Configuring Explicit FTPS in FileZilla Server for Secure Transfers
Learn how to secure FileZilla Server using Explicit FTPS. This guide covers certificate configuration, passive port ranges, and firewall settings to prevent plaintext credential leaks.
30 Jan 2026, 15:55 UTC

The Problem: Preventing Plaintext Credential Leakage
Standard FTP transmits usernames, passwords, and file data in plaintext. Anyone with access to the network path between the client and server can capture these credentials using a packet sniffer. To secure this traffic, you must implement FTP over TLS (FTPS), which encrypts the control and data channels.
The most effective approach for modern environments is Explicit FTPS. Unlike Implicit FTPS (which requires a dedicated port like 990), Explicit FTPS starts on the standard port 21 and upgrades the connection to an encrypted state using the STARTTLS command. This ensures compatibility with most modern clients while enforcing encryption.
Prerequisites
- FileZilla Server installed and running (Version 1.x or newer recommended).
- Administrative access to the server hosting the application.
- Administrative access to the system firewall or network security group.
- An X.509 certificate (either a self-signed certificate generated by the server or one issued by a trusted Certificate Authority).
Step 1: Configure the TLS Certificate
The server cannot encrypt traffic without a certificate to identify itself and negotiate the handshake.
- Open the FileZilla Server Administration interface.
- Navigate to Settings > FTP Server > TLS settings.
- Under the Certificate section, select Generate new self-signed certificate for internal testing, or Import certificate if you have a CA-issued
.crtand.keyfile. - Define the Common Name (CN) as the Fully Qualified Domain Name (FQDN) of your server (e.g.,
ftp.example.com). This prevents "Hostname Mismatch" errors on the client side.
Step 2: Enforce Explicit FTPS
To prevent users from accidentally connecting via insecure plaintext FTP, you must mandate encryption.
- In the TLS settings menu, ensure Enable FTP over TLS support (FTPS) is checked.
- Select Require TLS for all connections. This forces the server to reject any client that does not support the
STARTTLScommand. - Verify that the Implicit FTPS option is disabled unless you have a specific legacy requirement for port 990.
Step 3: Define Passive Mode Port Ranges
Encryption complicates how firewalls handle data transfers. In Passive Mode, the server tells the client which port to use for the file transfer. If these ports are random, the firewall will block them.
- Navigate to Settings > FTP Server > Passive mode settings.
- Select Use custom port range.
- Enter a specific range, such as
50000 - 50100. - Enter the External IP address of the server if it is behind a NAT (Network Address Translation) device.
Step 4: Firewall Configuration
You must open the following ports on your server's firewall to allow encrypted traffic to flow:
| Port | Protocol | Purpose |
|---|---|---|
| 21 | TCP | Control Channel (Command/Auth) |
| 50000-50100 | TCP | Passive Data Channel (File Transfers) |
Verification and Diagnostics
To confirm the encryption is active and the firewall is not blocking the data channel, perform these checks:
1. Client Connection Check
Connect using a FileZilla Client. Set the Encryption dropdown to Require explicit FTP over TLS. If successful, the status log will show: Status: TLS session established.
2. Command Line Handshake
Run the following command from a remote machine with OpenSSL installed to verify the TLS handshake independently of the client software:
openssl s_client -starttls ftp -connect <your-server-ip>:21Expected Result: The output should display the certificate chain and end with Verify return code: 0 (ok) (if using a trusted CA) or a certificate validation error (if using self-signed).
3. Server Log Audit
Check the FileZilla Server logs. Look for the entry: SSL/TLS handshake succeeded. If you see TLS handshake failed, verify that the client and server support the same TLS version (TLS 1.2 or 1.3 is recommended).
Limitations and Risks
- Self-Signed Warnings: Clients will see a warning that the certificate is not trusted. This is normal for self-signed certificates but should be replaced by a CA-signed certificate in production.
- Inspection Failures: Some "Deep Packet Inspection" (DPI) firewalls cannot read encrypted FTP traffic and may drop the connection because they cannot see the
PASVresponse. You may need to disable FTP inspection on your firewall for the specific server IP.
Rollback Procedure
If connectivity is lost and you need to revert to plaintext FTP for troubleshooting:
- Go to TLS settings.
- Uncheck Require TLS for all connections.
- Change the encryption requirement to Optional.
- Restart the FileZilla Server service.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.