2.4.4 Set 'ip tftp source-interface' to the Loopback Interface

Information

Specify the IP address of an interface as the source address for TFTP connections.

This is required so that the TFTP servers can easily identify routers and authenticate requests by their IP address.

Solution

Bind the TFTP client to the loopback interface.

hostname(config)#ip tftp source-interface loopback {<em>loobpback_interface_number</em>}

Impact:

Organizations should plan and implement trivial file transfer protocol (TFTP) services in the enterprise by setting 'tftp source-interface loopback', which enables the TFTP servers to identify routers and authenticate requests by IP address.

See Also

https://workbench.cisecurity.org/benchmarks/12917

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Cisco

Control ID: f2cbd4afb53a072164824762bc6823d2a687bf63e486bc75df76775e8e0f5a73