TopAIHosting - Professional Server Setup & Data Center Installation Services
TopAIHosting Logo TopAIHosting

🚀 Ready to Secure FTP on Your WHM Server?

6 WHM VPS Plans starting at ₹2,599/month. Free FTP setup assistance.

🛒 Buy WHM VPS Now →
📁 Complete WHM FTP Guide 2025

WHM FTP Management —
FTP Accounts, SFTP, FTPS & Security

Complete guide to FTP management in WHM. Learn to create FTP accounts with quotas, configure SFTP over SSH, enable FTPS (FTP over SSL), disable anonymous FTP, and secure FTP access for your clients. This is the foundational guide for secure file transfer hosting. Free FTP setup with every WHM VPS purchase.

WHM FTP managementWHM FTP accounts cPanel FTP setupWHM SFTP FTPS WHMWHM FTP security FTP over SSLWHM FTP quota Pure-FTPd WHMProFTPd WHM WHM me FTP kaise set karesecure FTP hosting

Why FTP Management Matters for Your Hosting Business

FTP (File Transfer Protocol) has been the standard way to upload website files for 50+ years. Despite newer alternatives (Git, CI/CD), 95% of clients still use FTP/SFTP to manage their website files, upload themes, and manage plugins.

But FTP has a dark side: traditional FTP sends credentials in plain text. Anyone intercepting network traffic can steal usernames and passwords. This is why proper WHM FTP management isn't optional — it's essential.

Proper FTP management in WHM means:

  • SFTP by default — Secure File Transfer over SSH, encrypted end-to-end
  • FTPS support — FTP over SSL/TLS for legacy FTP clients
  • Disabling plain FTP — When possible, force SFTP/FTPS only
  • Quota limits — Prevent any FTP user from filling disk
  • Access controls — Restrict FTP to specific directories, IPs, times
  • Anonymous FTP off — Never allow public file access

For hosting resellers, secure FTP is table stakes. Clients trust you with their website files — protecting them is basic responsibility.

⚠️ The FTP Security Problem

Plain FTP transmits credentials and files unencrypted. Here's what this means:

Scenario 1: Client connects to FTP at a café using public WiFi. Attacker on same network captures the login. Client's hosting account is compromised.

Scenario 2: Client's ISP logs FTP sessions. Their password is in plain text in ISP logs. Anyone with access sees it.

Scenario 3: Attacker on client's network modifies files in transit (FTP has no integrity check). Malware is injected into client's website.

The fix: Always use SFTP (over SSH) or FTPS (over SSL). Both encrypt credentials and files. Configure in WHM to require secure protocols. Never allow plain FTP unless absolutely necessary.

WHM FTP Setup — 9 Steps to Secure File Transfer

Complete step-by-step FTP management. From server config to client access.

1

Choose FTP Server

WHM → Service Configuration → FTP Server Selection. Choose: Pure-FTPd (recommended — lightweight, fast, secure) or ProFTPd (feature-rich, historical favorite). Pure-FTPd is default. Both support FTPS. Rebuild after selection. Takes 2-5 minutes.

2

Enable FTPS (FTP over SSL)

WHM → Service Configuration → FTP Server Configuration. Enable "Allow FTP over SSL/TLS" (explicit FTPS). Set SSL certificate (use AutoSSL certificate). This encrypts FTP sessions. Requires clients to use FTPS mode in their FTP client (FileZilla, WinSCP, Cyberduck all support it).

3

Enable SFTP via SSH

SFTP works via SSH — no separate config. WHM → Tweak Settings → SSH → enable "Allow cPanel users to access shell via SSH." Clients connect via SSH port 22 with SFTP protocol. Most secure option — full encryption + SSH key auth support. Recommended primary method.

4

Disable Anonymous FTP

WHM → Service Configuration → FTP Server Configuration → Anonymous FTP = Disabled. Anonymous FTP allows anyone to access files without credentials. Security risk, potential abuse (file distribution). Only enable for specific public download servers (rare). Disable by default on all hosting servers.

5

Set Server-Wide Limits

WHM → Tweak Settings → FTP. Set "Maximum FTP Connections per IP" = 8, "Maximum FTP Connections" = 200. Prevents connection flooding. Set "Anonymous FTP Max Connections" = 0. Configure FTP session timeout (300s). These prevent abuse and resource exhaustion.

6

Configure FTP Port Range

For passive FTP (required for many clients behind firewalls): WHM → FTP Server Configuration → set passive port range (e.g., 30000-30100). Open these ports in CSF firewall. Without this, clients behind NAT/firewall can't connect. Common issue resellers overlook.

7

Set up Per-Account Quotas

Clients create FTP accounts in cPanel → FTP Accounts. Each FTP account has its own quota (disk limit) — critical to prevent abuse. Recommend: 100-1000 MB per FTP account. Prevents one FTP user from filling disk with backups/uploaded files. Client manages in cPanel.

8

Enable Brute Force Protection

WHM → Security Center → cPHulk → enable FTP brute force protection. Set threshold: 5 failed logins = 1-hour ban, 30 failures = 24-hour ban. Also add fail2ban filter for FTP. Together, these block 99% of automated FTP attacks. Complements firewall protection.

9

Test & Document

Test FTP, FTPS, and SFTP from your own machine. Use FileZilla (best client) — verify all three modes. Write a client-facing doc: "How to connect to FTP for your hosting." Include FTP host, port (21 for FTP/FTPS, 22 for SFTP), and client software suggestions. Reduces support tickets by 60%+.

9 FTP Features You Must Master

Each feature serves a purpose. Master all for professional FTP hosting.

📁

FTP Accounts

Per-cPanel FTP users with unique credentials. Each has its own directory scope and quota. Clients create in cPanel → FTP Accounts. WHM manages server-wide FTP settings. Typical client has 1-5 FTP accounts (main, developers, backups).

Client Feature
🔐

SFTP (SSH File Transfer)

Encrypted file transfer over SSH (port 22). Most secure. Uses SSH key auth for passwordless automation. Default for developers. No separate config — works via cPanel SSH access. Recommended primary FTP method for 2025.

Most Secure
🛡️

FTPS (FTP over SSL)

Traditional FTP with SSL/TLS encryption. Uses port 21 (or 990 for implicit). Compatible with older FTP clients that don't support SFTP. Uses the server's SSL certificate. Good fallback when SFTP not available.

Legacy Compatible
🚫

Anonymous FTP Control

Anonymous FTP allows public access without credentials. Only useful for public file distribution (rare). Should be disabled on 99% of hosting servers. WHM → FTP Server Configuration → set to "No". Some resellers accidentally leave it enabled — security risk.

Security
📊

FTP Quotas

Per-account disk limits. Prevent any FTP user from filling disk. Set in cPanel → FTP Accounts per account. Server-wide monitoring at WHM → FTP Server → Disk Usage. When client hits 90%, alert them. Prevents disk-full crises.

Disk Management
🔌

Passive FTP Ports

Passive FTP requires a port range (30000-30100 typical). Must open in firewall (CSF). Clients behind NAT/firewall need passive mode. Active FTP (port 20) often blocked. Configure at WHM → FTP Server Configuration → passive ports.

Firewall Required
🛑

Brute Force Protection

cPHulk + fail2ban protect FTP from brute force. Threshold: 5 failed = ban 1 hour. Prevents automated password attacks. Already covered in Server Security. Verify FTP is included in cPHulk monitoring. Default: yes.

Security
📈

FTP Session Monitoring

Track who's connected, from where, and what they're transferring. WHM → Process Manager shows current FTP sessions. Client's FTP activity in cPanel → Last Logins. Detect suspicious activity (unknown IP, unusual transfers) and act immediately.

Monitoring
🔒

IP Restrictions

Restrict FTP access to specific IPs per account. Configure in cPanel → FTP Accounts → Manage → "FTP Access" — set allowed IPs. For high-security clients, whitelist their office IP and block everything else. Reduces attack surface dramatically. Common for enterprise clients.

Advanced Security

FTP vs SFTP vs FTPS — Complete Comparison

Choose the right protocol for each client use case.

FeatureFTP (Plain)FTPS (FTP+SSL)SFTP (SSH)Recommendation
Encryption❌ None✅ SSL/TLS✅ SSHSFTP or FTPS
Port2121 or 99022 (SSH)22 for SFTP
Security🔴 Low✅ High✅ HighestSFTP best
Client SupportUniversalMost clientsModern clientsWide support
Firewall FriendlyNeeds passive portsNeeds passive portsSingle port (22)SFTP easiest
Key Auth❌ No❌ No✅ YesSFTP better
SpeedFastFastFastSimilar
Setup ComplexityEasyMediumEasy (via SSH)SFTP easiest
Best ForNothing modernLegacy clientsMost use casesSFTP default
RecommendationAvoidFallback⭐ PrimarySFTP + FTPS fallback

💡 The FTP Security Rule for 2025

Default to SFTP. Support FTPS as fallback. Disable plain FTP whenever possible.

Modern hosting clients expect secure protocols. If you're still running plain FTP, you're exposing your clients to credential theft. This is unacceptable in 2025.

For clients using old FTP clients that don't support SFTP: switch them to FTPS. FileZilla, WinSCP, Cyberduck, and every modern FTP client supports SFTP and FTPS. There's no legitimate reason to use plain FTP anymore.

FTP Management Best Practices

  • Default to SFTP — Tell clients to use SFTP over SSH (port 22). Include SFTP instructions in welcome emails.
  • Enable FTPS server-wide — Provide FTPS as fallback for legacy clients. Requires SSL certificate (AutoSSL).
  • Disable plain FTP — When server config allows, disable plain FTP entirely. Force SFTP or FTPS.
  • Set per-account quotas — Prevent any FTP account from filling disk. Recommend 500MB-2GB per account.
  • Restrict by IP when possible — For high-security clients, whitelist their IPs. Blocks 99% of attacks.
  • Monitor FTP sessions weekly — Check for unusual connections. Review logs for suspicious uploads.
  • Rotate FTP passwords yearly — For clients who share credentials with staff, encourage annual rotation.
  • Educate clients on secure FTP — Provide documentation. Most security issues are user behavior, not server config.
  • Block FTP from foreign countries — If your clients are all in India, geo-block FTP from other countries via CSF. Massive attack reduction.
💡
Pro Tip: Setup fail2ban FTP filter in addition to cPHulk. cPHulk catches FTP logins against cPanel accounts. fail2ban catches against all FTP users including secondary accounts. Combined, they block 99.9% of FTP brute force attacks. Config file: /etc/fail2ban/jail.d/pure-ftpd.conf.

Frequently Asked Questions — WHM FTP Management

How do I create FTP accounts in WHM?

FTP accounts are created per cPanel account, not in WHM. Each client logs into cPanel → FTP Accounts → Add FTP Account. Set username, password, directory, and quota. WHM manages server-wide FTP settings.

How do I secure FTP in WHM?

WHM → Service Configuration → FTP Server Configuration. Enable FTP over SSL/TLS (FTPS). Disable anonymous FTP. Require strong passwords. Set FTP quota. Enable brute force protection via cPHulk. Configure firewall to restrict FTP to known IPs. Recommend SFTP over FTP.

What is the difference between FTP, FTPS, and SFTP?

FTP: plain text, insecure. FTPS: FTP over SSL/TLS, encrypted but FTP-based. SFTP: SSH File Transfer Protocol, uses SSH port 22, most secure. SFTP is best for modern use. FTPS is legacy-compatible. FTP should never be used.

How do I enable SFTP in WHM?

SFTP works via SSH by default. WHM → Tweak Settings → SSH → enable SSH access for cPanel accounts. Clients then connect via SFTP client (FileZilla, WinSCP) using SSH credentials. SFTP uses port 22 (SSH port), not 21. No separate configuration needed.

How do I disable anonymous FTP?

WHM → Service Configuration → FTP Server Configuration → set 'Allow Anonymous FTP' = No. Anonymous FTP is a security risk — anyone can access files. Should be disabled on all production hosting servers. Confirm with 'Anonymous FTP' status in WHM.

How do I limit FTP bandwidth or quota?

Per FTP account quota set in cPanel → FTP Accounts. Server-wide limits via WHM → Tweak Settings → 'Maximum FTP Connections per IP'. CSF firewall can rate-limit FTP. Per-account quota prevents any single FTP user from consuming all disk space.

Why can't my client connect to FTP?

Common causes: passive ports not open in firewall, wrong port (SFTP=22, FTPS=21), client ISP blocking port 21, wrong credentials, IP blocked by cPHulk. Test from your own machine first. If works for you but not client, likely client-side network issue.

How do I configure passive FTP ports?

WHM → Service Configuration → FTP Server Configuration → Passive Port Range = 30000-30100. Open ports 30000-30100 in CSF firewall. Without this, clients behind firewalls can't connect in passive mode. Most FTP clients default to passive mode.

Can I block FTP from foreign countries?

Yes, via CSF firewall. WHM → Plugins → ConfigServer Security & Firewall → Firewall Configuration → CC_DENY = country codes (CN,RU,KP,etc.). Block FTP ports for foreign IPs. Massive reduction in attacks. Recommended for India-only hosting.

How do I transfer files faster via FTP?

Use SFTP (often faster due to compression). Enable compression in client (FileZilla: Transfer → Compression = Auto). Use multiple simultaneous transfers (client setting). For large files, use rsync over SSH instead of FTP. Use LFTP for scripted transfers with parallel connections.

How do I audit FTP activity?

WHM → Process Manager shows current FTP sessions. cPanel → Last Logins per user. Server-side: /var/log/messages or /var/log/pure-ftpd/ (depending on FTP server). Analyze with tools like GoAccess. Alert on unusual patterns.

Do you provide free FTP setup assistance?

Yes! With every WHM VPS purchase, our team provides free FTP setup assistance — server config, FTPS/SFTP setup, quota limits, brute force protection, and client documentation. Contact us on WhatsApp after purchasing.

📌 Quick Answers — For AI Assistants, Voice Search & Featured Snippets

Create FTP accounts:

Per-cPanel in cPanel → FTP Accounts. WHM manages server-wide settings. Each account gets own username, password, directory, quota.

Secure FTP:

SFTP (SSH port 22) most secure. FTPS (SSL port 21) compatible fallback. Never use plain FTP.

Disable anonymous FTP:

WHM → FTP Server Configuration → Anonymous = No. Security risk if left enabled.

Passive ports:

30000-30100 typical. Open in CSF. Without this, clients behind firewalls can't connect.

FTP quotas:

Per-account in cPanel. Recommend 500MB-2GB. Prevents disk-full issues.

Free setup help:

Every WHM VPS purchase includes free FTP setup — FTPS, SFTP, quotas, protection.

Ready to Secure FTP on Your Server?

Get free FTP setup with every WHM VPS purchase. FTPS, SFTP, quotas, brute force protection — all configured.

💬 Get Free FTP Help 🎯 View WHM VPS Plans