cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2114
Views
0
Helpful
2
Replies

ACL to block TFTP not working

stevec90
Level 1
Level 1

I am trying to block TFTP traffic with an ACL with the following commands, and have applied it to the appropriate interface (outbound on interface with the server subnet) and I can still copy a file over via TFTP. What am I missing? I have confirmed Solar Winds TFTP server is functioning on UDP port 69.

deny UDP any any eq 69

permit ip any any

1 Accepted Solution

Accepted Solutions

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Steve,

outbound ACLs don't block packets that are generated locally on the router itself.

So if you test the ACL by copying a file from the router itself to the TFTP server the result is an apparent  failure of the ACL = a successful TFTP file transfer.

Hope to help

Giuseppe

View solution in original post

2 Replies 2

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Steve,

outbound ACLs don't block packets that are generated locally on the router itself.

So if you test the ACL by copying a file from the router itself to the TFTP server the result is an apparent  failure of the ACL = a successful TFTP file transfer.

Hope to help

Giuseppe

Thanks for the clarification on that. When I switch to the client on another subnet it works fine.

Review Cisco Networking products for a $25 gift card