Skip to main content

SFTP and vsftpd: Secure File Transfer to a VDS

VDS / VPS Servers · 29.09.2026

How SFTP differs from plain FTP and vsftpd

SFTP (SSH File Transfer Protocol) transfers files over a regular SSH connection on port 22. You do not need a separate server for it: if SSH is already working, see the article on first SSH connection to a VDS, SFTP is already available. All traffic, including the login and password, is encrypted automatically.

vsftpd is a separate classic FTP server that by default sends data and passwords in plain text. To get encryption, vsftpd must be explicitly configured for FTPS (FTP over TLS), which is a different protocol with its own ports and passive-mode quirks. Without ties to old FTP clients, it is simpler and safer to use SFTP for new projects from the start.

SFTP over SSH: a user without shell access

You do not need to give a user full command-line access just to transfer files. Create a separate user with a shell restricted to SFTP only:

useradd -m -s /usr/sbin/nologin sftpuser
passwd sftpuser

The nologin shell blocks a regular SSH login, but it does not interfere with the SFTP subsystem, because it is handled separately from the command shell at the sshd configuration level.

Restricting the user to their own folder (chroot)

To prevent the user from leaving their directory and seeing the rest of the filesystem, set up chroot in /etc/ssh/sshd_config:

Match User sftpuser
    ChrootDirectory /home/sftpuser
    ForceCommand internal-sftp
    AllowTcpForwarding no
    X11Forwarding no

For chroot to work, the /home/sftpuser directory and all its parent folders must be owned by root and must not be writable by group or others:

chown root:root /home/sftpuser
chmod 755 /home/sftpuser
mkdir /home/sftpuser/upload
chown sftpuser:sftpuser /home/sftpuser/upload

After editing the configuration, check the syntax and restart SSH:

sshd -t
systemctl restart sshd

For more on hardening sshd itself, see the article on SSH Hardening.

Installing and configuring vsftpd with TLS

If you still need classic FTP, say for a legacy client, install vsftpd and enable encryption right away:

apt install vsftpd -y

In /etc/vsftpd.conf, enable TLS and disable anonymous access:

anonymous_enable=NO
ssl_enable=YES
rsa_cert_file=/etc/ssl/certs/vsftpd.pem
rsa_private_key_file=/etc/ssl/private/vsftpd.key
force_local_data_ssl=YES
force_local_logins_ssl=YES

Without the last two parameters, the server still allows unencrypted connections, which defeats the whole point of the certificate.

Firewall and FTP passive mode

FTP uses two connections: a control connection on port 21 and a separate one for data transfer. In passive mode, the data port is picked from a range that must be explicitly opened in the firewall. Set the range in the config:

pasv_min_port=40000
pasv_max_port=40100

And open ports 21 and 40000-40100 — configuring firewall rules on a VDS is described in the article on setting up UFW. For SFTP you do not need to open separate ports — it uses the same port 22 as SSH.

What to choose: SFTP or vsftpd

Final checklist:

  • For a new project with no ties to old FTP clients, use SFTP: fewer ports, built-in encryption, one service instead of two.
  • Always set up chroot for SFTP users to restrict access to their own folder.
  • If you specifically need vsftpd, be sure to enable ssl_enable and disable anonymous login.
  • For vsftpd, open port 21 and the passive port range in the firewall; for SFTP, port 22 is enough.
  • Periodically review the list of users with SFTP/FTP access and remove the ones no longer needed.
← Back to Knowledge Base Ask Support