// Engineering Log
File Transfer Protocols: Part 1 — FTP
Published on 2026-09-22
FTP (File Transfer Protocol) — one of the oldest Internet protocols. Its current specification, RFC 959, was adopted in 1985, and the protocol has changed little since. FTP is still encountered at hosting providers, in network equipment, on legacy warehouse and accounting systems. To work with it properly — or to reasonably decide to avoid it — it’s useful to understand how it is organized.
Two connections: control and data
The main feature of FTP is that it uses two separate TCP connections.
- Control connection. The client connects to the server on port 21 and keeps this connection for the whole session. Text commands (
USER,PASS,LIST,RETR,STOR) and server replies with three-digit codes go over it. - Data connection. A separate connection is opened for each file transfer or directory listing and closed after the transfer.
It is this second connection that creates most problems with firewalls and NAT.
Active and passive mode
The mode defines who opens the data connection.
Active mode (the PORT command). The client tells the server its address and port, and the server connects to the client — per RFC 959 from port 20. If the client is behind NAT or a firewall, the incoming connection from the server will not reach it. Therefore, in practice active mode almost never works.
Passive mode (the PASV command, for IPv6 — EPSV per RFC 2428). The server opens a port on its side and tells the client, and the client connects itself. For a client behind NAT this is convenient, but now the server must accept incoming connections on arbitrary ports. From this come two mandatory settings:
- Range of passive ports. The server selects ports only from a specified range, and that range is what is opened in the firewall.
- External address. If the server itself is behind NAT, it must tell the client the public address, not the internal one; otherwise the client will try to connect “nowhere”.
The main problem: everything is sent in cleartext
In classic FTP there is no encryption. The USER and PASS commands with the username and password, directory listings and the files themselves are sent over the network as-is. Anyone who can intercept the traffic — on a shared Wi-Fi, at the ISP, or on an intermediate node — will see the password.
Therefore FTP without encryption is acceptable only in an isolated network where interception is impossible. For transfer over the Internet use FTPS or SFTP.
Minimal secure vsftpd configuration
vsftpd is the most common FTP server in Linux distributions. If FTP is still needed, here is a basic set of parameters from man vsftpd.conf:
# /etc/vsftpd.conf
listen=YES
anonymous_enable=NO # anonymous login disabled (default YES)
local_enable=YES # allow local system users to log in
write_enable=YES # allow uploading files
chroot_local_user=YES # jail users to their home directory
# passive mode: narrow port range for firewall
pasv_enable=YES
pasv_min_port=40000
pasv_max_port=40100
# pasv_address=203.0.113.10 # if server is behind NAT — external address
# encryption (FTPS)
ssl_enable=YES
rsa_cert_file=/etc/ssl/certs/ftp.example.ru.pem
rsa_private_key_file=/etc/ssl/private/ftp.example.ru.key
force_local_logins_ssl=YES # password only over secure channel
force_local_data_ssl=YES # data tooImportant points:
anonymous_enableis enabled by default — you need to explicitly disable it.pasv_min_portandpasv_max_portdefault to 0, meaning the server will pick any available port. Without a fixed range it is impossible to configure the firewall correctly.chroot_local_userprevents the user from leaving their home directory. Make the chroot root non-writable for the user and place files in a subdirectory.- With
ssl_enable=YESand theforce_*_sslparameters the server effectively becomes FTPS: logins without TLS will not be allowed.
Firewall rules for such a server — port 21 and range 40000–40100/TCP. For UFW:
sudo ufw allow 21/tcp
sudo ufw allow 40000:40100/tcpWhere FTP is still justified
- Devices that only support FTP: old MFPs with scan-to-folder, IP cameras, industrial equipment.
- Hosting panels where FTP is the only way to upload website files. If the provider supports SFTP, it’s better to switch to it.
- File exchange with a counterparty whose system supports only FTP. In that case — at least use FTPS and a separate account with minimal privileges.
Common mistakes
- Port 21 is open, but the passive port range is not. The client connects and authenticates but hangs when retrieving a directory listing.
- Server behind NAT without
pasv_address. The server tells the client an internal address, and the data connection is not established. - “Temporary” anonymous writable access. An open writable anonymous FTP is quickly found and used to store other people’s files.
- FTP without TLS over the Internet. The server password leaks at the first interception. If the same password is used for SSH or mail, everything is compromised at once.
Conclusion
FTP is simple and widely supported, but its architecture — two connections and cleartext — is poorly suited for the modern Internet. Use it only where unavoidable, and only with encryption. For new tasks, choose SFTP from the start.
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related