Back to Gyanamguru Training Portal

FTP Dual-Channel Architecture Simulation

Active FTP: Server connects back from TCP Port 20 to Client High Port (Requires Firewall Inbound Open)

Status: Step 1 -> Client opens Control Connection to Server TCP Port 21.

FTP Client Console (Client_Host - 192.168.1.50)
C:\Users\Admin> ftp 10.0.0.100 Connected to 10.0.0.100. 220 (vsFTPd 3.0.3) User (10.0.0.100:(none)): admin 331 Please specify the password. Password: 230 Login successful. ftp>
ftp>

What is File Transfer Protocol (FTP)?

File Transfer Protocol (FTP) is an Application Layer protocol running over TCP. It utilizes an out-of-band architecture splitting session logic into two discrete channels: a Control Channel (Port 21) for commands/responses, and a separate Data Channel (Port 20 or High Random Ports) for raw file streams and directory listings.

Active Mode vs. Passive Mode FTP

FTP Command & Response Codes

Secure FTP Alternatives

Previous Lab (SNMP) Next Lab (DNS Resolution)
×

FTP Protocol Port & Command Matrix

Active Transfer Mode: Active Mode (PORT)

FTP Channel Architecture

Channel Type Direction (Active) Direction (Passive) Port Numbers
Control ChannelClient -> ServerClient -> ServerClient High Port -> Server 21
Data ChannelServer -> ClientClient -> ServerServer 20 -> Client High Port (Active)
Client High Port -> Server High Port (Passive)
FTP CommandsPORT, USER, PASS, RETRPASV, LIST, STOR, QUITTransmitted in ASCII Cleartext

Firewall Configuration Rules

Active FTP Firewall Impact: Client firewall must permit unsolicited inbound connections on random high ports from Server Port 20.

Passive FTP Firewall Impact: Server firewall must open a configured pool of high ports (e.g., 50000-51000) for incoming client connections.