Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.3.4 (16 of 20 in this unit)49 of 84 in the Network Fundamentals course

FTP, SFTP and TFTP

Three ways to move files, and where network engineers still use each one.

Beginner · 7 min read

FTP (File Transfer Protocol) and TFTP (Trivial File Transfer Protocol) are protocols for copying files between a client and a server. FTP runs over TCP with a login and separate control and data connections; TFTP is a minimal protocol over UDP port 69 with no authentication, often used to move configurations and software images to and from network devices.

In simple terms: They are ways to copy files over a network. FTP is the full version with a login; TFTP is a very simple version that network devices often use for backups and software updates.

A situation

Before you change a router's configuration, your team lead says: “Back up the config first.” Later that month, a new IOS image must be copied to twenty routers. Both jobs mean moving files between a server and network devices. Three common protocols can do this, and each one suits a different job.

What they are

FTPSFTPTFTP
Full nameFile Transfer ProtocolSSH File Transfer ProtocolTrivial File Transfer Protocol
Transport and portTCP 21 (control), plus a data connectionTCP 22 (inside SSH)UDP 69
LoginUsername and passwordUsername and password or keyNone
EncryptionNone (FTPS adds TLS)YesNone
Can list foldersYesYesNo: you must know the file name
Typical useOld file serversSecure file transferConfigs, IOS images, IP phone boot files

FTP: two connections

FTP is unusual because it uses two TCP connections. The control connection to port 21 carries commands, such as the login and “send me this file”. A separate data connection carries the file itself or a folder listing. FTP has two ways to open that data connection:

  • Active mode: the client tells the server which port to use, and the server connects back to the client from port 20.
  • Passive mode: the server tells the client which port to use, and the client opens the data connection as well.
Step 1 of 5 · USER / PASS
FTP client
192.168.1.20
Firewall + NAT
allows outbound only
FTP server
198.51.100.25

In active mode, the server would open the data connection inbound to the client. A firewall or NAT router in front of the client usually blocks that, which is why passive mode is the normal choice today.

Why TFTP is still everywhere

TFTP is very small. It has no login, no folder listing and no encryption. It sends the file in small blocks over UDP and waits for an acknowledgement after each one, so TFTP itself handles lost blocks. That makes it slow and insecure, but so simple that even a device that is still booting can use it. That is why network devices and IP phones still rely on it.

R110.1.1.1Core switchTFTP server10.1.99.50
  1. 1. Write request. R1 sends a request to UDP port 69 to write the file r1-confg.
  2. 2. Data blocks. R1 sends the file in blocks of 512 bytes.
  3. 3. Acknowledge. The server acknowledges each block before R1 sends the next one.

How to verify it

Copy the running configuration to a TFTP server. The router asks for the server address and the file name. This output is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#copy running-config tftp:
Address or name of remote host []? 10.1.99.50
Destination filename [r1-confg]?
!!
2147 bytes copied in 0.384 secs (5591 bytes/sec)
What to look for: each ! means data was transferred successfully (a . would mean a timeout). The last line, 2147 bytes copied, confirms the backup reached the server. Pressing Enter at the filename prompt accepts the default name shown in brackets.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#copy tftp: flash:
Address or name of remote host []? 10.1.99.50
Source filename []? isr4300-universalk9.17.09.04a.SPA.bin
Destination filename [isr4300-universalk9.17.09.04a.SPA.bin]?
Accessing tftp://10.1.99.50/isr4300-universalk9.17.09.04a.SPA.bin...
Loading isr4300-universalk9.17.09.04a.SPA.bin from 10.1.99.50 (via GigabitEthernet0/0/0): !!!!!!!!!!!!!!!!!!!!
[OK - 593015180 bytes]
What to look for: the Loading … via GigabitEthernet0/0/0 line shows which interface was used, the ! marks show progress, and [OK - 593015180 bytes] confirms that the whole IOS XE image arrived in flash. Large images over TFTP are slow; FTP, SCP or HTTP(S) are faster choices where the device supports them.

To use FTP instead, give the router a login first. These commands are based on Cisco documentation, not run on a lab device:

ip ftp username backup

The username the router uses when it logs in to an FTP server.

ip ftp password B4ckup-Pass

The matching password (sent in clear text, like all FTP logins).

copy running-config ftp://10.1.99.50/r1-confg

Copy the configuration to the FTP server.

Check yourself

Predict · scenario 1

A switch that is still booting must download a file from a server using a simple protocol over UDP, with no username. Which protocol is it using?

Predict · scenario 2

An FTP client behind a NAT router logs in successfully, but every folder listing hangs. Which change usually fixes it?

Predict · scenario 3

Your security team bans clear-text passwords. Which protocol should you use to move files to a Linux server?