|
| 1 | +TFTP Server |
| 2 | +=========== |
| 3 | + |
| 4 | +The TFTP server hands out files to devices on the local network, for |
| 5 | +example a fallback boot image for devices whose own firmware partition |
| 6 | +has failed, or configuration files for IP phones and similar equipment. |
| 7 | +It is read-only, so clients cannot upload files. |
| 8 | + |
| 9 | +Files are served from a root directory, by default `/var/lib/tftpboot`. |
| 10 | +This directory is persistent on all supported boards and writable by |
| 11 | +admin users, so files can be placed there from the CLI or a shell. A |
| 12 | +directory on USB media, e.g., `/media/usb/tftp`, can be used instead. |
| 13 | + |
| 14 | +> [!IMPORTANT] |
| 15 | +> Only world-readable files are served. Files copied with the CLI |
| 16 | +> `copy` command are made world-readable automatically, files copied |
| 17 | +> from a shell must be given mode `0644` or similar. |
| 18 | +
|
| 19 | +> [!CAUTION] |
| 20 | +> TFTP has no authentication. Every file below the root can be read by |
| 21 | +> any client that reaches the server, so never keep a saved system |
| 22 | +> configuration there -- it carries password hashes, keys, and other |
| 23 | +> secrets. Limit the server to the interfaces facing the clients. |
| 24 | +
|
| 25 | + |
| 26 | +## Basic Configuration |
| 27 | + |
| 28 | +<pre class="cli"><code>admin@example:/> <b>configure</b> |
| 29 | +admin@example:/config/> <b>set tftp enabled true</b> |
| 30 | +admin@example:/config/> <b>leave</b> |
| 31 | +</code></pre> |
| 32 | + |
| 33 | +The server listens on all interfaces by default. To restrict it to a |
| 34 | +subset, list the interfaces to serve on: |
| 35 | + |
| 36 | +<pre class="cli"><code>admin@example:/config/> <b>edit tftp</b> |
| 37 | +admin@example:/config/tftp/> <b>set interface eth1</b> |
| 38 | +admin@example:/config/tftp/> <b>set interface eth2</b> |
| 39 | +admin@example:/config/tftp/> <b>leave</b> |
| 40 | +</code></pre> |
| 41 | + |
| 42 | +When the firewall is enabled, the `tftp` service must also be allowed |
| 43 | +in the zone facing the clients, see [Firewall](firewall.md). |
| 44 | + |
| 45 | + |
| 46 | +## Uploading Files |
| 47 | + |
| 48 | +Files can be fetched to the TFTP root with the `copy` command from any |
| 49 | +of the supported remote sources, or copied from USB media. A directory |
| 50 | +destination keeps the source file name: |
| 51 | + |
| 52 | +<pre class="cli"><code>admin@example:/> <b>copy tftp://192.168.1.1/fallback.itb /var/lib/tftpboot/</b> |
| 53 | +admin@example:/> <b>copy /media/usb/phones.cfg /var/lib/tftpboot/</b> |
| 54 | +admin@example:/> <b>dir /var/lib/tftpboot</b> |
| 55 | +/var/lib/tftpboot directory |
| 56 | +fallback.itb phones.cfg |
| 57 | +</code></pre> |
| 58 | + |
| 59 | +Files are removed with the `remove` command, which asks for |
| 60 | +confirmation: |
| 61 | + |
| 62 | +<pre class="cli"><code>admin@example:/> <b>remove /var/lib/tftpboot/phones.cfg</b> |
| 63 | +Remove /var/lib/tftpboot/phones.cfg, are you sure? (y/N)? y |
| 64 | +</code></pre> |
| 65 | + |
| 66 | + |
| 67 | +## Per-Client Directories |
| 68 | + |
| 69 | +Some devices, IP phones in particular, expect a configuration file with |
| 70 | +a fixed name that differs per device. With `client-directory` set, the |
| 71 | +server first looks for the requested file in a subdirectory of the root |
| 72 | +named after the client, and falls back to the root itself if there is |
| 73 | +none: |
| 74 | + |
| 75 | +<pre class="cli"><code>admin@example:/config/tftp/> <b>set client-directory mac</b> |
| 76 | +</code></pre> |
| 77 | + |
| 78 | +With this setting a request for `config.xml` from the device with MAC |
| 79 | +address `00:11:22:33:44:55` is answered with |
| 80 | +`/var/lib/tftpboot/00-11-22-33-44-55/config.xml` if that file exists, |
| 81 | +otherwise with `/var/lib/tftpboot/config.xml`. Use `ip` instead of |
| 82 | +`mac` to name the directories after the client IP address. |
| 83 | + |
| 84 | + |
| 85 | +## Network Boot |
| 86 | + |
| 87 | +Devices that boot over the network learn the boot file name and TFTP |
| 88 | +server address from the DHCP server. See [Network Boot](dhcp.md#network-boot) |
| 89 | +in the DHCP server documentation for how to hand these out. |
| 90 | + |
| 91 | + |
| 92 | +## Monitoring |
| 93 | + |
| 94 | +<pre class="cli"><code>admin@example:/> <b>show tftp</b> |
| 95 | +Root directory : /var/lib/tftpboot |
| 96 | +Interfaces : all |
| 97 | +Client directory : none |
| 98 | + |
| 99 | +<span class="header">NAME SIZE MODIFIED </span> |
| 100 | +fallback.itb 7.0M 2026-09-18 05:18 |
| 101 | +phones.cfg 812B 2026-09-17 12:00 |
| 102 | +</code></pre> |
| 103 | + |
| 104 | +The file list is the operational view of the root directory and shows |
| 105 | +only files the server can actually hand out. A file missing from the |
| 106 | +list is either not world-readable or outside the configured root. |
0 commit comments