2.4.4 Set 'ip tftp source-interface' to the Loopback Interface

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Specify the IP address of an interface as the source address for TFTP connections.

Rationale:

This is required so that the TFTP servers can easily identify routers and authenticate requests by their IP address.

Solution

Bind the TFTP client to the loopback interface.


hostname(config)#ip tftp source-interface loopback {loobpback_interface_number}

Impact:

Organizations should plan and implement trivial file transfer protocol (TFTP) services in the enterprise by setting 'tftp source-interface loopback', which enables the TFTP servers to identify routers and authenticate requests by IP address.

Default Value:

The address of the closest interface to the destination is selected as the source address.

References:

http://www.cisco.com/en/US/docs/ios-xml/ios/fundamentals/command/F_through_K.html#GUID-9AA27050-A578-47CD-9F1D-5A8E2B449209

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(13), CSCv6|9.1

Plugin: Cisco

Control ID: e681d3474e7a708035149ea4a74e0c373615fd2e2221074818e95dbde413b610