Why FTP Management Matters for Your Hosting Business
FTP (File Transfer Protocol) has been the standard way to upload website files for 50+ years. Despite newer alternatives (Git, CI/CD), 95% of clients still use FTP/SFTP to manage their website files, upload themes, and manage plugins.
But FTP has a dark side: traditional FTP sends credentials in plain text. Anyone intercepting network traffic can steal usernames and passwords. This is why proper WHM FTP management isn't optional — it's essential.
Proper FTP management in WHM means:
- SFTP by default — Secure File Transfer over SSH, encrypted end-to-end
- FTPS support — FTP over SSL/TLS for legacy FTP clients
- Disabling plain FTP — When possible, force SFTP/FTPS only
- Quota limits — Prevent any FTP user from filling disk
- Access controls — Restrict FTP to specific directories, IPs, times
- Anonymous FTP off — Never allow public file access
For hosting resellers, secure FTP is table stakes. Clients trust you with their website files — protecting them is basic responsibility.
⚠️ The FTP Security Problem
Plain FTP transmits credentials and files unencrypted. Here's what this means:
Scenario 1: Client connects to FTP at a café using public WiFi. Attacker on same network captures the login. Client's hosting account is compromised.
Scenario 2: Client's ISP logs FTP sessions. Their password is in plain text in ISP logs. Anyone with access sees it.
Scenario 3: Attacker on client's network modifies files in transit (FTP has no integrity check). Malware is injected into client's website.
The fix: Always use SFTP (over SSH) or FTPS (over SSL). Both encrypt credentials and files. Configure in WHM to require secure protocols. Never allow plain FTP unless absolutely necessary.
WHM FTP Setup — 9 Steps to Secure File Transfer
Complete step-by-step FTP management. From server config to client access.
Choose FTP Server
WHM → Service Configuration → FTP Server Selection. Choose: Pure-FTPd (recommended — lightweight, fast, secure) or ProFTPd (feature-rich, historical favorite). Pure-FTPd is default. Both support FTPS. Rebuild after selection. Takes 2-5 minutes.
Enable FTPS (FTP over SSL)
WHM → Service Configuration → FTP Server Configuration. Enable "Allow FTP over SSL/TLS" (explicit FTPS). Set SSL certificate (use AutoSSL certificate). This encrypts FTP sessions. Requires clients to use FTPS mode in their FTP client (FileZilla, WinSCP, Cyberduck all support it).
Enable SFTP via SSH
SFTP works via SSH — no separate config. WHM → Tweak Settings → SSH → enable "Allow cPanel users to access shell via SSH." Clients connect via SSH port 22 with SFTP protocol. Most secure option — full encryption + SSH key auth support. Recommended primary method.
Disable Anonymous FTP
WHM → Service Configuration → FTP Server Configuration → Anonymous FTP = Disabled. Anonymous FTP allows anyone to access files without credentials. Security risk, potential abuse (file distribution). Only enable for specific public download servers (rare). Disable by default on all hosting servers.
Set Server-Wide Limits
WHM → Tweak Settings → FTP. Set "Maximum FTP Connections per IP" = 8, "Maximum FTP Connections" = 200. Prevents connection flooding. Set "Anonymous FTP Max Connections" = 0. Configure FTP session timeout (300s). These prevent abuse and resource exhaustion.
Configure FTP Port Range
For passive FTP (required for many clients behind firewalls): WHM → FTP Server Configuration → set passive port range (e.g., 30000-30100). Open these ports in CSF firewall. Without this, clients behind NAT/firewall can't connect. Common issue resellers overlook.
Set up Per-Account Quotas
Clients create FTP accounts in cPanel → FTP Accounts. Each FTP account has its own quota (disk limit) — critical to prevent abuse. Recommend: 100-1000 MB per FTP account. Prevents one FTP user from filling disk with backups/uploaded files. Client manages in cPanel.
Enable Brute Force Protection
WHM → Security Center → cPHulk → enable FTP brute force protection. Set threshold: 5 failed logins = 1-hour ban, 30 failures = 24-hour ban. Also add fail2ban filter for FTP. Together, these block 99% of automated FTP attacks. Complements firewall protection.
Test & Document
Test FTP, FTPS, and SFTP from your own machine. Use FileZilla (best client) — verify all three modes. Write a client-facing doc: "How to connect to FTP for your hosting." Include FTP host, port (21 for FTP/FTPS, 22 for SFTP), and client software suggestions. Reduces support tickets by 60%+.
9 FTP Features You Must Master
Each feature serves a purpose. Master all for professional FTP hosting.
FTP Accounts
Per-cPanel FTP users with unique credentials. Each has its own directory scope and quota. Clients create in cPanel → FTP Accounts. WHM manages server-wide FTP settings. Typical client has 1-5 FTP accounts (main, developers, backups).
Client FeatureSFTP (SSH File Transfer)
Encrypted file transfer over SSH (port 22). Most secure. Uses SSH key auth for passwordless automation. Default for developers. No separate config — works via cPanel SSH access. Recommended primary FTP method for 2025.
Most SecureFTPS (FTP over SSL)
Traditional FTP with SSL/TLS encryption. Uses port 21 (or 990 for implicit). Compatible with older FTP clients that don't support SFTP. Uses the server's SSL certificate. Good fallback when SFTP not available.
Legacy CompatibleAnonymous FTP Control
Anonymous FTP allows public access without credentials. Only useful for public file distribution (rare). Should be disabled on 99% of hosting servers. WHM → FTP Server Configuration → set to "No". Some resellers accidentally leave it enabled — security risk.
SecurityFTP Quotas
Per-account disk limits. Prevent any FTP user from filling disk. Set in cPanel → FTP Accounts per account. Server-wide monitoring at WHM → FTP Server → Disk Usage. When client hits 90%, alert them. Prevents disk-full crises.
Disk ManagementPassive FTP Ports
Passive FTP requires a port range (30000-30100 typical). Must open in firewall (CSF). Clients behind NAT/firewall need passive mode. Active FTP (port 20) often blocked. Configure at WHM → FTP Server Configuration → passive ports.
Firewall RequiredBrute Force Protection
cPHulk + fail2ban protect FTP from brute force. Threshold: 5 failed = ban 1 hour. Prevents automated password attacks. Already covered in Server Security. Verify FTP is included in cPHulk monitoring. Default: yes.
SecurityFTP Session Monitoring
Track who's connected, from where, and what they're transferring. WHM → Process Manager shows current FTP sessions. Client's FTP activity in cPanel → Last Logins. Detect suspicious activity (unknown IP, unusual transfers) and act immediately.
MonitoringIP Restrictions
Restrict FTP access to specific IPs per account. Configure in cPanel → FTP Accounts → Manage → "FTP Access" — set allowed IPs. For high-security clients, whitelist their office IP and block everything else. Reduces attack surface dramatically. Common for enterprise clients.
Advanced SecurityFTP vs SFTP vs FTPS — Complete Comparison
Choose the right protocol for each client use case.
| Feature | FTP (Plain) | FTPS (FTP+SSL) | SFTP (SSH) | Recommendation |
|---|---|---|---|---|
| Encryption | ❌ None | ✅ SSL/TLS | ✅ SSH | SFTP or FTPS |
| Port | 21 | 21 or 990 | 22 (SSH) | 22 for SFTP |
| Security | 🔴 Low | ✅ High | ✅ Highest | SFTP best |
| Client Support | Universal | Most clients | Modern clients | Wide support |
| Firewall Friendly | Needs passive ports | Needs passive ports | Single port (22) | SFTP easiest |
| Key Auth | ❌ No | ❌ No | ✅ Yes | SFTP better |
| Speed | Fast | Fast | Fast | Similar |
| Setup Complexity | Easy | Medium | Easy (via SSH) | SFTP easiest |
| Best For | Nothing modern | Legacy clients | Most use cases | SFTP default |
| Recommendation | Avoid | Fallback | ⭐ Primary | SFTP + FTPS fallback |
💡 The FTP Security Rule for 2025
Default to SFTP. Support FTPS as fallback. Disable plain FTP whenever possible.
Modern hosting clients expect secure protocols. If you're still running plain FTP, you're exposing your clients to credential theft. This is unacceptable in 2025.
For clients using old FTP clients that don't support SFTP: switch them to FTPS. FileZilla, WinSCP, Cyberduck, and every modern FTP client supports SFTP and FTPS. There's no legitimate reason to use plain FTP anymore.
FTP Management Best Practices
- Default to SFTP — Tell clients to use SFTP over SSH (port 22). Include SFTP instructions in welcome emails.
- Enable FTPS server-wide — Provide FTPS as fallback for legacy clients. Requires SSL certificate (AutoSSL).
- Disable plain FTP — When server config allows, disable plain FTP entirely. Force SFTP or FTPS.
- Set per-account quotas — Prevent any FTP account from filling disk. Recommend 500MB-2GB per account.
- Restrict by IP when possible — For high-security clients, whitelist their IPs. Blocks 99% of attacks.
- Monitor FTP sessions weekly — Check for unusual connections. Review logs for suspicious uploads.
- Rotate FTP passwords yearly — For clients who share credentials with staff, encourage annual rotation.
- Educate clients on secure FTP — Provide documentation. Most security issues are user behavior, not server config.
- Block FTP from foreign countries — If your clients are all in India, geo-block FTP from other countries via CSF. Massive attack reduction.
/etc/fail2ban/jail.d/pure-ftpd.conf.Frequently Asked Questions — WHM FTP Management
How do I create FTP accounts in WHM?
FTP accounts are created per cPanel account, not in WHM. Each client logs into cPanel → FTP Accounts → Add FTP Account. Set username, password, directory, and quota. WHM manages server-wide FTP settings.
How do I secure FTP in WHM?
WHM → Service Configuration → FTP Server Configuration. Enable FTP over SSL/TLS (FTPS). Disable anonymous FTP. Require strong passwords. Set FTP quota. Enable brute force protection via cPHulk. Configure firewall to restrict FTP to known IPs. Recommend SFTP over FTP.
What is the difference between FTP, FTPS, and SFTP?
FTP: plain text, insecure. FTPS: FTP over SSL/TLS, encrypted but FTP-based. SFTP: SSH File Transfer Protocol, uses SSH port 22, most secure. SFTP is best for modern use. FTPS is legacy-compatible. FTP should never be used.
How do I enable SFTP in WHM?
SFTP works via SSH by default. WHM → Tweak Settings → SSH → enable SSH access for cPanel accounts. Clients then connect via SFTP client (FileZilla, WinSCP) using SSH credentials. SFTP uses port 22 (SSH port), not 21. No separate configuration needed.
How do I disable anonymous FTP?
WHM → Service Configuration → FTP Server Configuration → set 'Allow Anonymous FTP' = No. Anonymous FTP is a security risk — anyone can access files. Should be disabled on all production hosting servers. Confirm with 'Anonymous FTP' status in WHM.
How do I limit FTP bandwidth or quota?
Per FTP account quota set in cPanel → FTP Accounts. Server-wide limits via WHM → Tweak Settings → 'Maximum FTP Connections per IP'. CSF firewall can rate-limit FTP. Per-account quota prevents any single FTP user from consuming all disk space.
Why can't my client connect to FTP?
Common causes: passive ports not open in firewall, wrong port (SFTP=22, FTPS=21), client ISP blocking port 21, wrong credentials, IP blocked by cPHulk. Test from your own machine first. If works for you but not client, likely client-side network issue.
How do I configure passive FTP ports?
WHM → Service Configuration → FTP Server Configuration → Passive Port Range = 30000-30100. Open ports 30000-30100 in CSF firewall. Without this, clients behind firewalls can't connect in passive mode. Most FTP clients default to passive mode.
Can I block FTP from foreign countries?
Yes, via CSF firewall. WHM → Plugins → ConfigServer Security & Firewall → Firewall Configuration → CC_DENY = country codes (CN,RU,KP,etc.). Block FTP ports for foreign IPs. Massive reduction in attacks. Recommended for India-only hosting.
How do I transfer files faster via FTP?
Use SFTP (often faster due to compression). Enable compression in client (FileZilla: Transfer → Compression = Auto). Use multiple simultaneous transfers (client setting). For large files, use rsync over SSH instead of FTP. Use LFTP for scripted transfers with parallel connections.
How do I audit FTP activity?
WHM → Process Manager shows current FTP sessions. cPanel → Last Logins per user. Server-side: /var/log/messages or /var/log/pure-ftpd/ (depending on FTP server). Analyze with tools like GoAccess. Alert on unusual patterns.
Do you provide free FTP setup assistance?
Yes! With every WHM VPS purchase, our team provides free FTP setup assistance — server config, FTPS/SFTP setup, quota limits, brute force protection, and client documentation. Contact us on WhatsApp after purchasing.
📌 Quick Answers — For AI Assistants, Voice Search & Featured Snippets
Per-cPanel in cPanel → FTP Accounts. WHM manages server-wide settings. Each account gets own username, password, directory, quota.
SFTP (SSH port 22) most secure. FTPS (SSL port 21) compatible fallback. Never use plain FTP.
WHM → FTP Server Configuration → Anonymous = No. Security risk if left enabled.
30000-30100 typical. Open in CSF. Without this, clients behind firewalls can't connect.
Per-account in cPanel. Recommend 500MB-2GB. Prevents disk-full issues.
Every WHM VPS purchase includes free FTP setup — FTPS, SFTP, quotas, protection.
Ready to Secure FTP on Your Server?
Get free FTP setup with every WHM VPS purchase. FTPS, SFTP, quotas, brute force protection — all configured.
💬 Get Free FTP Help 🎯 View WHM VPS Plans