Routelearn.net
Course menu

Course 12: IP Services on IOSLesson 2.2 (4 of 5 in this course)77 of 91 in the CCNA series

SSH, TFTP and FTP for device management

Copying configurations and IOS images with TFTP and FTP, and the file system commands on Cisco devices.

Intermediate · 10 min read

Device management protocols are the protocols an administrator uses to reach network devices remotely and move files to and from them: SSH for an encrypted command-line session, and TFTP, FTP or SCP for copying configuration files and IOS images between a device and a server.

In simple terms: They're how you look after a router without standing next to it. SSH lets you log in safely over the network, and file transfer protocols let you back up its settings or load new software.

A real-life situation

A Cisco security advisory says R1's IOS version has a bug, and your manager wants it upgraded tonight. You are at home. You also realise there is no backup of R1's configuration anywhere but the router itself. You need three things: a secure way to reach the CLI from home (SSH), a way to copy the config off the router, and a way to copy a 100 MB image on to it. In the lab, SRV1 (192.168.20.10) runs a TFTP and an FTP server.

What these tools are

ProtocolTransportLoginEncryptedUsed for
SSHTCP 22YesYesRemote CLI access
TelnetTCP 23YesNoRemote CLI access (avoid)
TFTPUDP 69NoNoQuick copies of configs and images
FTPTCP 21 + data connectionYesNoLarger, more reliable copies
SCPTCP 22 (inside SSH)YesYesSecure copies

The protocols themselves are explained in FTP, SFTP and TFTP and SSH and Telnet. On a Cisco device, the router is the client: you type copy on the router and it connects to the server.

The IOS file system

Cisco IOS names each storage area with a prefix ending in a colon, a bit like a drive letter:

  • flash: holds the IOS image and other files. It keeps its contents when the power is off.
  • nvram: holds the startup-config (nvram:startup-config).
  • system: holds the running-config in RAM (system:running-config).
  • tftp:, ftp:, scp: are network locations. usbflash0: is a USB stick on routers that have a port.

show file systems lists them all, and dir or show flash: lists the files in one.

Why it works that way

TFTP is tiny: it sends the file in numbered 512-byte blocks and waits for an acknowledgement of each block before sending the next. That is easy to build into a router's boot code, which is why TFTP is everywhere. But it is slow over long distances, has no login, and anyone who can reach the server can read or overwrite files. FTP uses TCP, which handles lost packets and sends many segments at once, and it asks for a username and password. That makes it the better choice for large images, but the password and the file still travel in clear text.

The secure options are SSH for the CLI and SCP for copying, because both run inside an encrypted SSH session. On the CCNA, TFTP and FTP are what you are asked about; in real networks SCP is a good habit.

How it works step by step

Gi0/2 .2.1Gi0/0 .1192.168.10.0/24Gi0/1 .1.2 Gi0/010.0.12.0/30Gi0/1 .1192.168.20.0/24InternetNTP 198.51.100.10R1HQ edgeSW1mgmt 192.168.10.2PC1VLAN 10, DHCP clientR2server siteSRV1192.168.20.10
  1. 1. You reach R1's CLI with SSH. Through the VPN at HQ, you log in to R1 with a local username. Everything you type is encrypted.
  2. 2. copy running-config tftp: R1 sends its running config to SRV1 as a backup file.
  3. 3. copy ftp: flash: R1 logs in to SRV1's FTP server and downloads the new IOS image into flash.
  4. 4. R1 boots the new image. After checking the file's hash and pointing boot system at it, you save and reload.
1. Back up the config
copy running-config tftp:
2. Check free space
show flash: or dir flash:
3. Copy the new image
copy ftp: flash: (or tftp:)
4. Check the image
verify /md5 flash:<file>
5. Point the router at it
boot system flash:<file>
6. Save and reload
copy running-config startup-config, reload
7. Confirm
show version
A safe IOS upgrade on a router with enough flash for both images.

How to configure it on Cisco IOS

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. File names, sizes and prompts vary by platform and release. The image names here are examples for an ISR G2 router.

1. SSH access (a short recap)

The full explanation is in Passwords, local users and SSH. The minimum on R1 is:

hostname R1 ip domain name hq.example.com crypto key generate rsa modulus 2048 ip ssh version 2 username admin privilege 15 secret Adm1n-Pass line vty 0 4 login local transport input ssh

A hostname and domain name are needed to name the RSA key. transport input ssh refuses Telnet.

2. Back up the configuration with TFTP

copy running-config tftp:

Privileged EXEC. IOS asks for the server address and a file name.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#copy running-config tftp:
Address or name of remote host []? 192.168.20.10
Destination filename [r1-confg]? R1-backup-2026-10-06.cfg
!!
2148 bytes copied in 1.212 secs (1772 bytes/sec)
Each ! is a successful chunk. The default file name is the hostname in lowercase plus -confg.

3. Copy a new IOS image with FTP

ip ftp username backup ip ftp password Ftp-Pass-789 ip ftp source-interface GigabitEthernet0/1

Global configuration. The login R1 uses on SRV1's FTP server. Without it, IOS tries an anonymous login.

copy ftp://192.168.20.10/c2900-universalk9-mz.SPA.157-3.M8.bin flash:

Privileged EXEC. You can also put the login in the URL: ftp://backup:Ftp-Pass-789@192.168.20.10/file, though it then shows in the command history.

The same copy with TFTP, answering the prompts:

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#copy tftp: flash:
Address or name of remote host []? 192.168.20.10
Source filename []? c2900-universalk9-mz.SPA.157-3.M8.bin
Destination filename [c2900-universalk9-mz.SPA.157-3.M8.bin]?
Accessing tftp://192.168.20.10/c2900-universalk9-mz.SPA.157-3.M8.bin...
Loading c2900-universalk9-mz.SPA.157-3.M8.bin from 192.168.20.10 (via GigabitEthernet0/1): !!!!!!!!!!!!!!!!!!!!
...
[OK - 110634256 bytes]

110634256 bytes copied in 412.884 secs (267953 bytes/sec)
Press Enter to accept the name in square brackets. If flash is too small, IOS asks whether to erase it first; say no and delete old files yourself so you keep a fallback.

4. Check the image and boot it

verify /md5 flash:c2900-universalk9-mz.SPA.157-3.M8.bin

Calculates the file's MD5 hash. Compare it with the hash on Cisco's download page; a different value means a damaged copy.

configure terminal boot system flash:c2900-universalk9-mz.SPA.157-3.M8.bin boot system flash:c2900-universalk9-mz.SPA.155-3.M10.bin end copy running-config startup-config reload

boot system lines are tried in order, so the old image is a fallback. Save before reloading, or the boot commands are lost.

Full example (R1)

! Global configuration ip ftp username backup ip ftp password Ftp-Pass-789 ip ftp source-interface GigabitEthernet0/1 boot system flash:c2900-universalk9-mz.SPA.157-3.M8.bin boot system flash:c2900-universalk9-mz.SPA.155-3.M10.bin ! ! Privileged EXEC copy running-config tftp://192.168.20.10/R1-backup-2026-10-06.cfg copy ftp://192.168.20.10/c2900-universalk9-mz.SPA.157-3.M8.bin flash: verify /md5 flash:c2900-universalk9-mz.SPA.157-3.M8.bin copy running-config startup-config reload

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#dir flash:
Directory of flash:/

    1  -rw-   106219980  Mar 2 2024 10:14:22 +00:00  c2900-universalk9-mz.SPA.155-3.M10.bin
    2  -rw-   110634256  Oct 6 2026 21:40:51 +00:00  c2900-universalk9-mz.SPA.157-3.M8.bin
    3  -rw-        2148  Oct 6 2026 21:31:07 +00:00  R1-pre-upgrade.cfg

255744000 bytes total (38883584 bytes free)
Both images are present, and you can see the free space before and after a copy. show flash: gives similar output.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show version | include image|uptime
R1 uptime is 4 minutes
System image file is "flash:c2900-universalk9-mz.SPA.157-3.M8.bin"
After the reload, System image file names the new image and the uptime is short. The full show version also shows the IOS release and the configuration register.
show boot

On many platforms, shows the boot variable: the images the router will try at the next reload. Where it isn't available, show running-config | include boot shows the boot system lines.

What goes wrong and how to troubleshoot it

  • "Timed out" or "No such file" with TFTP. Ping the server from the router, check the file is in the TFTP server's root folder, and check no ACL blocks UDP 69 (or the data ports TFTP moves to).
  • FTP login fails. The ip ftp username and password don't match a user on the server, or IOS used anonymous login because they weren't set.
  • Not enough space in flash. Delete unused files with delete flash:<file>. Never delete the image the router is running unless the new one is copied and verified.
  • The router boots into ROMMON. No valid image was found, often because the boot system line has a typo. From ROMMON you can boot an image by name or load one with TFTP.
  • SSH refuses connections. No RSA key, no local user with login local, or transport input doesn't include ssh.

Common mistakes

  • Reloading without saving, so the new boot system line is lost.
  • Expecting copy tftp: running-config to replace the config. It merges.
  • Thinking the TFTP server pushes the file. The router is the client and starts every transfer.
  • Skipping verify /md5 and booting a damaged image.
  • Mixing up the ports: TFTP is UDP 69; FTP is TCP 21 for control plus a data connection (TCP 20 in active mode).

💡 Exam tip: the blueprint item is describe the capabilities and functions of TFTP/FTP in the network, next to configure network devices for remote access using SSH. Know that TFTP is UDP 69 with no authentication, FTP is TCP 20/21 with a username and password, and neither encrypts. Be ready to read a copy command and say which way the file goes: the first argument is always the source.

Key takeaways

  • Use SSH (TCP 22) for remote CLI access; Telnet sends everything in clear text.
  • copy <source> <destination>: the router is the TFTP/FTP client.
  • TFTP: UDP 69, no login, simple. FTP: TCP 21 + data, login with ip ftp username/password.
  • Upgrade safely: back up, check space, copy, verify /md5, boot system, save, reload, show version.
  • Copying into running-config merges; it doesn't replace.

Check yourself

Predict · scenario 1

You run 'copy tftp: running-config' with a file that doesn't contain R1's 'ip route' lines. What happens to R1's existing static routes?

Predict · scenario 2

Which statement about TFTP is true?

Predict · scenario 3

You copied a new IOS image into flash and reloaded. show version still shows the old image. What was most likely missed?

Predict · scenario 4

R1 must download an image from an FTP server that needs a login. Which commands give R1 the credentials?

Predict · scenario 5

Where does the startup configuration live on a Cisco router?

FAQ

What is the difference between TFTP and FTP for Cisco devices?
TFTP runs over UDP port 69, has no login and no directory listing, and is very simple, so it is built into almost every device. FTP runs over TCP (port 21 for control, a separate data connection for the file), needs a username and password, and is more reliable for large files such as IOS images. Neither encrypts the file; SCP or SFTP do.
Does copy tftp: running-config replace my configuration?
No. Copying into the running config merges: each line is applied as if you had typed it. Commands in the file are added or changed, but nothing that is missing from the file is removed. To replace a configuration completely, use configure replace, or copy to startup-config and reload.
Why does the router still boot the old IOS after I copied the new image?
Copying a file into flash doesn't change what the router boots. Without a boot system command it usually boots the first valid image in flash. Add boot system flash:<new file>, save the configuration, and then reload.
Do I need SSH to use TFTP or FTP?
No. The copy command is typed on the router's CLI, which you reach by console or SSH. The router itself then acts as the TFTP or FTP client and connects to the server. SSH is simply the secure way to reach that CLI remotely.