<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.2clever.uk/index.php?action=history&amp;feed=atom&amp;title=SMEServer_FTP</id>
	<title>SMEServer FTP - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.2clever.uk/index.php?action=history&amp;feed=atom&amp;title=SMEServer_FTP"/>
	<link rel="alternate" type="text/html" href="https://wiki.2clever.uk/index.php?title=SMEServer_FTP&amp;action=history"/>
	<updated>2026-05-01T09:37:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://wiki.2clever.uk/index.php?title=SMEServer_FTP&amp;diff=98&amp;oldid=prev</id>
		<title>Rdswikiadmin at 17:16, 14 January 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.2clever.uk/index.php?title=SMEServer_FTP&amp;diff=98&amp;oldid=prev"/>
		<updated>2026-01-14T17:16:34Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:16, 14 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Copied from; https://wiki.koozali.org/Ftp&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Copied from; https://wiki.koozali.org/Ftp &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;(This page was last modified on 26 September 2025, at 18:18.)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In short SME uses port 21 for FTP. Default mode used is passive. To use it you will need a custom template and enabling ports (PassivePort  https://bugs.koozali.org/show_bug.cgi?id=12454).  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;In short SME uses port 21 for FTP. Default mode used is passive. To use it you will need a custom template and enabling ports (PassivePort  https://bugs.koozali.org/show_bug.cgi?id=12454).  &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rdswikiadmin</name></author>
	</entry>
	<entry>
		<id>https://wiki.2clever.uk/index.php?title=SMEServer_FTP&amp;diff=91&amp;oldid=prev</id>
		<title>Rdswikiadmin: Created page with &quot;Copied from; https://wiki.koozali.org/Ftp  In short SME uses port 21 for FTP. Default mode used is passive. To use it you will need a custom template and enabling ports (PassivePort  https://bugs.koozali.org/show_bug.cgi?id=12454).   Starting SME10, ftp default  is to use explicit TLS over ftp (FTPs explicite) &#039;&#039;&#039;Easy filezilla connexion to SME would use url with FTPES://.&#039;&#039;&#039; {| class=&quot;wikitable&quot; |+disambiguation !term / protocol !port !deamon !explanation |- |ftp ftp://...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.2clever.uk/index.php?title=SMEServer_FTP&amp;diff=91&amp;oldid=prev"/>
		<updated>2026-01-13T11:17:14Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Copied from; https://wiki.koozali.org/Ftp  In short SME uses port 21 for FTP. Default mode used is passive. To use it you will need a custom template and enabling ports (PassivePort  https://bugs.koozali.org/show_bug.cgi?id=12454).   Starting SME10, ftp default  is to use explicit TLS over ftp (FTPs explicite) &amp;#039;&amp;#039;&amp;#039;Easy filezilla connexion to SME would use url with FTPES://.&amp;#039;&amp;#039;&amp;#039; {| class=&amp;quot;wikitable&amp;quot; |+disambiguation !term / protocol !port !deamon !explanation |- |ftp ftp://...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Copied from; https://wiki.koozali.org/Ftp&lt;br /&gt;
&lt;br /&gt;
In short SME uses port 21 for FTP. Default mode used is passive. To use it you will need a custom template and enabling ports (PassivePort  https://bugs.koozali.org/show_bug.cgi?id=12454). &lt;br /&gt;
&lt;br /&gt;
Starting SME10, ftp default  is to use explicit TLS over ftp (FTPs explicite) &amp;#039;&amp;#039;&amp;#039;Easy filezilla connexion to SME would use url with FTPES://.&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+disambiguation&lt;br /&gt;
!term / protocol&lt;br /&gt;
!port&lt;br /&gt;
!deamon&lt;br /&gt;
!explanation&lt;br /&gt;
|-&lt;br /&gt;
|ftp ftp://&lt;br /&gt;
|21&lt;br /&gt;
|proftpd&lt;br /&gt;
|unencrypted file transfer protocol, all is clear text, no encryption. disabled on SME&amp;gt;=10&lt;br /&gt;
|-&lt;br /&gt;
|ftps ftpes://&lt;br /&gt;
|21&lt;br /&gt;
|proftpd&lt;br /&gt;
|explicit TLS encrypted file transfer protocol, password exchange and files are encrypted&lt;br /&gt;
|-&lt;br /&gt;
|ftps ftps://&lt;br /&gt;
|900&lt;br /&gt;
|proftpd&lt;br /&gt;
|implicit TLS, not available on SME&lt;br /&gt;
|-&lt;br /&gt;
|sftp&lt;br /&gt;
|22&lt;br /&gt;
|sshd&lt;br /&gt;
|secured file transfer protocol over ssh. this needs a RSA or EC key  on SME Server&lt;br /&gt;
|}&lt;br /&gt;
SME Server offers a ftp server, which is Proftpd. If enabled it  allows you to access to the Primary ibay files folder with anonymous access, and to any content your user is allowed, if authenticated, inside /home/e-smith/files.&lt;br /&gt;
&lt;br /&gt;
Prior to SME 10 ftp was using cleat text communication (&amp;#039;&amp;#039;&amp;#039;FTP&amp;#039;&amp;#039;&amp;#039;), allowing one to listen to your password and files exchanged on the network. Now TLS is enforced by default (&amp;#039;&amp;#039;&amp;#039;FTPs&amp;#039;&amp;#039;&amp;#039;), and it is suggested that you keep it enabled.&lt;br /&gt;
&lt;br /&gt;
While you may be used to the traditional port 21 for file transfer protocol (&amp;#039;&amp;#039;&amp;#039;FTP&amp;#039;&amp;#039;&amp;#039;), this page is here to help you have steady access to your ftp server, by understanding it, and enabling the extra needed ports.&lt;br /&gt;
&lt;br /&gt;
Your server is using &lt;br /&gt;
&lt;br /&gt;
Do not confuse &amp;#039;&amp;#039;&amp;#039;sFTP&amp;#039;&amp;#039;&amp;#039;, which is part of ssh protocol and uses port 22, with &amp;#039;&amp;#039;&amp;#039;FTPs&amp;#039;&amp;#039;&amp;#039; which is the regular ftp protocol over port 21 using a layer of SSL/TLS encryption.&lt;br /&gt;
&lt;br /&gt;
== FTP connection modes : active versus passive ==&lt;br /&gt;
SME by default offers both active and passive mode when you are on LAN. However, as soon as you try to access from a  remote location you will have some difficulties depending on the situation.&lt;br /&gt;
&lt;br /&gt;
By default, for passive connection,  Proftpd will use ports from 1024 and up, which means that you must forward &amp;#039;&amp;#039;all&amp;#039;&amp;#039; ports 1024-65535 from the NAT to the FTP server!  And you have to allow many (possibly) dangerous ports in your fire-walling rules!  Not a good situation.&lt;br /&gt;
&lt;br /&gt;
==== The Modes ====&lt;br /&gt;
&lt;br /&gt;
===== active =====&lt;br /&gt;
From the server-side firewall&amp;#039;s standpoint, to support active mode FTP the following communication channels need to be opened (http://slacksite.com/other/ftp.html):&lt;br /&gt;
&lt;br /&gt;
* FTP server&amp;#039;s port 21 from anywhere (Client initiates connection)&lt;br /&gt;
* FTP server&amp;#039;s port 21 to ports &amp;gt; 1024 (Server responds to client&amp;#039;s control port)&lt;br /&gt;
* FTP server&amp;#039;s port 20 to ports &amp;gt; 1024 (Server initiates data connection to client&amp;#039;s data port)&lt;br /&gt;
* FTP server&amp;#039;s port 20 from ports &amp;gt; 1024 (Client sends ACKs to server&amp;#039;s data port)&lt;br /&gt;
&lt;br /&gt;
===== passive =====&lt;br /&gt;
From the server-side firewall&amp;#039;s standpoint, to support passive mode FTP the following communication channels need to be opened (http://slacksite.com/other/ftp.html):&lt;br /&gt;
&lt;br /&gt;
* FTP server&amp;#039;s port 21 from anywhere (Client initiates connection)&lt;br /&gt;
* FTP server&amp;#039;s port 21 to ports &amp;gt; 1024 (Server responds to client&amp;#039;s control port)&lt;br /&gt;
* FTP server&amp;#039;s ports &amp;gt; 1024 from anywhere (Client initiates data connection to random port specified by server)&lt;br /&gt;
* FTP server&amp;#039;s ports &amp;gt; 1024 to remote ports &amp;gt; 1024 (Server sends ACKs (and data) to client&amp;#039;s data port)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
note port 20 does not need to be open inward on SME, as it is only used to send from SME, however if you have a restrictive firewall between Internet and SME limiting outgoing connection you need to open port 20 to be able to do active ftp. http://www.proftpd.org/docs/howto/AWS.html&lt;br /&gt;
&lt;br /&gt;
==== Examples ====&lt;br /&gt;
&lt;br /&gt;
===== SME is server-gateway connected to Internet - Client is remote behind a NAT =====&lt;br /&gt;
Active mode will not work because the NAT will mostly hide the client port.&lt;br /&gt;
&lt;br /&gt;
Passive mode will need to use the &amp;lt;code&amp;gt;PassivePorts&amp;lt;/code&amp;gt; directive in your &amp;lt;code&amp;gt;proftpd.conf&amp;lt;/code&amp;gt; to control what ports &amp;lt;code&amp;gt;proftpd&amp;lt;/code&amp;gt; will use for its passive data transfers, and you will need to open those port in your SME firewall.&lt;br /&gt;
&lt;br /&gt;
===== SME is server-gateway behind a firewall / NAT  to Internet - Client is remote behind a NAT =====&lt;br /&gt;
Active mode will not work because the NAT will mostly hide the client port.&lt;br /&gt;
&lt;br /&gt;
Passive mode will need to use the &amp;lt;code&amp;gt;PassivePorts&amp;lt;/code&amp;gt; directive in your &amp;lt;code&amp;gt;proftpd.conf&amp;lt;/code&amp;gt; to control what ports &amp;lt;code&amp;gt;proftpd&amp;lt;/code&amp;gt; will use for its passive data transfers, and you will need to open those port in your SME firewall and in your firewall between you SME and Internet. You might also need a template custom to add MasqueradeAddress (http://www.proftpd.org/docs/modules/mod_core.html#MasqueradeAddress).&lt;br /&gt;
&lt;br /&gt;
===== SME is server-gateway connected to Internet - Client is remote directly connected to the Internet =====&lt;br /&gt;
Active mode will work.&lt;br /&gt;
&lt;br /&gt;
Passive mode will need to use the &amp;lt;code&amp;gt;PassivePorts&amp;lt;/code&amp;gt; directive in your &amp;lt;code&amp;gt;proftpd.conf&amp;lt;/code&amp;gt; to control what ports &amp;lt;code&amp;gt;proftpd&amp;lt;/code&amp;gt; will use for its passive data transfers, and you will need to open those port in your SME firewall.&lt;br /&gt;
&lt;br /&gt;
== SSL mode: Explicit SSL versus Implicit SSL ==&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;SME 10 and above uses explicit SSL mode for FTPs&amp;#039;&amp;#039;&amp;#039; over port 21 only and does not need port 990. &amp;lt;u&amp;gt;The client must explicitly request for SSL/TLS to be able to go on&amp;lt;/u&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
FTPS (FTP over TLS) is served up in two incompatible modes. If using explicit FTPS, the client connects to the normal FTP port and explicitly switches into secure (TLS) mode with &amp;quot;AUTH TLS&amp;quot;, whereas implicit FTPS is an older style service that assumes TLS mode right from the start of the connection (and normally listens on TCP port 990, rather than 21). &lt;br /&gt;
&lt;br /&gt;
In a FileZilla client this means prefixing the host with &amp;quot;FTPES://&amp;quot; to connect an  &amp;quot;explicit&amp;quot; FTPS server, or &amp;quot;FTPS://&amp;quot; for the legacy &amp;quot;implicit&amp;quot; server (for which you will likely also need to set the port to 990).&lt;br /&gt;
&lt;br /&gt;
== Filezilla config ==&lt;br /&gt;
[[File:Filezilla-ftpes.png|left|thumb]]&lt;br /&gt;
If you use a client such a filezilla, starting SME 10, you will need to select the options&lt;br /&gt;
&lt;br /&gt;
* encryption: TLS/SSL explicit encription &lt;br /&gt;
* port: 21&lt;br /&gt;
* hostname : you ip or domain name&lt;br /&gt;
* user name: your user name &lt;br /&gt;
* password : your password user&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
== SME enabling from smanager ==&lt;br /&gt;
[[File:Smanager2-ftp.png|none|thumb|898x898px]]&lt;br /&gt;
&lt;br /&gt;
== FTP configuration options in SME ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+configuration db&lt;br /&gt;
!key&lt;br /&gt;
!Property&lt;br /&gt;
!default&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;10&amp;quot; |ftp&lt;br /&gt;
|access&lt;br /&gt;
|private&lt;br /&gt;
|-&lt;br /&gt;
|TcpPorts&lt;br /&gt;
|49200:49999&lt;br /&gt;
|-&lt;br /&gt;
|TCPPort&lt;br /&gt;
|21&lt;br /&gt;
|-&lt;br /&gt;
|ChrootDir&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|TLSEnable&lt;br /&gt;
|on&lt;br /&gt;
|-&lt;br /&gt;
|TLSRequired&lt;br /&gt;
|on&lt;br /&gt;
|-&lt;br /&gt;
|TLSVerifyClient&lt;br /&gt;
|off&lt;br /&gt;
|-&lt;br /&gt;
|LoginAccess&lt;br /&gt;
|private&lt;br /&gt;
|-&lt;br /&gt;
|DisableAnonymous&lt;br /&gt;
|yes&lt;br /&gt;
|-&lt;br /&gt;
|status&lt;br /&gt;
|disabled&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+account db for ibay type&lt;br /&gt;
!Property&lt;br /&gt;
!default&lt;br /&gt;
|-&lt;br /&gt;
|PublicAccess&lt;br /&gt;
|none&lt;br /&gt;
|-&lt;br /&gt;
|DisableAnonymous&lt;br /&gt;
|no&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TODO ==&lt;br /&gt;
&lt;br /&gt;
*http://www.proftpd.org/docs/modules/mod_core.html#MasqueradeAddress Virtualhost vs Class see http://www.proftpd.org/docs/howto/NAT.html&lt;br /&gt;
* http://www.proftpd.org/docs/howto/FXP.html&lt;br /&gt;
&lt;br /&gt;
===Bug report===&lt;br /&gt;
Proftpd is listed in the [https://bugs.koozali.org/enter_bug.cgi?product=SME%20Server%2010.X bugtracker server] section.&lt;br /&gt;
&lt;br /&gt;
Please report all bugs, new feature requests and documentation issues there.&lt;br /&gt;
&lt;br /&gt;
Current bugs:&lt;br /&gt;
&lt;br /&gt;
https://bugs.koozali.org/buglist.cgi?bug_status=UNCONFIRMED&amp;amp;bug_status=CONFIRMED&amp;amp;bug_status=NEEDINFO&amp;amp;bug_status=IN_PROGRESS&amp;amp;bug_status=RESOLVED&amp;amp;f1=cf_package&amp;amp;list_id=102854&amp;amp;o1=equals&amp;amp;query_format=advanced&amp;amp;resolution=---&amp;amp;v1=e-smith-proftpd&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Sources ==&lt;br /&gt;
&lt;br /&gt;
* https://wiki.filezilla-project.org/FTP_over_TLS#Explicit_vs_Implicit_FTPS&lt;br /&gt;
* http://www.proftpd.org/docs/howto/TLS.html&lt;br /&gt;
* https://hstechdocs.helpsystems.com/manuals/globalscape/archive/secureserver3/Explicit_versus_Implicit_SSL.htm&lt;br /&gt;
* https://winscp.net/eng/docs/ftp_modes&lt;br /&gt;
* http://www.proftpd.org/docs/howto/NAT.html&lt;br /&gt;
* http://slacksite.com/other/ftp.html&lt;br /&gt;
&lt;br /&gt;
[[Category:Howto]]&lt;/div&gt;</summary>
		<author><name>Rdswikiadmin</name></author>
	</entry>
</feed>