Cisco ASA Series Configuration Manual page 320

Firewall cli, asa services module, and the adaptive security virtual appliance
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Chapter 13
Inspection of Basic Internet Protocols
TFTP Inspection
The inspection engine inspects TFTP read request (RRQ), write request (WRQ), and error notification
(ERROR), and dynamically creates connections and translations, if necessary, to permit file transfer
between a TFTP client and server.
A dynamic secondary channel and a PAT translation, if necessary, are allocated on a reception of a valid
read (RRQ) or write (WRQ) request. This secondary channel is subsequently used by TFTP for file
transfer or error notification.
Only the TFTP server can initiate traffic over the secondary channel, and at most one incomplete
secondary channel can exist between the TFTP client and server. An error notification from the server
closes the secondary channel.
TFTP inspection must be enabled if static PAT is used to redirect TFTP traffic.
For information on enabling TFTP inspection, see
Configure Application Layer Protocol Inspection,
page
12-9.
Cisco ASA Series Firewall CLI Configuration Guide
13-46

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents