A situation
Before you change a router's configuration, your team lead says: “Back up the config first.” Later that month, a new IOS image must be copied to twenty routers. Both jobs mean moving files between a server and network devices. Three common protocols can do this, and each one suits a different job.
What they are
| FTP | SFTP | TFTP | |
|---|---|---|---|
| Full name | File Transfer Protocol | SSH File Transfer Protocol | Trivial File Transfer Protocol |
| Transport and port | TCP 21 (control), plus a data connection | TCP 22 (inside SSH) | UDP 69 |
| Login | Username and password | Username and password or key | None |
| Encryption | None (FTPS adds TLS) | Yes | None |
| Can list folders | Yes | Yes | No: you must know the file name |
| Typical use | Old file servers | Secure file transfer | Configs, IOS images, IP phone boot files |
FTP: two connections
FTP is unusual because it uses two TCP connections. The control connection to port 21 carries commands, such as the login and “send me this file”. A separate data connection carries the file itself or a folder listing. FTP has two ways to open that data connection:
- Active mode: the client tells the server which port to use, and the server connects back to the client from port 20.
- Passive mode: the server tells the client which port to use, and the client opens the data connection as well.
In active mode, the server would open the data connection inbound to the client. A firewall or NAT router in front of the client usually blocks that, which is why passive mode is the normal choice today.
Why TFTP is still everywhere
TFTP is very small. It has no login, no folder listing and no encryption. It sends the file in small blocks over UDP and waits for an acknowledgement after each one, so TFTP itself handles lost blocks. That makes it slow and insecure, but so simple that even a device that is still booting can use it. That is why network devices and IP phones still rely on it.
- 1. Write request. R1 sends a request to UDP port 69 to write the file r1-confg.
- 2. Data blocks. R1 sends the file in blocks of 512 bytes.
- 3. Acknowledge. The server acknowledges each block before R1 sends the next one.
How to verify it
Copy the running configuration to a TFTP server. The router asks for the server address and the file name. This output is based on Cisco documentation, not run on a lab device.
R1#copy running-config tftp: Address or name of remote host []? 10.1.99.50 Destination filename [r1-confg]? !! 2147 bytes copied in 0.384 secs (5591 bytes/sec)
! means data was transferred successfully (a . would mean a timeout). The last line, 2147 bytes copied, confirms the backup reached the server. Pressing Enter at the filename prompt accepts the default name shown in brackets.R1#copy tftp: flash: Address or name of remote host []? 10.1.99.50 Source filename []? isr4300-universalk9.17.09.04a.SPA.bin Destination filename [isr4300-universalk9.17.09.04a.SPA.bin]? Accessing tftp://10.1.99.50/isr4300-universalk9.17.09.04a.SPA.bin... Loading isr4300-universalk9.17.09.04a.SPA.bin from 10.1.99.50 (via GigabitEthernet0/0/0): !!!!!!!!!!!!!!!!!!!! [OK - 593015180 bytes]
! marks show progress, and [OK - 593015180 bytes] confirms that the whole IOS XE image arrived in flash. Large images over TFTP are slow; FTP, SCP or HTTP(S) are faster choices where the device supports them.To use FTP instead, give the router a login first. These commands are based on Cisco documentation, not run on a lab device:
ip ftp username backupThe username the router uses when it logs in to an FTP server.
ip ftp password B4ckup-PassThe matching password (sent in clear text, like all FTP logins).
copy running-config ftp://10.1.99.50/r1-confgCopy the configuration to the FTP server.
Check yourself
A switch that is still booting must download a file from a server using a simple protocol over UDP, with no username. Which protocol is it using?
An FTP client behind a NAT router logs in successfully, but every folder listing hangs. Which change usually fixes it?
Your security team bans clear-text passwords. Which protocol should you use to move files to a Linux server?