D-Link Forums

The Graveyard - Products No Longer Supported => Hubs and Switches => DGS-1224T => Topic started by: lil_evil on March 02, 2015, 01:48:05 AM

Title: Disable tftp // put ACLs on a trunk port
Post by: lil_evil on March 02, 2015, 01:48:05 AM
Dear all,

I am running a couple of dgs-1210. I recently came accross the issue of an TFTP directory traversal vulnerability.
So I was looking for mechanism to deactivate the tftp server on the switches.
However, as it turned out, I was unable to find any way to disable tftp on the switch.
Please correct me if I am wrong but this doesnt seem to be possible.

Secondly, I thought of putting an ACL on the switch, however since the switches are the end of the distribution, they are linkaggregated via LCAP to the core.
With the build-in ACL configurator I can only include non-aggregated ports into an ACL, hence the aggregated port (po1) is excluded.

What I am trying to achieve seems rather trivial, but I unfortuantly failed so far.
I would be very greatful if someone could throw me a lifeline.

many thanks
lil