust some setting to allow for larger transfers, and so on.&amp;nbsp; I use TFTPD64 which is the 64bit version of TFTPD32, but have not had any issues with transfering large files using that.&lt;/P&gt;&lt;P&gt;Might be worth a try to change the TFTP server you are using to see if that is the cause of your problem.&lt;/P&gt;&lt;P&gt;http://tftpd32.jounin.net/tftpd32_download.html&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 12:48:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452152#M267683</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-09T12:48:28Z</dc:date>
    </item>
    <item>
      <title>Hello,I tried to use my core</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452153#M267684</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I tried to use my core switch as TFTP server and also my PC using TFTP 64.&lt;/P&gt;&lt;P&gt;Same issue on both systems (see file attached for TFTP64).&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 14:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452153#M267684</guid>
      <dc:creator>Thomas P</dc:creator>
      <dc:date>2014-04-09T14:44:14Z</dc:date>
    </item>
    <item>
      <title>Why do you think the ASA is</title>
      <link>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452154#M267685</link>
      <description>&lt;P&gt;Why do you think the ASA is the one at fault here? Have you tried to connect the switch directly to the CME? Does this work? If this also doesn't solve the issue, have you tried using FTP instead of TFTP?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 15:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-transfer-tftp-through-asa-5505/m-p/2452154#M267685</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2014-04-09T15:14:53Z</dc:date>
    </item>
  </channel>
</rss>

