Unanswered Question
Sep 17th, 2009

Hi, I have been configuring access-list on a 2811 router to deny all traffic except TFTP. Right now, only the router who's IP adresse are in the ACL, can copy their running-config to the TFTP server. However, the router that is directly connected to the TFTP server, and on which interface the ACL is placed out, is enable to copy it's own running-config, even thow the ACL is not allowing his IP address (only those from the other routers in the network). Look like the routers is not passing it's own traffic in the ACL ?? Is thi possible ??.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
g-lacoursiere Thu, 09/17/2009 - 18:46

Here is the topology and the runing-config of router named R2.

Its the R2 router that is able to copy to the TFTP server even though the access-list does not permit him to copy.

I hope this is not too confusing !!

Thanks for your answer.

Leo Laohoo Sun, 09/20/2009 - 20:29

Just a test, but remove permit ip any any.

Have you tried using ip access-group TFTP in?

Ganesh Hariharan Mon, 01/11/2010 - 03:44


Configure ip access-group TFTP in  in your interface and then check  and share your results !!




This Discussion