Cisco Pix 506 tftp config file to different subnet

Cisco Pix 506 tftp config file to different subnet

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Cisco Pix 506 tftp config file to different subnet goodwiki 05-26-2006
Posted by goodwiki on May 26, 2006, 5:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have about 13 PIX 506e's that I use to create VPN tunnels back to my
515e. I would like to place a TFTP server on my home network and then
use the write net command at each of the 506e's to write back to one
TFTP server. I understand that the Write Net commands tries to use
interface 1 and that is fine. I can write the file to local TFTP
servers but I do not want to use 14 different TFTP server if I can
avoid it. When I try to write to any TFTP server other than the one on
the local network I get a Timed out attempting to connect. I cannot
ping the home TFTP server from the other firewall either so I think I
have a connectivity problem from the firewall. I can ping every TFTP
server from the home network so the VPN tunnels work but for some
reason, I can not ping the TFTP servers from the Firewall.

Any help on this would be great. My guess is that it either can not be
done or I have to place a command on the firewall that will allow the
firewall to ping other network.

Thanks in advance for this.


Posted by Walter Roberson on May 28, 2006, 1:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>I have about 13 PIX 506e's that I use to create VPN tunnels back to my
>515e. I would like to place a TFTP server on my home network and then
>use the write net command at each of the 506e's to write back to one
>TFTP server. I understand that the Write Net commands tries to use
>interface 1 and that is fine.

No, "write net" uses the interface named in the tftp-server command.

>I can write the file to local TFTP
>servers but I do not want to use 14 different TFTP server if I can
>avoid it. When I try to write to any TFTP server other than the one on
>the local network I get a Timed out attempting to connect. I cannot
>ping the home TFTP server from the other firewall either so I think I
>have a connectivity problem from the firewall.

You might not have configured icmp permit echo-reply outside

Also, be aware that some ISPs block tftp -- and you don't really want
to be tftp'ing a configuration (complete with passwords) in
cleartext over the public internet. Probably what you want to do is
extend your VPN tunnels to include the outside interface of the
PIXes.

Similar ThreadsPosted
Cisco Pix 506 config March 31, 2005, 10:00 am
Schools subnet = 10.0.0.1 Classes subnet 10.0.0.1 can't connect to internet May 23, 2005, 4:02 pm
Help with Cisco ASA 5505 config for BellSouth DSL April 16, 2007, 2:28 pm
Config cisco routers such as a VPN server July 23, 2007, 1:58 pm
Help with Cisco ASA 5505 config for BellSouth DSL August 8, 2007, 5:08 pm
(video tutorial) Config Cisco Routers for Call Manager July 23, 2007, 2:01 pm
How to route traffic from one LAN subnet to another LAN subnet? December 26, 2007, 5:37 pm
FWSM: tftp-problem October 5, 2008, 4:37 am
mydoom and TFTP warnings by Languard March 8, 2006, 4:29 am
VPN Security Risk - Subnet Key Exchange April 19, 2005, 12:51 pm

The site map in XML format XML site map

Contact Us | Privacy Policy