ok so I have an ASA 5505 and try to back it up and tftp the config. there is a vpn tunnel between the two locations. i can tftp when im on the subnet but not through the tunnel. so where does the back up originate from? the outside interface?
I would imagine so, its more than likely the same as when the device is acting as a dhcp-rely across a tunnel. The request is sourced from the outside.
try add a rule to your crypto access-list that specifies the outside interface IP address to the tftp server IP address using tftp and the mirror the access-list on the remote end.
I believe this relates to WHERE the TFTP traffic is being generated on the ASA and if the traffic is being recognised as interesting and thus sent down the tunnel.
The TFTP traffic never passes THROUGH an interface so is not identified as interesting, and thus sent down the tunnel. You'll have a similar problem with ping from the ASA (unless you specify an interface)...
-Blue
The significant problems we face cannot be solved at the same level of thinking we were at when we created them
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.