A real-life situation
A Cisco security advisory says R1's IOS version has a bug, and your manager wants it upgraded tonight. You are at home. You also realise there is no backup of R1's configuration anywhere but the router itself. You need three things: a secure way to reach the CLI from home (SSH), a way to copy the config off the router, and a way to copy a 100 MB image on to it. In the lab, SRV1 (192.168.20.10) runs a TFTP and an FTP server.
What these tools are
| Protocol | Transport | Login | Encrypted | Used for |
|---|---|---|---|---|
| SSH | TCP 22 | Yes | Yes | Remote CLI access |
| Telnet | TCP 23 | Yes | No | Remote CLI access (avoid) |
| TFTP | UDP 69 | No | No | Quick copies of configs and images |
| FTP | TCP 21 + data connection | Yes | No | Larger, more reliable copies |
| SCP | TCP 22 (inside SSH) | Yes | Yes | Secure copies |
The protocols themselves are explained in FTP, SFTP and TFTP and SSH and Telnet. On a Cisco device, the router is the client: you type copy on the router and it connects to the server.
The IOS file system
Cisco IOS names each storage area with a prefix ending in a colon, a bit like a drive letter:
flash:holds the IOS image and other files. It keeps its contents when the power is off.nvram:holds the startup-config (nvram:startup-config).system:holds the running-config in RAM (system:running-config).tftp:,ftp:,scp:are network locations.usbflash0:is a USB stick on routers that have a port.
show file systems lists them all, and dir or show flash: lists the files in one.
Why it works that way
TFTP is tiny: it sends the file in numbered 512-byte blocks and waits for an acknowledgement of each block before sending the next. That is easy to build into a router's boot code, which is why TFTP is everywhere. But it is slow over long distances, has no login, and anyone who can reach the server can read or overwrite files. FTP uses TCP, which handles lost packets and sends many segments at once, and it asks for a username and password. That makes it the better choice for large images, but the password and the file still travel in clear text.
The secure options are SSH for the CLI and SCP for copying, because both run inside an encrypted SSH session. On the CCNA, TFTP and FTP are what you are asked about; in real networks SCP is a good habit.
How it works step by step
- 1. You reach R1's CLI with SSH. Through the VPN at HQ, you log in to R1 with a local username. Everything you type is encrypted.
- 2. copy running-config tftp: R1 sends its running config to SRV1 as a backup file.
- 3. copy ftp: flash: R1 logs in to SRV1's FTP server and downloads the new IOS image into flash.
- 4. R1 boots the new image. After checking the file's hash and pointing boot system at it, you save and reload.
How to configure it on Cisco IOS
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. File names, sizes and prompts vary by platform and release. The image names here are examples for an ISR G2 router.
1. SSH access (a short recap)
The full explanation is in Passwords, local users and SSH. The minimum on R1 is:
hostname R1
ip domain name hq.example.com
crypto key generate rsa modulus 2048
ip ssh version 2
username admin privilege 15 secret Adm1n-Pass
line vty 0 4
login local
transport input sshA hostname and domain name are needed to name the RSA key. transport input ssh refuses Telnet.
2. Back up the configuration with TFTP
copy running-config tftp:Privileged EXEC. IOS asks for the server address and a file name.
R1#copy running-config tftp: Address or name of remote host []? 192.168.20.10 Destination filename [r1-confg]? R1-backup-2026-10-06.cfg !! 2148 bytes copied in 1.212 secs (1772 bytes/sec)
-confg.3. Copy a new IOS image with FTP
ip ftp username backup
ip ftp password Ftp-Pass-789
ip ftp source-interface GigabitEthernet0/1Global configuration. The login R1 uses on SRV1's FTP server. Without it, IOS tries an anonymous login.
copy ftp://192.168.20.10/c2900-universalk9-mz.SPA.157-3.M8.bin flash:Privileged EXEC. You can also put the login in the URL: ftp://backup:Ftp-Pass-789@192.168.20.10/file, though it then shows in the command history.
The same copy with TFTP, answering the prompts:
R1#copy tftp: flash: Address or name of remote host []? 192.168.20.10 Source filename []? c2900-universalk9-mz.SPA.157-3.M8.bin Destination filename [c2900-universalk9-mz.SPA.157-3.M8.bin]? Accessing tftp://192.168.20.10/c2900-universalk9-mz.SPA.157-3.M8.bin... Loading c2900-universalk9-mz.SPA.157-3.M8.bin from 192.168.20.10 (via GigabitEthernet0/1): !!!!!!!!!!!!!!!!!!!! ... [OK - 110634256 bytes] 110634256 bytes copied in 412.884 secs (267953 bytes/sec)
4. Check the image and boot it
verify /md5 flash:c2900-universalk9-mz.SPA.157-3.M8.binCalculates the file's MD5 hash. Compare it with the hash on Cisco's download page; a different value means a damaged copy.
configure terminal
boot system flash:c2900-universalk9-mz.SPA.157-3.M8.bin
boot system flash:c2900-universalk9-mz.SPA.155-3.M10.bin
end
copy running-config startup-config
reloadboot system lines are tried in order, so the old image is a fallback. Save before reloading, or the boot commands are lost.
Full example (R1)
! Global configuration
ip ftp username backup
ip ftp password Ftp-Pass-789
ip ftp source-interface GigabitEthernet0/1
boot system flash:c2900-universalk9-mz.SPA.157-3.M8.bin
boot system flash:c2900-universalk9-mz.SPA.155-3.M10.bin
!
! Privileged EXEC
copy running-config tftp://192.168.20.10/R1-backup-2026-10-06.cfg
copy ftp://192.168.20.10/c2900-universalk9-mz.SPA.157-3.M8.bin flash:
verify /md5 flash:c2900-universalk9-mz.SPA.157-3.M8.bin
copy running-config startup-config
reloadHow to verify it
R1#dir flash: Directory of flash:/ 1 -rw- 106219980 Mar 2 2024 10:14:22 +00:00 c2900-universalk9-mz.SPA.155-3.M10.bin 2 -rw- 110634256 Oct 6 2026 21:40:51 +00:00 c2900-universalk9-mz.SPA.157-3.M8.bin 3 -rw- 2148 Oct 6 2026 21:31:07 +00:00 R1-pre-upgrade.cfg 255744000 bytes total (38883584 bytes free)
show flash: gives similar output.R1#show version | include image|uptime R1 uptime is 4 minutes System image file is "flash:c2900-universalk9-mz.SPA.157-3.M8.bin"
show version also shows the IOS release and the configuration register.show bootOn many platforms, shows the boot variable: the images the router will try at the next reload. Where it isn't available, show running-config | include boot shows the boot system lines.
What goes wrong and how to troubleshoot it
- "Timed out" or "No such file" with TFTP. Ping the server from the router, check the file is in the TFTP server's root folder, and check no ACL blocks UDP 69 (or the data ports TFTP moves to).
- FTP login fails. The
ip ftp usernameandpassworddon't match a user on the server, or IOS used anonymous login because they weren't set. - Not enough space in flash. Delete unused files with
delete flash:<file>. Never delete the image the router is running unless the new one is copied and verified. - The router boots into ROMMON. No valid image was found, often because the
boot systemline has a typo. From ROMMON you can boot an image by name or load one with TFTP. - SSH refuses connections. No RSA key, no local user with
login local, ortransport inputdoesn't include ssh.
Common mistakes
- Reloading without saving, so the new
boot systemline is lost. - Expecting
copy tftp: running-configto replace the config. It merges. - Thinking the TFTP server pushes the file. The router is the client and starts every transfer.
- Skipping
verify /md5and booting a damaged image. - Mixing up the ports: TFTP is UDP 69; FTP is TCP 21 for control plus a data connection (TCP 20 in active mode).
💡 Exam tip: the blueprint item is describe the capabilities and functions of TFTP/FTP in the network, next to configure network devices for remote access using SSH. Know that TFTP is UDP 69 with no authentication, FTP is TCP 20/21 with a username and password, and neither encrypts. Be ready to read a copy command and say which way the file goes: the first argument is always the source.
Key takeaways
- Use SSH (TCP 22) for remote CLI access; Telnet sends everything in clear text.
copy <source> <destination>: the router is the TFTP/FTP client.- TFTP: UDP 69, no login, simple. FTP: TCP 21 + data, login with
ip ftp username/password. - Upgrade safely: back up, check space, copy,
verify /md5,boot system, save, reload,show version. - Copying into running-config merges; it doesn't replace.
Check yourself
You run 'copy tftp: running-config' with a file that doesn't contain R1's 'ip route' lines. What happens to R1's existing static routes?
Which statement about TFTP is true?
You copied a new IOS image into flash and reloaded. show version still shows the old image. What was most likely missed?
R1 must download an image from an FTP server that needs a login. Which commands give R1 the credentials?
Where does the startup configuration live on a Cisco router?