// Engineering Log

File Transfer Protocols: Part 3 — TFTP and SCP

Published on 2026-09-22

TFTP and SCP do not compete with FTP and SFTP for the role of the primary file-transfer method. They are narrow tools: the first is needed for network equipment and network booting, the second — for fast copying between servers over SSH. But you encounter them often, and both have characteristics worth knowing.

TFTP: a minimal protocol for hardware

TFTP (Trivial File Transfer Protocol) is described in RFC 1350. It runs over UDP, the server listens on port 69. The protocol can do exactly two things — read a file and write a file — and nothing else:

  • no authentication: no login, no password;
  • no directory listing: you need to know the filename in advance;
  • no encryption;
  • data is sent in 512-byte blocks, each block is acknowledged before the next is sent, so TFTP is slow on high-latency links.

This simplicity is not a drawback but the point. A TFTP client fits into the boot ROM of a network card or a router bootloader, where there’s no room for a full stack.

Where TFTP is used

  • Network boot (PXE). A diskless computer gets from the DHCP server the address of a TFTP server and the name of the boot file, downloads the bootloader via TFTP and continues booting. This is how operating systems are deployed on dozens of machines and how thin clients are booted.
  • Firmware and configuration for network equipment. Switches, routers and IP phones can fetch firmware or configuration from a TFTP server. IP phones often download their settings this way at startup.
  • Recovering a bricked device. Many routers in recovery mode accept firmware only via TFTP.

How to run a TFTP server safely

On Debian and Ubuntu the common package is tftpd-hpa. Settings are in /etc/default/tftpd-hpa:

bash
TFTP_USERNAME="tftp"
TFTP_DIRECTORY="/srv/tftp"
TFTP_ADDRESS="192.0.2.5:69"
TFTP_OPTIONS="--secure"
  • --secure confines the server to the /srv/tftp directory: a client will not be able to request files outside it.
  • TFTP_ADDRESS is better bound to an address on the internal network, not to all interfaces.
  • File uploads are disabled by default — enable them only if the device truly needs to upload files to the server.

TFTP risks

The lack of authentication means anyone who can reach the server can download any file from its directory if they know or guess the name. And configurations for IP phones and routers often contain SIP account passwords and keys. Therefore:

  • Never expose a TFTP server to the Internet — only on the internal network or in a separate VLAN for equipment;
  • keep only what devices currently need in the directory;
  • after flashing equipment, stop the server if it is no longer needed.

SCP: copying over SSH

SCP (secure copy) is a command for copying files between computers over SSH. The syntax mirrors regular cp:

bash
# copy a file to the server
scp backup.tar.gz admin@192.0.2.10:/srv/backup/

# copy a directory from the server, preserving timestamps and permissions
scp -rp admin@192.0.2.10:/var/www/site ./site-copy

Authentication, encryption and keys are the same as SSH, so a separate server is not needed: if you can SSH to a machine, you can copy files to/from it.

What changed in OpenSSH 9.0

Historically scp used its own scp/rcp protocol. It had design problems: filenames were processed by the remote shell, meaning spaces and special characters had to be escaped twice, and vulnerabilities were found in the protocol itself.

Starting with OpenSSH 9.0 (2022) the scp command by default uses the SFTP protocol. The syntax for the user didn’t change, but under the hood it now uses the same protocol as sftp. If the remote side does not support SFTP — for example, an old device or a limited SSH server — you can revert to the old protocol with the -O option:

bash
scp -O firmware.bin admin@192.0.2.20:/tmp/

From this it follows that the contrast “SCP — non-interactive, SFTP — interactive” now describes different interfaces, not different protocols. scp is convenient for one-off commands, sftp — for working in an interactive session or a batch script.

Alternatives to SCP for regular tasks

  • rsync over SSH — transfers only changed parts of files, can resume interrupted transfers and synchronize directories. For backups and regular copying it is better than scp.
  • sftp in batch mode — sftp -b commands.txt user@host executes a prepared list of commands, convenient for scheduled exports.

Common mistakes

  • TFTP server exposed to the Internet. Anyone can download configurations with passwords.
  • The firewall allows port 69 but TFTP still doesn’t work. Data comes from another, random server port, so you need a conntrack helper for TFTP (or allow the reply traffic).
  • Old scripts using scp fail on a new server. The usual reason is SFTP by default: the remote side doesn’t support SFTP — -O helps, but it’s better to update the remote side.
  • Copying large directories with scp -r every time from scratch. For recurring tasks use rsync.

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply