Choosing the Right Transfer Protocol in FileZilla: FTP, FTPS, and SFTP
A technical guide to choosing between FTP, FTPS, and SFTP in FileZilla, focusing on security trade-offs, firewall traversal, and verification of encrypted connections.
05 Jan 2026, 01:34 UTC

The Protocol Selection Problem
When configuring a new connection in FileZilla, the most critical decision is selecting the transfer protocol. Choosing the wrong one leads to three common failure points: credentials sent in plain text over the network, "Failed to retrieve directory listing" errors caused by firewall blocks, or immediate connection timeouts due to protocol mismatches.
The goal is to balance security requirements against the constraints of your network firewall and the capabilities of the remote server.
Protocol Comparison Matrix
| Feature | FTP (Plain) | FTPS (FTP over TLS) | SFTP (SSH File Transfer) |
|---|---|---|---|
| Encryption | None | TLS/SSL | SSH-2 |
| Primary Port | 21 | 21 (Explicit) | 22 |
| Firewall Complexity | High (Multiple ports) | High (Dynamic ports) | Low (Single port) |
| Auth Method | Password | Password/Cert | Password/SSH Key |
| Use Case | Public/Non-sensitive | Legacy Enterprise | Linux Servers/Secure Ops |
Engineering Trade-offs
FTP (Plain)
FTP is a legacy protocol that transmits both usernames and passwords in cleartext. It is only appropriate for public mirrors or internal networks where security is handled at a different layer. It is generally avoided in professional engineering workflows.
FTPS (Explicit TLS)
FTPS adds a layer of TLS (Transport Layer Security) to the standard FTP protocol. While it secures the data, it retains the "dual-channel" architecture of FTP: a control channel for commands and a separate data channel for file transfers.
The Firewall Constraint: Because the data channel uses a dynamic range of ports, FTPS often fails when the client is behind a strict NAT (Network Address Translation) or firewall. This typically manifests as a successful login followed by a hang during the MLSD (directory listing) command.
SFTP (SSH File Transfer Protocol)
Despite the name, SFTP is not FTP with security added; it is an entirely different protocol based on SSH (Secure Shell). It handles both commands and data over a single encrypted tunnel (usually port 22).
The Infrastructure Constraint: SFTP requires an SSH server to be running on the destination. If the server is a dedicated FTP appliance, SFTP will not work regardless of the client settings.
Implementation: Configuring Secure FTPS
If your server requires FTPS (Explicit TLS), follow these steps in the FileZilla Site Manager to ensure the connection is encrypted and can traverse most firewalls using Passive mode.
- Open Site Manager (Ctrl+S).
- Click New Site and provide a name.
- Protocol: Select
FTP - File Transfer Protocol. - Encryption: Select
Require explicit FTP over TLS. (Avoid "Use plain FTP" for any production data). - Logon Type: Select
Normaland enter your credentials. - Switch to the Transfer Settings tab.
- Transfer Mode: Select
Passive. This tells the server to open the data port, which is more likely to pass through your local firewall. - Click Connect.
Verification and Diagnostics
To verify that your connection is actually encrypted and not falling back to plain text, check the Message Log at the top of the FileZilla interface. Look for the following sequence:
Status: Action: TLS connection established
Status: Status: TLS session resumed
Status: Command: AUTH TLS
If you see Status: Connection established without any mention of TLS or SSL, your credentials may be exposed. If the log shows Failed to retrieve directory listing, the issue is likely a firewall blocking the passive port range on the server side.
Limitations
- Certificate Trust: FTPS requires the client to trust the server's SSL certificate. If the server uses a self-signed certificate, FileZilla will prompt you to trust it manually.
- Implicit TLS: Some older servers use "Implicit TLS" (usually on port 990). If Explicit TLS fails, check if the server specifically requires Implicit mode.
- SFTP Mismatch: Attempting to connect to an SFTP server using the "FTP" protocol setting will result in a
421or530error, as the protocols are fundamentally incompatible.
Rollback
Since these changes are saved per-site in the Site Manager and do not alter system-level network configurations, "rolling back" simply involves deleting the site entry or changing the Encryption dropdown back to Only use plain FTP if troubleshooting connectivity on a non-secure legacy system.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.