<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cant do TFTP from outside the firewall even with allowing tf in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631781#M581103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall is not doing any NAT (no nat-control) and my ip 150.1.1.241 is the outside ip and my router where I need to do tftp it 1.1.4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already allowed tftp from outside to 1.1.4.2 and also enabled inspection on tftp under global-policy...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Feb 2011 21:58:24 GMT</pubDate>
    <dc:creator>pemasirid</dc:creator>
    <dc:date>2011-02-25T21:58:24Z</dc:date>
    <item>
      <title>cant do TFTP from outside the firewall even with allowing tftp</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631775#M581091</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having issue with doing tftp to device behind the firewall (ASA) even though I have allow tftp from outside. Here is the message I see on the console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa/C2(config)# &lt;/P&gt;&lt;P&gt;ciscoasa/C2(config)# &lt;/P&gt;&lt;P&gt;ciscoasa/C2(config)# %ASA-6-302016: Teardown UDP connection 113 for Outside:150.1.1.241/69 to Inside:1.1.4.2/64253 duration 0:02:18 bytes 80&lt;/P&gt;&lt;P&gt;%ASA-6-302016: Teardown UDP connection 114 for Outside:150.1.1.241/0 to Inside:1.1.4.2/64253 duration 0:02:19 bytes 0&lt;/P&gt;&lt;P&gt;%ASA-7-609002: Teardown local-host Outside:150.1.1.241 duration 0:06:04&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the message I see on the device where I'm trying to tftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R2#copy flash: tftp:&lt;/P&gt;&lt;P&gt;Source filename []? IOSCA.ser&lt;/P&gt;&lt;P&gt;Address or name of remote host []? 150.1.1.241&lt;/P&gt;&lt;P&gt;Destination filename [IOSCA.ser]? &lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;%Error opening t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://150.1.1.241/IOSCA.ser" target="_blank"&gt;ftp://150.1.1.241/IOSCA.ser&lt;/A&gt;&lt;SPAN&gt; (Timed out)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;R2#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my ACL on ASA applied to outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa/C2# sh run acc&lt;/P&gt;&lt;P&gt;ciscoasa/C2# sh run access-l&lt;/P&gt;&lt;P&gt;ciscoasa/C2# sh run access-list out&lt;/P&gt;&lt;P&gt;access-list out extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list out extended permit esp host 1.1.6.3 host 1.1.4.2 &lt;/P&gt;&lt;P&gt;access-list out extended permit udp host 1.1.6.3 host 1.1.4.2 eq isakmp &lt;/P&gt;&lt;P&gt;access-list out extended permit udp host 150.1.1.241 host 1.1.4.2 eq tftp &lt;/P&gt;&lt;P&gt;access-list out extended permit udp host 1.1.6.3 host 1.1.4.2 eq ntp &lt;/P&gt;&lt;P&gt;access-list out extended permit udp host 1.1.3.1 host 1.1.4.2 gt 33434 &lt;/P&gt;&lt;P&gt;access-list out extended permit udp host 1.1.6.3 host 1.1.4.2 gt 33434 &lt;/P&gt;&lt;P&gt;access-list out extended permit udp host 1.1.6.4 host 1.1.4.2 eq isakmp &lt;/P&gt;&lt;P&gt;access-list out extended permit esp host 1.1.6.4 host 1.1.4.2 &lt;/P&gt;&lt;P&gt;access-list out extended permit udp any host 1.1.4.2 eq tftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if someone can find the issue..&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631775#M581091</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2019-03-11T19:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631776#M581095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a NAT translation for 1.1.4.2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631776#M581095</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2011-02-25T21:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631777#M581097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're tring to TFTP to a server behind the ASA....&lt;/P&gt;&lt;P&gt;The NAT address is 150.1.1.241?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have a static NAT to allow inbound traffic to this host from the outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then assuming the above IP is the static NAT IP, and the ACL out is assigned to the outside, you need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out extended permit udp any host 150.1.1.241 eq tftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631777#M581097</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-25T21:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631778#M581098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nope, its nat-control not enabled.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it works without firewall (bypassing asa)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631778#M581098</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2011-02-25T21:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631779#M581100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're trying to TFTP to 150.1.1.241 and I don't see it being permitted in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631779#M581100</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-25T21:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631780#M581102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does 150.1.1.241 have a route to the TFTP server? Are you seeing a deny in your logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631780#M581102</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2011-02-25T21:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631781#M581103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall is not doing any NAT (no nat-control) and my ip 150.1.1.241 is the outside ip and my router where I need to do tftp it 1.1.4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already allowed tftp from outside to 1.1.4.2 and also enabled inspection on tftp under global-policy...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 21:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631781#M581103</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2011-02-25T21:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631782#M581104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, it has route to TFTP...have a look below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R2#copy flash: tftp:&lt;/P&gt;&lt;P&gt;Source filename []? IOSCA.ser&lt;/P&gt;&lt;P&gt;Address or name of remote host []? 150.1.1.241&lt;/P&gt;&lt;P&gt;Destination filename [IOSCA.ser]? &lt;/P&gt;&lt;P&gt;.....&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;%Error opening t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://150.1.1.241/IOSCA.ser"&gt;ftp://150.1.1.241/IOSCA.ser&lt;/A&gt;&lt;SPAN&gt; (Timed out)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;R2#&lt;/P&gt;&lt;P&gt;R2#&lt;/P&gt;&lt;P&gt;R2#ping 150.1.1.241&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 150.1.1.241, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/3/8 ms&lt;/P&gt;&lt;P&gt;R2#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 22:00:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631782#M581104</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2011-02-25T22:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631783#M581105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;packet-tracer input outside udp 150.1.1.241 1025 1.1.4.2 69 det&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above should show if an inbound TFTP connection between those IPs is allowed and succesful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 22:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631783#M581105</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-25T22:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631784#M581106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume that the TFTP server logs doesn't show a connection attempt? Is there any info on the connection in the ASA logs? Can you try a packet tracer and see where it is failing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 22:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631784#M581106</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2011-02-25T22:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631785#M581107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Colin/Fedarico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for both of your responses.. However I was in hurry to change the topology and I have already did the write erase..anyway its a good tool which I fortoton to check..but surly on my next try I will do and let you both know the update..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 22:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631785#M581107</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2011-02-25T22:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: cant do TFTP from outside the firewall even with allowing tf</title>
      <link>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631786#M581108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Going over the thread Collin was correct from the start.&lt;/P&gt;&lt;P&gt;Just let us know when you need assistance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Feb 2011 22:50:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-do-tftp-from-outside-the-firewall-even-with-allowing-tftp/m-p/1631786#M581108</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-02-25T22:50:01Z</dc:date>
    </item>
  </channel>
</rss>

