OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 16.7 Legacy Series »
  • TFTP blocked
« previous next »
  • Print
Pages: [1]

Author Topic: TFTP blocked  (Read 4609 times)

tomas.morales

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
TFTP blocked
« on: August 15, 2016, 03:15:14 pm »
Hi

I need TFTP for building servers and downloading software internally in our network. Although we have rules that allow UDP/TCP on port 69, the file transfer is blocked:


Aug 15 12:52:50 ny4fw07 filterlog: 175,16777216,,0,ixl2_vlan242,match,pass,in,4,0x0,,64,0,0,DF,17,udp,98,10.132.242.14,10.132.250.203,43011,69,78
Aug 15 12:52:50 ny4fw07 filterlog: 68,16777216,,0,ixl1_vlan250,match,pass,out,4,0x0,,63,0,0,DF,17,udp,98,10.132.242.14,10.132.250.203,43011,69,78
Aug 15 12:52:50 ny4fw07 filterlog: 278,16777216,,0,ixl1_vlan250,match,block,in,4,0x0,,64,64178,0,none,17,udp,68,10.132.250.203,10.132.242.14,48105,43011,48
Aug 15 12:52:57 ny4fw07 filterlog: 278,16777216,,0,ixl1_vlan250,match,block,in,4,0x0,,64,64179,0,none,17,udp,68,10.132.250.203,10.132.242.14,55791,43011,48


I haven't able to find any reference to TFTP in opnsense doc. In pfsense there is a reference that I need a TFTP proxy....
Logged

fabian

  • Hero Member
  • *****
  • Posts: 2768
  • Karma: 199
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: TFTP blocked
« Reply #1 on: August 15, 2016, 06:28:43 pm »
the problem is that the server answers the request from a different port (see https://tools.ietf.org/html/rfc1350) and the firewall usually will block that because from its point of view this is a new connection which is not allowed.

If your policy allows that, you can try to pass any UDP traffic from your TFTP server.
Logged

tomas.morales

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: TFTP blocked
« Reply #2 on: August 17, 2016, 12:09:00 pm »
Thanks for the advice. We actually did that as a workaround.
Logged

echappatte

  • Newbie
  • *
  • Posts: 15
  • Karma: 3
    • View Profile
Re: TFTP blocked
« Reply #3 on: August 17, 2016, 06:00:39 pm »
On some client you can set a "firewall compatibility mode" that use only defined TFTP ports.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 16.7 Legacy Series »
  • TFTP blocked
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2