cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1168
Views
0
Helpful
2
Replies

How do I set up rule to allow TFTP from DMZ?

Velocity2089
Level 1
Level 1

Hello! I'm trying to set up a firewall rule to allow TFTP traffic to come from my switches in my DMZ so as to do proper configuration backups. Ideally I'd like to allow ONLY these 2 IP's for TFTP traffic and nothing else. I set up the below rule for one of them but had no luck.

Any thoughts on what I may be missing?

 

access-list dmz1_access_in extended permit udp host 10.1.61.20 host 10.1.80.220 eq tftp

 

10.1.61.20 = DMZ Switch

10.1.80.220 = TFTP Server

 

2 Replies 2

nkarthikeyan
Level 7
Level 7

Hello,

TFTP requires high ports range 1024 - 65535 also needs to be allowed... Also some cases it requires bi-directional flows.

So i request you to try by allowing 1024-65535 1st and the try for the bi-directional port allow for the same if 1st method doesn't works.

 

Regards

Karthik

 

Turns out I had the correct rules in place. The issue was that I had routes missing to the DMZ subnet.
Review Cisco Networking for a $25 gift card