Theme
Connect with an FTPS client
FTPS is FTP wrapped in TLS. Use it if you were told to, or if your existing tooling speaks it.
If you have a free choice, prefer SFTP. It is simpler, it uses one connection instead of two, and it copes better with firewalls.
FTPS or FTPES
Two ways to do the same thing. Your client will offer both, under confusing names.
| FTPS, implicit | FTPES, explicit | |
|---|---|---|
| Port | 990 | 21 |
| How TLS starts | Immediately, before anything is sent | The connection starts in the clear and is upgraded with a command before your password is sent |
| Client calls it | Implicit FTP over TLS, FTPS | Explicit FTP over TLS, FTPES, FTP with TLS |
Both are encrypted end to end. Pick whichever your administrator enabled; if both, either is fine.
Never plain FTP
Plain, unencrypted FTP is not offered on any plan. If a client connects on port 21 and does not upgrade to TLS, it is refused.
If a tool only speaks plain FTP, it cannot be used here, and that is deliberate.
The settings
| Field | Value |
|---|---|
| Protocol | FTP, with Require explicit TLS or Require implicit TLS |
| Host | The address you were given for SFTP and FTPS, usually ending .on.sftp.cloud |
| Port | 990 for implicit, 21 for explicit |
| Encryption | Required. Never "if available" |
| Username | Your full username, including everything after the @ |
| Password | Yours |
| Transfer mode | Passive |
A branded web address will not work here
A custom domain such as files.company.com serves the browser only. FTPS connects to the address your administrator gave you for it.
FileZilla
- File, then Site Manager, then New site.
- Protocol: FTP - File Transfer Protocol.
- Encryption: Require explicit FTP over TLS (port 21), or Require implicit FTP over TLS (port 990).
- Host and Port to match.
- Logon Type: Normal. User: your full username. Password: yours.
- Under Transfer Settings, choose Passive.
- Connect.
WinSCP
- New Session.
- File protocol: FTP.
- Encryption: TLS/SSL Explicit encryption (port 21) or TLS/SSL Implicit encryption (port 990).
- Host name, Port number, User name, Password.
- Login.
Passive mode
Use passive mode. FTP opens a second connection for the data itself, and passive mode lets the client open it outward, which works through firewalls and network address translation. Active mode asks the server to connect back to you and usually fails.
Every client defaults to passive. Only change it if you were told to.
The greeting and the messages
Your organization can set the text you see when you connect, when you sign in, and when you disconnect. If it says something specific to your company, that is why.
A refused sign in never says which part was wrong. Ask your administrator.
The certificate
Your client may show the server's TLS certificate on first connection. It is a normal public certificate issued for the address you are connecting to, and there is nothing special to accept.
If your client warns that the certificate does not match the name you typed, you are connecting to the wrong address. Check it.
Second factors do not apply here
FTPS has no way to ask you for a code, so an authenticator app or a passkey does not protect this connection. Your password does.
If you want strong sign in and your tooling allows it, switch to SFTP with a key.