Home › Topics › Best SFTP Server for Windows › FileZilla Server vs Sysax

FileZilla Server vs Sysax Multi Server: FTP Server Setup and What the Free Option Leaves Out

"We already have FileZilla." Somebody says this in the first five minutes of nearly every file transfer project. They are right, in the sense that the FileZilla client is on half the desktops in the building. What the project needs is a server. FileZilla makes one of those too, and it is a different program that happens to share the name, the logo, and the reputation. Most of the trouble on this page starts in the gap between the two.

This article does two jobs. First, it is a straightforward guide to setting up FileZilla FTP Server on Windows, because that is what most people arriving here want. Second, it compares the free FileZilla Server with our own Sysax Multi Server, says plainly what each one does and does not do, and helps you decide which fits. One disclosure before anything else: Sysax Multi Server is our product. The rule in this library is that rivals' strengths get stated without a "but" attached, and that rule holds here.

It is part of our Best SFTP Server for Windows comparison, which covers six products. This page takes one pairing from that comparison and goes deeper.

Two Different Programs With One Name

The FileZilla client is the program most people mean when they say FileZilla. It runs on your desktop and connects to servers. It speaks three protocols: FTP, FTPS, and SFTP.

FileZilla Server is the other one. It runs as a background service and accepts connections from clients. It is free and open source, and it speaks two protocols: FTP and FTPS. It does not speak SFTP. The project's own documentation is direct about this: SFTP on the server side is offered only in the commercial edition, FileZilla Pro Enterprise Server.

That asymmetry is the single most important fact on this page. The client does SFTP, so people assume the server does too. Then a partner's SFTP client is pointed at a FileZilla Server on port 22 and finds nothing there. FTPS and SFTP sound like siblings and are unrelated protocols; SFTP vs FTPS explains the difference. The names in this field were not chosen to make anyone's life easier.

Remember: the FileZilla client supports FTP, FTPS, and SFTP. The free FileZilla Server supports FTP and FTPS only. If a partner requires SFTP, the free server cannot provide it, however it is configured.

How to Set Up FileZilla FTP Server on Windows

If FTP and FTPS are what you need, FileZilla Server is quick to set up. The sequence below is for the current generation of the server on Windows. Menu names may shift slightly between releases, but the order of work does not.

Install the server

  1. Download FileZilla Server from the FileZilla project's own website. Avoid download portals, which sometimes repackage installers.
  2. Run the installer. Choose to install the server as a Windows service that starts automatically, so that it runs with nobody logged in.
  3. When asked, set the port for the administration interface. The default is 14148. Set an administration password and record it somewhere safe.
  4. Finish the installation and start the administration interface.

Connect the administration interface

The administration interface is a separate program that manages the service. Connect it to host 127.0.0.1, port 14148, with the password you set. On first connection it shows the server's certificate fingerprint and asks you to confirm it. Then open the Server menu and choose Configure.

Configure the FTP listener and encryption

  1. Under Server listeners, confirm a listener on port 21. For its protocol, choose the option that requires explicit FTP over TLS. The option that also permits plain FTP should be used only in a lab.
  2. In the FTP and FTPS protocol settings, review the TLS certificate. The server generates a self-signed certificate automatically. For a public server, replace it with one issued for your host name. The server has a built-in option to obtain a Let's Encrypt certificate.
  3. In the passive mode settings, set a custom port range, for example 50000 to 50100. If the server is behind NAT, enter the public IP address or host name that clients should be told to use.

Create a user and a folder

  1. Create the folder on disk first, for example C:\FTP\acme.
  2. Under Rights management, open Users and add a user, for example acme.
  3. Set the user to require a password and enter one.
  4. Under Mount points, add an entry. Set the virtual path to / and the native path to C:\FTP\acme. The virtual path is what the user sees. The native path is where it really is.
  5. Set the access mode to read only or read and write, as the job requires.
  6. Click Apply.

Open the firewall and test

The server is now listening, and Windows Defender Firewall still needs to be told. From an elevated PowerShell prompt:

New-NetFirewallRule -DisplayName "FTP control" -Direction Inbound -Protocol TCP -LocalPort 21 -Action Allow
New-NetFirewallRule -DisplayName "FTP passive range" -Direction Inbound -Protocol TCP -LocalPort 50000-50100 -Action Allow

Ask for the same two rules on the network's edge firewall, forwarded to the server if NAT is in use. Leave port 14148 closed to the outside. The administration interface is for you, not for the internet. Then test from a machine outside your network:

curl -v --ssl-reqd --user acme ftp://ftp.example.com/

A directory listing means the control connection, TLS, and the passive data connection all work. A login followed by a hang means the passive range is not open or the public address is not set. The general version of these steps, including that fault, is in how to set up an FTP server on Windows, and the port list is in ports for FTP, FTPS and SFTP.

Five Settings to Check Before Partners Connect

A server that passes its first test is working. It is not yet finished. These five checks take a quarter of an hour and apply to any FTP server, though the wording here follows FileZilla Server's menus.

Plain FTP is really off. Run the test command again without --ssl-reqd. It should be refused. If a listing comes back, the listener still accepts unencrypted logins, and sooner or later a partner's script will use one without anyone noticing.

The administration interface stays local. By default it listens only on the server itself. Leave it that way. If you must administer the server remotely, reach the machine through your normal remote management tools first, then connect locally. An administration port open to the internet is a second front door with a single lock.

Each partner has their own user and their own mount point. A shared account, or two users pointed at the same native path, means one partner can read another's files. Check the mount points list for each user and confirm that no native path appears twice. It is a dull five minutes, and it prevents an awkward phone call.

Failed logins are being limited. Turn on the automatic banning of addresses after repeated failures, and add IP filters for partners who connect from fixed addresses. Any server on port 21 starts receiving password guesses within hours of going live.

You can find the log. Note where the log files are written and how long they are kept. Then find your own test login in them. A log is only useful to someone who knows where it is, and the time to learn that is before the first dispute about whether a file arrived. The full list of what a secure server needs is in what makes an FTP server secure.

What FileZilla Server Does Well

FileZilla Server deserves its reputation within its scope, and the scope is worth stating fairly.

  • It is free and open source. There is no license to buy and the code is public.
  • It is actively maintained. Releases and security fixes continue to appear, which cannot be said of every free server.
  • It handles FTPS properly. Explicit FTP over TLS, certificate management, and integrated Let's Encrypt certificates are all there.
  • The administration interface is clean. Users, groups, mount points, and listeners are where you would look for them.
  • It includes sensible protections. Its feature list covers connection filtering by IP address, temporary banning after repeated failures, speed limits, and configurable logging.
  • It is not tied to Windows. It also runs on macOS and on Debian Linux, which our own server does not.

For an FTP or FTPS server with a modest number of accounts, run by someone happy to maintain a user list by hand, it is a good choice and we will not pretend otherwise. What open-source tools do well in general is covered in what open source transfer tools genuinely do well.

What the Free Server Leaves Out

The limits are few and specific. Whether they matter depends entirely on who will connect to you.

SFTP. This is the large one. Many organizations now require SFTP from their partners as a matter of policy, and a growing number of systems offer nothing else. The free server cannot accept an SFTP connection. The vendor's answer is its paid Pro Enterprise edition.

Directory logins and a second factor. The free server keeps its own list of users and can also check a user against the system's own credentials. Active Directory integration and two-factor authentication are listed as features of the Pro Enterprise edition. For ten partner accounts a hand-kept list is fine. For three hundred staff who already have domain logins, it is a second password for everyone.

Browser-based transfer. FileZilla Server offers FTP and FTPS. It does not provide a web page where an occasional user can upload a file over HTTPS without installing a client.

Compliance machinery. Its published feature list does not include a FIPS 140-2 mode, which some regulated environments require by name.

Meridian Parts ran FileZilla Server for two years without a single complaint. It took orders from eleven distributors over FTPS every night. Then Meridian won a large retail customer whose onboarding document had one line under Protocol: "SFTP only. No exceptions." Meridian's administrator opened the server's settings to add an SFTP listener and could not find one. He assumed he was looking in the wrong menu. He was looking at the right menu of a product that did not have the feature. The customer's go-live date was nine days away. Nothing had been wrong with the server. The requirement had changed around it.

FileZilla Server and Sysax Multi Server, Side by Side

Sysax Multi Server is a commercial file transfer server for Windows. It starts from the other end of the list above: several protocols in one service, with Windows-native logins. The table compares it with the free FileZilla Server. Where FileZilla's paid edition changes the answer, the table says so.

Question FileZilla Server (free) Sysax Multi Server
Protocols FTP, FTPS. SFTP only in the paid Pro Enterprise edition SFTP, FTPS, FTP, and HTTPS web transfer
Accounts Its own user list, optionally system credentials. Active Directory in Pro Enterprise Its own accounts, Windows accounts, Active Directory or LDAP, or an external database
Second factor at login In Pro Enterprise Yes
SSH public key login Not applicable without SFTP Yes
FIPS 140-2 mode Not listed Yes
Activity logging Configurable log files Log files and a log database
Actions when files arrive Not a focus of the product Event triggers, such as email or encryption on upload
Runs on Windows, macOS, Debian Linux Windows only
Cost Free Licensed per server; a free edition exists for personal, non-commercial use
Support Community forum Vendor support

Two rows favor FileZilla Server outright: cost and platforms. If the server must run on Linux or a Mac, our product is not an option. Current editions and prices for ours are on the edition comparison page. Check each vendor's own site for theirs, since features move between editions over time.

Which One Fits Your Situation

The honest decision is short, and it turns on the partners you have and the ones you expect.

Choose FileZilla Server when FTP and FTPS cover everyone who will ever connect, the number of accounts is small enough to manage by hand, and free and open source matter to you. It is also the answer when the host is not Windows.

Choose a multi-protocol commercial server, ours or another, when any of these is true. A partner requires SFTP. Staff should log in with their Active Directory accounts. A security review asks for a second factor, a FIPS mode, or an audit log in a database. Occasional users need a browser page instead of a client. Or you want someone to call when it breaks.

And if the only thing you need is free SFTP, the answer is neither product. It is the OpenSSH server included with Windows, which how to set up an SFTP server on Windows walks through. We would rather tell you that here than have you find out after a trial.

Whichever way you lean, test before you commit. Designing a trial that actually tests a file transfer server gives a method that works for free and paid products alike, and open source vs commercial transfer tools covers the tradeoff without the usual tribal loyalties.

Moving from FileZilla Server Later

Starting on FileZilla Server and moving when a requirement changes is a perfectly reasonable plan. The move is uneventful if you prepare for it, and the preparation is mostly writing things down while nothing is on fire.

SERVER MIGRATION CHECKLIST

BEFORE
[ ] List every user: name, home folder (native path), read/write rights
[ ] List every partner: contact, source addresses, protocol they use today
[ ] Record the passive port range and the public address setting
[ ] Record the host name partners use (it must not change)
[ ] Export or locate the TLS certificate and its private key
[ ] Note the log location and how far back the logs go

BUILD
[ ] Install the new server on a separate machine or port
[ ] Recreate users with the same names and the same home folders
[ ] Install the same certificate, so FTPS clients see no change
[ ] Set the same passive range and public address
[ ] Enable the new protocol (for example SFTP) and record the host key fingerprint

CUT OVER
[ ] Test each account on the new server from outside the network
[ ] Tell partners the date; send SFTP users the fingerprint
[ ] Switch the firewall forward or the DNS record to the new server
[ ] Keep the old server stopped but intact for an agreed period
[ ] Watch failed logins on the new server for the first week

Two items make the difference. Keeping the host name and the certificate means existing FTPS partners notice nothing. Recreating users with identical names and folders means scripts on the partner side keep working. Passwords are the awkward part, since they cannot normally be copied between different products. Plan to reissue them, or use the move as the occasion to switch partners to keys. Nobody enjoys a password reset, but it is the one migration task that also improves security. The wider method is in our migrating transfer workloads series.

The Version to Tell a Colleague

FileZilla Server is a free, well-maintained FTP and FTPS server, and it is a different program from the FileZilla client. Setting it up takes six steps: install it as a service, connect the administration interface, require FTP over TLS on port 21, set a passive port range and public address, create users with mount points, and open the firewall. Its main limit is that the free server has no SFTP; that, Active Directory logins, and two-factor authentication are in the paid edition. Sysax Multi Server is a commercial Windows server that provides SFTP, FTPS, FTP, and HTTPS together with directory logins. Choose by which protocols your partners require.

For the other products in this market, see the full comparison of SFTP servers for Windows and the other Windows FTP and SFTP servers, compared. For free clients and servers by job, see best FTP software for Windows. For what any server must do to be called secure, see what makes an FTP server secure. To try ours, the trial is on the download page.

Frequently Asked Questions

Does FileZilla Server support SFTP?
No. The free FileZilla Server supports FTP and FTPS only. SFTP on the server side is offered in the commercial FileZilla Pro Enterprise Server. The FileZilla client does support SFTP, which is the source of the confusion.
How do I set up a FileZilla FTP server?
Install FileZilla Server as a Windows service and connect the administration interface on port 14148. Require explicit FTP over TLS on port 21, set a passive port range and public address, and add users with a mount point for each. Then open port 21 and the passive range on the firewall and test from outside.
Is FileZilla Server free?
Yes. FileZilla Server is free and open source. A separate commercial edition, FileZilla Pro Enterprise Server, adds SFTP, Active Directory integration, and two-factor authentication.
What ports does FileZilla Server use?
It listens on TCP port 21 for FTP and explicit FTPS, and uses a passive port range you configure for data connections. Its administration interface uses port 14148 by default, which should not be exposed to the internet.
What is the difference between FileZilla Server and Sysax Multi Server?
FileZilla Server is a free FTP and FTPS server that runs on Windows, macOS, and Debian Linux. Sysax Multi Server is a commercial Windows server that offers SFTP, FTPS, FTP, and HTTPS in one service, with Active Directory logins, a second factor, and a FIPS 140-2 mode.
Can I move from FileZilla Server to another server later?
Yes. Keep the same host name, certificate, user names, and home folders, and existing partners will see little change. Passwords usually have to be reissued because they cannot be copied between products.

From the Sysax team: we build secure file transfer software for Windows. Sysax Multi Server is an FTP, FTPS, SFTP, and HTTPS server. Sysax FTP Automation handles scheduled, scripted transfers. Free trials are on the download page.