{"id":13229,"date":"2025-12-16T11:10:09","date_gmt":"2025-12-16T05:40:09","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=13229"},"modified":"2026-09-07T11:11:40","modified_gmt":"2026-09-07T05:41:40","slug":"use-ftp-on-linux","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/use-ftp-on-linux\/","title":{"rendered":"How to Use FTP on Linux Server 2026? &#8211; (Step by Step Expert Guide)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>To use FTP on a Linux server:<\/strong> install an FTP service (vsftpd), <strong>open ports 21<\/strong> and a passive range, create users and set permissions, enable TLS (FTPS) or prefer SFTP, then connect via a client <strong>(FileZilla)<\/strong> or CLI (ftp\/lftp). Test, automate, and harden for production.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re wondering how to use FTP on Linux server environments, this guide walks you through setup, secure configuration, and daily operations. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll cover <a href=\"https:\/\/www.youstable.com\/blog\/install-ftp-on-linux\/\">installing a production ready FTP<\/a> service, opening firewalls, enabling FTPS, creating users, connecting from clients, and troubleshooting using practical, <strong>step by step commands you can copy &amp; run<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-is-ftp-and-when-should-you-use-it\"><strong>What is FTP and When Should You Use it?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FTP <strong>(File Transfer Protocol)<\/strong> is a legacy protocol for transferring files between a client and server. It\u2019s simple and widely supported, but it\u2019s unencrypted by default. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For internet-facing workloads, use encrypted options like FTPS <strong>(FTP over TLS)<\/strong> or SFTP (over SSH). For private networks or legacy systems, FTP may still be appropriate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ftp-vs-ftps-vs-sftp\"><strong>FTP vs FTPS vs SFTP<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>FTP:<\/strong> Plain text credentials and data. Use only on trusted networks.<\/li>\n\n\n\n<li><strong>FTPS:<\/strong> FTP with TLS encryption. Works with traditional FTP clients; requires certificates.<\/li>\n\n\n\n<li><strong>SFTP:<\/strong> Runs over SSH (port 22), simpler through firewalls, strong security by default.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Modern best practice:<\/strong> prefer SFTP or FTPS. Only use plain FTP if you must\u2014and never expose it to the public internet without compensating controls.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"prerequisites\"><strong>Prerequisites<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-you-need\"><strong>What You Need<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A Linux server (Ubuntu\/Debian, AlmaLinux\/Rocky\/CentOS, or similar).<\/li>\n\n\n\n<li>Root or sudo access <a href=\"https:\/\/www.youstable.com\/blog\/how-to-connect-to-server-via-ssh\/\">via SSH<\/a>.<\/li>\n\n\n\n<li>Firewall access to open required ports.<\/li>\n\n\n\n<li>Domain or public IP (especially when behind NAT).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"choosing-your-ftp-server\"><strong>Choosing Your FTP Server<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>vsftpd:<\/strong> Very secure and fast. Great defaults for production.<\/li>\n\n\n\n<li><strong>ProFTPD:<\/strong> Highly configurable, Apache-like syntax.<\/li>\n\n\n\n<li><strong>Pure-FTPd:<\/strong> Lightweight, easy virtual users, good performance.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This tutorial uses vsftpd because it\u2019s widely available, efficient, and secure by design.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"install-an-ftp-server-on-linux\"><strong>Install an FTP Server on Linux<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ubuntu-debian\"><strong>Ubuntu\/Debian<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update\nsudo apt install -y vsftpd\nsudo systemctl enable --now vsftpd\nsudo systemctl status vsftpd<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"almalinux-rocky-centos-rhel\"><strong>AlmaLinux\/Rocky\/CentOS\/RHEL<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo dnf install -y vsftpd\nsudo systemctl enable --now vsftpd\nsudo systemctl status vsftpd<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"open-firewall-ports\"><strong>Open Firewall Ports<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FTP uses port 21 for control and a range of ports for passive data connections. Open both to allow transfers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ufw-ubuntu\"><strong>UFW (Ubuntu)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Allow control channel\nsudo ufw allow 21\/tcp\n# Allow a passive port range you will configure (e.g., 30000-31000)\nsudo ufw allow 30000:31000\/tcp\nsudo ufw reload\nsudo ufw status<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"firewalld-rhel-family\"><strong>firewalld (RHEL family)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo firewall-cmd --permanent --add-service=ftp\nsudo firewall-cmd --permanent --add-port=30000-31000\/tcp\nsudo firewall-cmd --reload\nsudo firewall-cmd --list-all<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"if-selinux-is-enforcing\"><strong>If SELinux Is Enforcing<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Allow vsftpd to read\/write where appropriate (use sparingly)\nsudo setsebool -P ftpd_full_access on\n# Or enable passive mode usage\nsudo setsebool -P ftpd_use_passive_mode on\n\n# Label your FTP directory properly (example: \/srv\/ftp)\nsudo semanage fcontext -a -t public_content_t \"\/srv\/ftp(\/.*)?\"\nsudo restorecon -Rv \/srv\/ftp<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Prefer least privilege:<\/strong> enable only the booleans you need and label directories correctly instead of granting broad access.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"secure-vsftpd-configuration-ftps\"><strong>Secure vsftpd Configuration (FTPS)<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"backup-and-edit-the-config\"><strong>Backup and Edit the Config<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo cp \/etc\/vsftpd.conf \/etc\/vsftpd.conf.bak\nsudo nano \/etc\/vsftpd.conf<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Use the following sensible baseline. Adjust passive ports to match your firewall rules and set your public IP or hostname if you\u2019re behind NAT.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>listen=YES\nanonymous_enable=NO\nlocal_enable=YES\nwrite_enable=YES\n\n# Restrict users to their home\nchroot_local_user=YES\nallow_writeable_chroot=YES\n\n# Passive mode\npasv_enable=YES\npasv_min_port=30000\npasv_max_port=31000\n# If behind NAT, set your public IP or DNS name\n# pasv_address=203.0.113.10\n\n# Logging\nxferlog_enable=YES\nxferlog_std_format=YES\n\n# TLS\/FTPS\nssl_enable=YES\nrsa_cert_file=\/etc\/ssl\/private\/vsftpd.pem\nrsa_private_key_file=\/etc\/ssl\/private\/vsftpd.pem\nrequire_ssl_reuse=NO\nssl_ciphers=HIGH\n\n# Optional: allow only TLS and disable SSLv3 older protocols\nssl_tlsv1=YES\nssl_tlsv1_1=YES\nssl_tlsv1_2=YES\nssl_sslv2=NO\nssl_sslv3=NO<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-a-tls-certificate\"><strong>Create a TLS Certificate<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo mkdir -p \/etc\/ssl\/private\nsudo openssl req -x509 -nodes -days 365 \n  -newkey rsa:2048 \n  -keyout \/etc\/ssl\/private\/vsftpd.pem \n  -out \/etc\/ssl\/private\/vsftpd.pem\nsudo chmod 600 \/etc\/ssl\/private\/vsftpd.pem<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"restart-vsftpd\"><strong>Restart vsftpd<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl restart vsftpd\nsudo systemctl status vsftpd<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">At this point, your server supports FTPS (explicit TLS). Most clients will connect to port 21 and negotiate TLS automatically.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-ftp-users-and-set-permissions\"><strong>Create FTP Users and Set Permissions<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"create-a-user-and-directory\"><strong>Create a User and Directory<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Example: user 'webuser' with home directory \/srv\/ftp\/web\nsudo useradd -m -d \/srv\/ftp\/web -s \/usr\/sbin\/nologin webuser\nsudo passwd webuser\n\n# Ensure ownership and secure permissions\nsudo chown -R webuser:webuser \/srv\/ftp\/web\nsudo chmod -R 755 \/srv\/ftp\/web<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For uploads, give write access to specific subfolders (e.g., \/srv\/ftp\/web\/uploads) instead of the root of the chroot to maintain security.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"optional-virtual-users\"><strong>Optional: Virtual Users<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">vsftpd supports virtual users mapped to a system account for large multi-user environments. It offers isolation without creating many shell users. For most small teams, standard local users with chroot is sufficient.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"connect-to-the-server-cli-and-gui\"><strong>Connect to the Server (CLI and GUI)<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"command-line-ftp-and-lftp\"><strong>Command Line (ftp and lftp)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Plain FTP (not encrypted) - only use on trusted networks\nftp -inv your-server.tld 21\n# inside ftp:\n# user &lt;username&gt; &lt;password&gt;\n# ls\n# put localfile\n# get remotefile\n# bye\n\n# Recommended: lftp (supports FTPS and robust mirroring)\nsudo apt install -y lftp  # or: sudo dnf install -y lftp\nlftp -u webuser your-server.tld\n# For explicit FTPS:\nlftp -u webuser -e \"set ftp:ssl-force true; set ssl:verify-certificate no\" your-server.tld<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"sftp-safer-over-ssh\"><strong>SFTP (Safer, Over SSH)<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SFTP doesn\u2019t require vsftpd\u2014if you already have SSH, you have SFTP. It\u2019s simpler through firewalls and fully encrypted.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Connect via SFTP\nsftp webuser@your-server.tld\n# Upload\/download\nput localfile\nget remotefile\n# Recursive\nput -r localdir\nget -r remotedir<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"graphical-clients-filezilla-winscp-cyberduck\"><strong>Graphical Clients (FileZilla, WinSCP, Cyberduck)<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Protocol:<\/strong> choose FTPS (Explicit TLS) or SFTP.<\/li>\n\n\n\n<li><strong>Host:<\/strong> your domain or IP.<\/li>\n\n\n\n<li><strong>Username\/Password:<\/strong> the <a href=\"https:\/\/www.youstable.com\/blog\/create-cpanel-account\/\">account you created<\/a>.<\/li>\n\n\n\n<li><strong>Passive mode:<\/strong> enabled.<\/li>\n\n\n\n<li><strong>Port:<\/strong> 21 for FTPS, 22 for SFTP.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"passive-mode-and-nat-considerations\"><strong>Passive Mode and NAT Considerations<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">FTP opens separate data connections. Passive mode is mandatory behind firewalls\/NAT. Set a narrow passive range in vsftpd, open it in your firewall, and, if behind NAT, set pasv_address to your public IP or DNS. This prevents data channel timeouts.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/vsftpd.conf (excerpt)\npasv_enable=YES\npasv_min_port=30000\npasv_max_port=31000\npasv_address=203.0.113.10  # your public IP or hostname<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"automate-transfers-and-backups\"><strong>Automate Transfers and Backups<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"lftp-mirror-examples\"><strong>lftp Mirror Examples<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Upload a local directory to the server via FTPS\nlftp -u webuser -e \"set ftp:ssl-force true; mirror -R .\/site \/public_html; bye\" your-server.tld\n\n# Download a remote directory\nlftp -u webuser -e \"set ftp:ssl-force true; mirror \/public_html .\/backup; bye\" your-server.tld<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"schedule-with-cron\"><strong>Schedule with Cron<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>crontab -e\n# Nightly sync at 2:30 AM\n30 2 * * * lftp -u webuser -e \"set ftp:ssl-force true; mirror -R .\/site \/public_html; bye\" your-server.tld<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"troubleshooting-ftp-on-linux\"><strong>Troubleshooting FTP on Linux<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"check-services-ports-and-tls\"><strong>Check Services, Ports, and TLS<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># Service health\nsudo systemctl status vsftpd\n\n# Confirm listening ports\nsudo ss -tulpn | grep :21\n\n# Test connectivity from client\nnc -vz your-server.tld 21\nnc -vz your-server.tld 30005\n\n# Test FTPS negotiation\nopenssl s_client -connect your-server.tld:21 -starttls ftp<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"review-logs\"><strong>Review Logs<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tail -f \/var\/log\/vsftpd.log\nsudo journalctl -u vsftpd -f\n# SELinux denials\nsudo ausearch -m avc -ts recent | audit2why\nsudo ausearch -m avc -ts recent | audit2allow -M ftpfix &amp;&amp; sudo semodule -i ftpfix.pp<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"common-errors-and-fixes\"><strong>Common Errors and Fixes<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>530 Login incorrect:<\/strong> wrong credentials or user shell set to nologin without PAM mapping; reset password and verify user exists.<\/li>\n\n\n\n<li><strong>Timeouts listing or transferring:<\/strong> passive ports\/firewall not open; set pasv_min\/max and open the range.<\/li>\n\n\n\n<li><strong>426\/425 errors:<\/strong> NAT not configured; set pasv_address to public IP.<\/li>\n\n\n\n<li><strong>TLS handshake fails:<\/strong> certificate path\/permissions wrong; ensure 600 on PEM and correct path in config.<\/li>\n\n\n\n<li><strong>Chroot write errors:<\/strong> add allow_writeable_chroot=YES and create dedicated writable subfolders.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"best-practices-and-hardening\"><strong>Best Practices and Hardening<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prefer SFTP or FTPS; disable plain FTP on the public internet.<\/li>\n\n\n\n<li>Disable anonymous access; enforce strong <a href=\"https:\/\/www.youstable.com\/blog\/ssh-keys-vs-password-authentication\/\">passwords or SSH keys<\/a>.<\/li>\n\n\n\n<li>Use chroot to isolate users to their home directories.<\/li>\n\n\n\n<li>Limit passive port ranges and restrict firewall rules.<\/li>\n\n\n\n<li>Enable fail2ban to block brute-force attempts.<\/li>\n\n\n\n<li>Keep vsftpd and OS packages updated.<\/li>\n\n\n\n<li>Audit logs regularly and rotate TLS certificates on schedule.<\/li>\n\n\n\n<li>If compliance-bound, restrict ciphers to modern suites and disable outdated TLS versions.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"when-managed-hosting-makes-life-easier\"><strong>When Managed Hosting Makes Life Easier<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019d rather avoid deep server tuning, a managed VPS or cloud server can help. At YouStable, our engineers configure secure SFTP\/FTPS, firewall rules, and monitoring for you, so you can focus on development and content instead of protocols and ports. Ask our team for a hardened setup tailored to your stack.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-default\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs\"><strong>FAQ&#8217;s<\/strong><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1765791979052\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003eis-ftp-or-sftp-better-for-a-linux-serveru003c-strongu003e\">u003cstrongu003eIs FTP or SFTP better for a Linux server?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>SFTP is generally better. It runs over SSH, is encrypted by default, and requires only port 22. FTPS is also secure but needs certificates and multiple ports. Avoid plain FTP on the public internet because credentials and data are unencrypted.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765791986245\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ewhich-ports-do-i-open-for-ftpu003c-strongu003e\">u003cstrongu003eWhich ports do I open for FTP?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Open TCP 21 for the control channel and a passive range for data (for example, 30000\u201331000). Configure the same range in vsftpd.conf and your firewall. For SFTP, only TCP 22 is needed.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765791994211\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ehow-do-i-enable-passive-mode-in-vsftpdu003c-strongu003e\">u003cstrongu003eHow do I enable passive mode in vsftpd?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Set pasv_enable=YES and define pasv_min_port\/pasv_max_port. If the server is behind NAT, set pasv_address to the public IP or DNS. Open the same port range in the firewall to avoid timeouts.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765792001590\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ehow-can-i-restrict-a-user-to-a-specific-directoryu003c-strongu003e\">u003cstrongu003eHow can I restrict a user to a specific directory?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Enable chroot_local_user=YES and allow_writeable_chroot=YES in vsftpd.conf. Create the user with a dedicated home (e.g., \/srv\/ftp\/user) and set ownership to that user. Provide write access only to necessary subfolders.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765792007965\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ewhats-the-easiest-way-to-transfer-entire-foldersu003c-strongu003e\">u003cstrongu003eWhat\u2019s the easiest way to transfer entire folders?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Use lftp\u2019s mirror command for FTPS or the sftp -r flag for SFTP. Example: lftp -u user -e u0022set ftp:ssl-force true; mirror -R .\/site \/public_html; byeu0022 host.tld or sftp user@host.tld then put -r .\/folder.u003cbru003eu003cbru003eWith the steps above, you now know how to use FTP on Linux server instances securely and efficiently\u2014from installation to automation. For production deployments where uptime and security matter, consider managed hosting from YouStable to get expert-built FTP\/SFTP that just works.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>To use FTP on a Linux server: install an FTP service (vsftpd), open ports 21 and a passive range, create [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":13791,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":82,"footnotes":""},"categories":[350,2259],"tags":[],"class_list":["post-13229","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-knowledgebase","category-kb-linux"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=13229"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13229\/revisions"}],"predecessor-version":[{"id":23238,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13229\/revisions\/23238"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/13791"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=13229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=13229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=13229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}