The best free FTP server depends first on the protocol your clients require. Traditional FTP and FTPS use FTP commands and separate control and data connections. SFTP is a different protocol that runs through SSH, so an SFTP client cannot connect to an FTP-only server.
For a graphical Windows setup, FileZilla Server is the simplest choice. Windows Server administrators already using IIS should use IIS FTP Server. On Linux, vsftpd is the lightweight option, while ProFTPD and Pure-FTPd provide more extensive hosting and authentication controls. If you do not need FTP compatibility at all, OpenSSH SFTP is usually the safer and simpler design.
Quick comparison
| Software | Best for | Platforms | Protocols | Notable limitation |
|---|---|---|---|---|
| FileZilla Server | Graphical FTP setup on Windows | Windows, macOS, Debian Linux | FTP, FTPS | SFTP is not included in the free server |
| IIS FTP Server | Windows Server and existing IIS sites | Windows and Windows Server | FTP, FTPS | Requires IIS configuration and Windows permissions |
| SFTPGo | Modern multi-protocol file transfer | Linux, Windows, macOS, containers | SFTP, SCP, FTP/S, WebDAV, HTTPS | Some advanced features are Enterprise-only |
| vsftpd | Minimal Linux FTP hosting | Unix-like systems | FTP, FTPS | Configuration is text-based |
| ProFTPD | Highly customized Unix deployments | Unix-like systems | FTP, FTPS; SFTP through an additional module | More complex to configure securely |
| Pure-FTPd | Virtual users and hosting | Unix-like systems, limited Windows support | FTP, FTPS | Best suited to administrators comfortable with Unix authentication |
| OpenSSH SFTP | Secure transfers where SSH is already available | Linux, Unix, Windows Server | SFTP, SCP | It is not an FTP server |
Every option below is free in the sense relevant to this list: it is open-source, built into the operating system, or has a free server edition. Check the license and edition details before deploying a product commercially.
1. FileZilla Server — best graphical FTP/FTPS server
FileZilla Server is the most approachable choice for administrators who want to create FTP accounts and permissions from a graphical interface. The free server supports FTP and FTP over TLS (FTPS), user and group access controls, certificates, logging, speed limits, and IP filtering.
#1 Best Overall
- Server 2022 Standard 16 Core
It does not provide SFTP in the free edition. FileZilla’s current feature documentation lists SFTP under its Enterprise Server offering, so installing the free server will not give an SSH-based transfer endpoint.
Useful configuration paths
- Server → Configure opens the main settings.
- Protocol settings → FTP and FTP over TLS (FTPS) → Passive mode controls passive transfers.
- Rights management → Users manages individual accounts.
- Rights management → Groups manages shared permissions.
- Server → Test FTP Network Configuration… checks network reachability.
For a server behind a router, select Use custom port range under passive-mode settings. A documented suggested range is 49152–65534, although a narrower range is easier to control. Enter the server’s public address under Public IP or hostname, then allow and forward the same passive range in the host firewall and router.
Opening port 21 alone is not enough. FTP uses one connection for commands and another for directory listings and file transfers. A common symptom of incomplete passive-mode configuration is that login succeeds but listings or transfers hang indefinitely.
FileZilla’s administration interface is separate from the FTP listener and commonly uses port 14148 when the installer defaults are retained. The installer also requires an administration password of at least 12 characters containing uppercase and lowercase letters, a number, and a special character. If no password is configured, remote administration is restricted to localhost.
2. IIS FTP Server — best for Windows Server environments
IIS FTP Server is the logical choice when the machine already runs Windows Server and IIS. It integrates with Windows authentication, NTFS permissions, IIS logging, site bindings, and Windows Firewall administration. The FTP Server role is included as an IIS feature on supported Windows versions.
Install the FTP role
- Open Server Manager and choose Manage → Add Roles and Features.
- Select Role-based or feature-based installation.
- Choose the target server.
- Expand Web Server (IIS) → FTP Server.
- Select FTP Service.
- Add FTP Extensibility only if IIS Manager authentication or ASP.NET membership authentication is required.
Create an FTP site
- Open IIS Manager and expand the server.
- Right-click Sites, or use Add FTP Site in the Actions pane.
- Provide a site name and physical path.
- Configure the IP address, port, SSL certificate, authentication, and authorization settings.
FTP settings are stored with the IIS site configuration. Microsoft warns that changing FTP settings can recycle an associated web application, so a dedicated FTP-only site is preferable if the server also hosts a production website.
Check FTP Authentication for login methods and FTP Authorization Rules for per-site access. Server-wide logging is available by selecting the server and opening FTP Logging. Passive data ports must be configured in the FTP firewall-support settings and then allowed through every firewall and NAT device between the client and server.
Windows authentication does not bypass NTFS permissions. A user may authenticate successfully and still receive “access denied” because IIS authorization permits the operation while the Windows filesystem ACL does not. Conversely, an NTFS permission does not help if the IIS authorization rule denies access.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #2
- Transform audio playing via your speakers and headphones
- Improve sound quality by adjusting it with effects
- Take control over the sound playing through audio hardware
3. SFTPGo — best modern all-in-one option
SFTPGo is an open-source, AGPLv3 file-transfer platform rather than a narrowly focused FTP daemon. Its open-source edition provides WebAdmin and WebClient interfaces, an API, local and encrypted filesystem storage, and support for SFTP, SCP, FTP/S, WebDAV, and HTTPS. It can also work with storage such as S3-compatible services, Google Cloud Storage, Azure Blob Storage, and remote SFTP or FTP backends.
The main advantage is a shared account and permission model across multiple protocols. For example, an organization can offer SFTP to administrators, HTTPS access to occasional users, and FTPS to a legacy integration without maintaining separate products and user databases.
SFTPGo’s dedicated SFTP service does not provide shell login or SSH port forwarding. That is useful when the account should be limited to file transfer rather than becoming a general SSH account.
Be careful when comparing the open-source and Enterprise editions. Current documentation may describe features such as clustering, advanced event actions, or certain identity-provider integrations that are not part of the free edition. Verify the edition column before designing around one of those features.
Free tools Windows power users keep installed
One-click scans. No signup required.
SFTPGo does not eliminate FTP networking problems. SFTP uses one SSH connection, but FTP and FTPS still require passive-mode ports when enabled. Also, an FTP client cannot connect using SFTP merely because both protocols are enabled in the same SFTPGo installation.
4. vsftpd — best lightweight Linux FTP server
vsftpd (“very secure FTP daemon”) is a small Linux and Unix FTP service with privilege separation, chroot support, virtual users, bandwidth limits, per-source connection limits, IPv6, and TLS. It is a strong fit for a single-purpose Linux host where a web administration panel is unnecessary.
The current upstream release is vsftpd 3.0.5. Its project notes include an ALPN fix that restores compatibility with current FileZilla clients. The default configuration file is:
/etc/vsftpd.conf
Directives use option=value syntax. Do not put spaces around the equals sign. A basic passive-mode configuration might look like this:
Recommended Free Tools
Rank #3
pasv_enable=YES
pasv_min_port=50000
pasv_max_port=50100
pasv_address=203.0.113.10
Replace the example address with the server’s public address, and allow or forward ports 50000 through 50100 as required. If the server has a directly assigned public IP, pasv_address may not be necessary; behind NAT, an incorrect advertised address is a frequent cause of failed transfers.
To restrict local users to their home directories, use:
chroot_local_user=YES
There is a particularly confusing exception: when chroot_list_enable=YES is also enabled, users in chroot_list_file are exceptions and are not chrooted. Test the effective behavior with a non-privileged account instead of assuming the list means “users to jail.”
The error 500 OOPS: vsftpd: refusing to run with writable root inside chroot means the chroot root is writable by the user. Make the jail root non-writable and create a writable child directory for uploads. Virtual users can also authenticate successfully but fail to upload because their filesystem permissions or vsftpd privilege mode is wrong; virtual_use_local_privs=YES changes virtual-user behavior, but it does not override Unix permissions.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 115. ProFTPD — best for advanced customization
ProFTPD is an Apache-style FTP daemon for Unix-like systems. Its configuration model supports virtual hosts, authentication modules, quotas, SQL and LDAP integration, access controls, and detailed per-directory behavior. It is a better fit than vsftpd when the server must fit an unusual hosting or identity-management design.
The stable upstream release is 1.3.9. The configuration file is commonly /etc/proftpd.conf or /usr/local/etc/proftpd.conf, depending on how it was installed. To test a specific file, run:
proftpd -c /path/to/proftpd.conf
TLS requires the mod_tls module. A basic policy is:
<IfModule mod_tls.c>
TLSEngine on
TLSRequired on
</IfModule>
If the TLS section is inside an <IfDefine USE_TLS> block, start the daemon with proftpd -DUSE_TLS.
Use DefaultRoot ~ to restrict ordinary users to their home directories. ProFTPD also honors /etc/ftpusers by default. A valid Unix account listed there will be rejected, which can look like a password or PAM problem until that file is checked.
Other issues are specific to its flexibility. TLS directives fail if mod_tls is not loaded. A virtual host may appear to be ignored because FTP does not select hosts exactly like HTTP name-based virtual hosting. Chrooted users can also encounter name-service problems involving NIS or NSS; in some environments, PersistentPasswd off is needed.
6. Pure-FTPd — best for virtual accounts and hosting
Pure-FTPd focuses on secure hosting features: privilege separation, virtual accounts, chroot-style isolation, quotas, database-backed authentication, and optional TLS. It is particularly useful when users should not correspond one-for-one with local Unix accounts.
The official release directory lists Pure-FTPd 1.0.54. Recent versions matter here because the project removed MD5, SHA-1, and MySQL PASSWORD() password-hashing options in 1.0.50. New deployments should use scrypt, Argon2, or the system crypt(3) function. Version 1.0.52 fixed an out-of-bounds read in MLSD, and version 1.0.53 added ldapi:// LDAP support.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Pure-FTPd’s layered authentication model can make troubleshooting less obvious. A virtual account may be valid in PureDB or another backend, yet still be unable to write because the mapped Unix user or target directory lacks filesystem permission. Check the account database, the server’s virtual-user policy, and the actual directory ownership separately.
When TLS works for login but transfers fail, verify that the client supports encrypted data channels as well as an encrypted control connection. FTPS protection must cover both parts of the FTP session if credentials and file contents are to remain private.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.7. OpenSSH SFTP — best when FTP is unnecessary
OpenSSH SFTP is the best option when the requirement is “let users transfer files securely” rather than “run an FTP service.” It is usually already installed or easily available on Linux, Unix, and Windows Server systems, and it avoids FTP’s separate passive data-channel design.
SFTP is exposed by an SSH subsystem, commonly configured as:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Full-featured professional audio and music editor that lets you record and edit music, voice and other audio recordings
- Add effects like echo, amplification, noise reduction, normalize, equalizer, envelope, reverb, echo, reverse and more
- Supports all popular audio formats including, wav, mp3, vox, gsm, wma, real audio, au, aif, flac, ogg and more
- Sound editing functions include cut, copy, paste, delete, insert, silence, auto-trim and more
- Integrated VST plugin support gives professionals access to thousands of additional tools and effects
Subsystem sftp /usr/lib/openssh/sftp-server
or:
Subsystem sftp internal-sftp
internal-sftp runs inside sshd, so chrooted users do not need a separate SFTP binary or a complete shell environment inside the jail. A typical restricted group configuration is:
Match Group sftpusers
ChrootDirectory /srv/sftp/%u
ForceCommand internal-sftp
X11Forwarding no
AllowTcpForwarding no
The chroot path and its parent directories must be owned by root and must not be writable by the user or group. Create a writable child directory instead, such as /srv/sftp/alice/upload.
Before restarting SSH, validate the configuration:
sshd -t
On Windows, check Event Viewer if the OpenSSH service refuses to start. A user who can connect but cannot upload usually has no writable child directory. A user who receives a shell instead of an SFTP session usually is not matching the Match block or is missing ForceCommand internal-sftp.
How to choose
- Need a Windows GUI? Choose FileZilla Server.
- Already running Windows Server and IIS? Use IIS FTP Server so authentication, logging, and permissions remain in one administration model.
- Need SFTP plus FTP/S, WebDAV, or a web client? Choose SFTPGo.
- Need only a small Linux FTP daemon? Start with vsftpd.
- Need SQL, LDAP, quotas, virtual hosts, or detailed policy rules? Evaluate ProFTPD.
- Need many virtual hosting accounts? Pure-FTPd is worth considering.
- Do legacy FTP clients not matter? Use OpenSSH SFTP instead of deploying FTP.
Security checklist before exposing a server
- Use SFTP or FTPS rather than plain FTP whenever traffic crosses an untrusted network.
- Restrict users to the smallest directory tree they need.
- Use separate accounts for applications and people; do not share administrator credentials.
- Set passive-mode ranges deliberately and allow only those ports through firewalls.
- Test uploads, downloads, directory listings, and failed authorization from outside the local network.
- Review logs for repeated login failures and unexpected source addresses.
- Keep the daemon and its operating system updated.
- Test the configuration after every TLS, chroot, authentication, or firewall change.
FAQ
Is SFTP the same as secure FTP?
No. SFTP is an SSH file-transfer subsystem. FTPS is the traditional FTP protocol protected with TLS. They use different connection methods and are not interchangeable.
Which free FTP server is easiest to set up on Windows?
FileZilla Server is generally the easiest graphical choice. IIS FTP Server is usually better when the machine already uses Windows Server, IIS, Windows authentication, and NTFS permissions.
Why does FTP login work but file transfer fail?
The control connection is working, but the data connection is not. Check passive-mode settings, the advertised public address, the configured port range, and firewall or NAT forwarding for that range.
Should I use FTP or SFTP for a new deployment?
Use OpenSSH SFTP when existing clients do not specifically require FTP or FTPS. SFTP avoids FTP’s separate data-channel and passive-port complexity. Use FTPS when compatibility with established FTP clients or integrations is required.
The Bottom Line
Choose FileZilla Server for a straightforward graphical FTP/FTPS server, IIS FTP Server for an IIS-based Windows environment, and vsftpd for lightweight Linux FTP hosting. Choose SFTPGo when one platform must serve several transfer protocols. If there is no legacy FTP requirement, skip FTP and deploy OpenSSH SFTP instead.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Whichever server you select, do not treat a successful login as a complete test: verify TLS or SSH protection, directory permissions, passive-mode networking where applicable, and the behavior of restricted accounts.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

