<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TFTP port number not 69 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227909#M346963</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;more ideas ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) is there a connection on UDP/69 directly before this UDP/33442 traffic is seen on the Checkpoint?&lt;/P&gt;&lt;P&gt;2) Look at your ASA log to see which traffic relates to your tftp-process to corelate that with the ChackPoint-Log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jul 2013 13:30:41 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2013-07-08T13:30:41Z</dc:date>
    <item>
      <title>TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227905#M346947</link>
      <description>&lt;P&gt;we have a pair of ASA that are on the Zone1(x.x.33.100), and we have TFTP server(x.x.223.108) on the Inside Zone. Zones are seperated by a Checkpoint FW. When I generate a tftp traffic to copy running config to the tftp server from the ASAs, the Checkpoint show a redam port number like 33442 somthing, instead a UDP 69.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any of you tell me why it is not 69? The configuration on the ASAs regarding for the traffic are default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227905#M346947</guid>
      <dc:creator>hanwucisco</dc:creator>
      <dc:date>2019-03-12T02:07:55Z</dc:date>
    </item>
    <item>
      <title>TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227906#M346950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just add a pic of the traffic on the checkpoint,&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/8/5/144580-Capture-ASA.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 20:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227906#M346950</guid>
      <dc:creator>hanwucisco</dc:creator>
      <dc:date>2013-07-05T20:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227907#M346954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TFTP uses a dynamic DATA-port, similar to FTP. Thats what this additional port should be in the Checkpoint-Log. If that traffic is denied, you have to enable TFTP-Inspection on the CheckPoint.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 21:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227907#M346954</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-07-05T21:26:25Z</dc:date>
    </item>
    <item>
      <title>TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227908#M346959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Karsten,&lt;/P&gt;&lt;P&gt;Our Checkpoint guy told me that the Inspection is enabled and this traffic is a "new initiation", meaning it is started to reach port 33442, instead of 69. &lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227908#M346959</guid>
      <dc:creator>hanwucisco</dc:creator>
      <dc:date>2013-07-08T13:11:13Z</dc:date>
    </item>
    <item>
      <title>TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227909#M346963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;more ideas ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) is there a connection on UDP/69 directly before this UDP/33442 traffic is seen on the Checkpoint?&lt;/P&gt;&lt;P&gt;2) Look at your ASA log to see which traffic relates to your tftp-process to corelate that with the ChackPoint-Log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227909#M346963</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-07-08T13:30:41Z</dc:date>
    </item>
    <item>
      <title>TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227910#M346965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Karsten,&lt;/P&gt;&lt;P&gt;No UDP/69 seen. The ASA logs look strange to me. I dont find any traffic in the log to destination of the TFTP server and there are a lot message as following,&lt;/P&gt;&lt;PRE&gt;&lt;A name="wp6175477"&gt;
&lt;/A&gt;%ASA-5-305013: Asymmetric NAT rules matched for forward and reverse 
flows; Connection &lt;EM&gt;protocol&lt;/EM&gt; src &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;source_address&lt;/EM&gt;/&lt;EM&gt;source_port &lt;/EM&gt;[(&lt;EM&gt;idfw_user&lt;/EM&gt;)] dst &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;dst_address&lt;/EM&gt;/&lt;EM&gt;dst_port &lt;/EM&gt;[(&lt;EM&gt;idfw_user&lt;/EM&gt;)] denied due to 
NAT reverse path failure.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 14:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227910#M346965</guid>
      <dc:creator>hanwucisco</dc:creator>
      <dc:date>2013-07-08T14:51:12Z</dc:date>
    </item>
    <item>
      <title>TFTP port number not 69</title>
      <link>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227911#M346967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason is that someone had a typo on the ACL and we corrected. As to why this typo can make that kind of symtom, i have got myself understood yet. &lt;/P&gt;&lt;P&gt;but thanks,&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 17:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tftp-port-number-not-69/m-p/2227911#M346967</guid>
      <dc:creator>hanwucisco</dc:creator>
      <dc:date>2013-07-17T17:09:52Z</dc:date>
    </item>
  </channel>
</rss>

