Managing Multi-Protocol Server Access with FileZilla Site Manager
Stop relying on Quickconnect. Learn how to use FileZilla Site Manager to organize SFTP and FTPS profiles, implement key-based authentication, and secure your stored credentials.
06 Feb 2026, 19:31 UTC

The problem: Credential fatigue and connection errors
Manually entering hostnames, ports, and authentication keys every time you need to upload a file is inefficient. More importantly, mixing up protocols—such as attempting to connect to an SFTP server using standard FTP—often results in vague timeout errors or "Connection refused" messages that waste engineering time.
Thesis: Centralizing connection profiles eliminates manual entry and enforces security protocols
FileZilla's Site Manager acts as a configuration database for your remote servers. Instead of relying on the Quickconnect bar, which is intended for one-off sessions, the Site Manager allows you to define the specific encryption and authentication requirements for each environment, ensuring you connect using the most secure method the server supports.
Configuring Protocol-Specific Profiles
To access the manager, navigate to File → Site Manager. Each single entry allows you to toggle between three primary protocols, each with different handshake behaviors.
FTPS (FTP over TLS)
FTPS adds a layer of TLS (Transport Layer Security) encryption to the traditional FTP protocol. For most modern servers, you should use Require explicit FTP over TLS. In this mode, the client connects to the standard port 21 and then explicitly requests a secure connection before sending credentials.
SFTP (SSH File Transfer Protocol)
Unlike FTPS, SFTP is a completely different protocol based on SSH. It uses a single encrypted channel for both commands and data, typically over port 22. This makes it significantly more firewall-friendly than FTPS, which requires a range of passive ports for data transfer.
Worked Example: Setting up Key-Based SFTP Authentication
Key-based authentication is the industry standard for secure server access, replacing vulnerable passwords with a public/private key pair. Here is how to configure it in FileZilla (assuming version 3.60+):
- Open Site Manager and click New Site.
- Set Protocol to
SFTP - SSH File Transfer Protocol. - Enter the Host (e.g.,
sftp.production-server.com) and Port22. - Change Logon Type to
Key file. - Click Browse and select your private key file (OpenSSH format or .ppk).
- If the key is encrypted with a passphrase, enter it in the Password field.
- Click Connect.
Verification: Check the status log at the top of the interface. A successful connection will explicitly state Status: Authentication succeeded. If the log shows Disconnected from server immediately after the key exchange, verify that the public key has been added to the server's authorized_keys file.
Managing and Exporting Configurations
All Site Manager entries are stored in an XML file (typically sitemanager.xml). This allows you to migrate your entire server list to a new workstation without manual reconfiguration.
- Export: Go to
File → Export...and check the Export Site Manager entries box. - Import: Use
File → Import...to load a previously exported XML file.
Security Trade-offs and Limitations
While the Site Manager is convenient, it introduces a specific security risk: plain-text storage. By default, FileZilla stores saved passwords in the XML configuration file without encryption. If an attacker gains access to your local file system, they can read your server passwords directly from the XML.
To mitigate this, you must enable a Master Password via Edit → Settings → Interface. This encrypts the stored credentials using a single password you provide at startup.
Actionable Closing
Audit your current connections. If you are using the Quickconnect bar for recurring tasks, migrate those entries to the Site Manager. Prioritize SFTP over FTPS for better firewall compatibility, and immediately enable the Master Password feature to ensure your sitemanager.xml file does not become a plaintext roadmap for unauthorized server access.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.