04-22-2013 09:28 AM - edited 03-16-2019 04:56 PM
Hello
I want to know if there is a way to limit access to the TFTP server of the CUCM or apply security to deliver the files that the ip phones needs but only
to the ip phones or CIPC not to other type of device such as a computer.
Im asking this because a security network scan tool detected the following files from the TFTP on the CUCM :
gkdefault.cfg
RINGLIST.DAT
SEPDefault.cnf
SIPDefault.cnf
XMLDefault.cnf.xml
i will appreciate your recommendations
Regards!
Solved! Go to Solution.
04-22-2013 12:48 PM
No way to limit TFTP access on the server itself, you can even download phone config files to your computer.
You would need to either use ACLs on your network, or if you want security on CUCM (authentication/encryption) enable that on CUCM.
You may follow the CUCM security guide for such task.
HTH
java
if this helps, please rate
www.cisco.com/go/pdihelpdesk
04-22-2013 12:48 PM
No way to limit TFTP access on the server itself, you can even download phone config files to your computer.
You would need to either use ACLs on your network, or if you want security on CUCM (authentication/encryption) enable that on CUCM.
You may follow the CUCM security guide for such task.
HTH
java
if this helps, please rate
www.cisco.com/go/pdihelpdesk
04-22-2013 03:28 PM
Hi Jaime V.
So, if i decide to implement security on CUCM, this will accomplish what i mentioned before? or either way i need to apply an ACL
The quickest way to do it would be using an ACL as you mentioned. I have a doubt about this, im pretending apply the ACL to permit tftp access only from the Voice Segments and deny the data segments but if i do this, it would be affected the CIPC's also, that utilize the data segment or am i wrong?
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide