<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not really. There are a in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl/m-p/2423607#M921900</link>
    <description>&lt;P&gt;Not really. There are a couple of flaws in your premises - Please refer to&lt;A href="https://supportforums.cisco.com/discussion/10928691/acl-tftp-traffic"&gt; this thread&lt;/A&gt; for a better ACL setup.&lt;/P&gt;&lt;P&gt;Generally speakng tftp only uses udp/69 for the initial destination protocol and port. The initial source port is randomly chosen and that exchange also sets up the Transaction ID (TID) which influences the subsequent udp ports used for the actual transfer. See also this &lt;A href="http://books.google.com/books?id=isybabuADPkC&amp;amp;pg=PA610&amp;amp;lpg=PA610&amp;amp;dq=tftp+source+and+destination+ports&amp;amp;source=bl&amp;amp;ots=XbJ0CZ6jAU&amp;amp;sig=CBfBIxiHgUyHITrq7BtRTO_hyzA&amp;amp;hl=en&amp;amp;sa=X&amp;amp;ei=23U9U9nSDsuksQTX7YCQAw&amp;amp;ved=0CGwQ6AEwBw#v=onepage&amp;amp;q=tftp%20source%20and%20destination%20ports&amp;amp;f=false"&gt;book excerpt&lt;/A&gt; for a more in-depth explanation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2014 15:02:54 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-04-03T15:02:54Z</dc:date>
    <item>
      <title>acl</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/2423606#M921898</link>
      <description>&lt;H5 class="uiStreamMessage" data-ft="{&amp;quot;type&amp;quot;:1,&amp;quot;tn&amp;quot;:&amp;quot;K&amp;quot;}" style="font-size: 11px; color: rgb(0, 0, 0); margin-top: 0px; margin-bottom: 5px; padding: 0px; word-break: break-word; word-wrap: break-word; font-family: Helvetica, Arial, 'lucida grande', tahoma, verdana, arial, sans-serif;"&gt;&lt;SPAN class="messageBody" data-ft="{&amp;quot;type&amp;quot;:3,&amp;quot;tn&amp;quot;:&amp;quot;K&amp;quot;}" style="color: rgb(51, 51, 51); font-size: 14px; line-height: 1.38;"&gt;Shouldnt this acl permit tftp from host 10.0.0.68, but deny any other tftp request? and also permit any other request other then tftp?&lt;BR /&gt;&lt;BR /&gt;access-list 100 permit udp host 10.0.0.68 eq tftp host 10.0.0.82 eq tftp&lt;BR /&gt;&lt;BR /&gt;access-list 100 deny udp any eq tftp any eq tftp&lt;BR /&gt;&lt;BR /&gt;access-list 100 permit ip any any&lt;/SPAN&gt;&lt;/H5&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/2423606#M921898</guid>
      <dc:creator>danielbj66</dc:creator>
      <dc:date>2020-02-21T13:09:02Z</dc:date>
    </item>
    <item>
      <title>Not really. There are a</title>
      <link>https://community.cisco.com/t5/network-security/acl/m-p/2423607#M921900</link>
      <description>&lt;P&gt;Not really. There are a couple of flaws in your premises - Please refer to&lt;A href="https://supportforums.cisco.com/discussion/10928691/acl-tftp-traffic"&gt; this thread&lt;/A&gt; for a better ACL setup.&lt;/P&gt;&lt;P&gt;Generally speakng tftp only uses udp/69 for the initial destination protocol and port. The initial source port is randomly chosen and that exchange also sets up the Transaction ID (TID) which influences the subsequent udp ports used for the actual transfer. See also this &lt;A href="http://books.google.com/books?id=isybabuADPkC&amp;amp;pg=PA610&amp;amp;lpg=PA610&amp;amp;dq=tftp+source+and+destination+ports&amp;amp;source=bl&amp;amp;ots=XbJ0CZ6jAU&amp;amp;sig=CBfBIxiHgUyHITrq7BtRTO_hyzA&amp;amp;hl=en&amp;amp;sa=X&amp;amp;ei=23U9U9nSDsuksQTX7YCQAw&amp;amp;ved=0CGwQ6AEwBw#v=onepage&amp;amp;q=tftp%20source%20and%20destination%20ports&amp;amp;f=false"&gt;book excerpt&lt;/A&gt; for a more in-depth explanation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 15:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl/m-p/2423607#M921900</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-04-03T15:02:54Z</dc:date>
    </item>
  </channel>
</rss>

