2.4.4 Set 'ip tftp source-interface' to the Loopback Interface

Information

Specify the IP address of an interface as the source address for TFTP connections.

Rationale:

This is required so that the TFTP servers can easily identify routers and authenticate requests by their IP address.

Impact:

Organizations should plan and implement trivial file transfer protocol (TFTP) services in the enterprise by setting 'tftp source-interface loopback', which enables the TFTP servers to identify routers and authenticate requests by IP address.

Solution

Bind the TFTP client to the loopback interface.

hostname(config)#ip tftp source-interface loopback {<em>loobpback_interface_number</em>}

Default Value:

The address of the closest interface to the destination is selected as the source address.

See Also

https://workbench.cisecurity.org/benchmarks/12741

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: 3ab3906f95dec6e8e24dcd45d45f01bb961e803c4a5a21039b64d22ad75a1e97