You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2012 R2配置FTP over SSL文件服务器及跨机访问咨询

搭建支持FTP over SSL的Windows Server文件服务器步骤及访问方法

Got it, let's walk through setting up an FTP server with SSL encryption on Windows Server—this will let your users securely download files. I’ll break this into clear, actionable steps:

1. Install the FTP Server Role

First, we need to add the necessary IIS and FTP components to your server:

  • Open Server Manager from the Start menu, then click Add Roles and Features from the dashboard.
  • Follow the wizard until you reach the Server Roles section. Expand Web Server (IIS), then check the box for FTP Server (this will auto-select FTP Service and FTP Extensibility—keep both checked).
  • Complete the wizard to install the roles; you might need to restart the server afterward if prompted.

2. Create an SSL Certificate (for encryption)

FTP over SSL requires a certificate. For testing, a self-signed certificate works fine; for production, use a certificate from a trusted CA.

  • Open IIS Manager (search for it in Start).
  • In the left pane, select your server name, then double-click Server Certificates in the middle pane.
  • Click Create Self-Signed Certificate in the right-hand actions menu. Name it something like FTP SSL Cert, select Web Hosting as the certificate store, then click OK.

3. Set Up the FTP Site with SSL

Now let's configure the actual FTP site and enable SSL:

  • In IIS Manager, right-click Sites in the left pane, then select Add FTP Site.
  • Enter a Site name (e.g., Student Thesis FTP) and browse to the Physical path where your files will be stored (e.g., D:\ThesisFiles). Click Next.
  • On the Binding and SSL page:
    • Select your server’s public IP address from the dropdown.
    • Leave the port as 21 (standard FTP control port).
    • Under SSL, choose Require SSL (to force all connections to use encryption) or Allow SSL (if you want to let unencrypted connections through, though not recommended).
    • Select the SSL certificate you created earlier from the dropdown. Click Next.
  • On the Authentication and Authorization Information page:
    • Check Basic authentication (since we’re using SSL, this is safe—credentials are encrypted).
    • Under Authorization, choose Specified users and enter the Windows user accounts that need access, or select All users if you want anyone with a valid account to connect.
    • Set permissions to Read (since users only need to download files; uncheck Write unless you want them to upload).
    • Click Finish to create the site.

4. Configure Firewall Rules

Windows Firewall will block FTP connections by default, so we need to open the necessary ports:

  • Open Windows Defender Firewall with Advanced Security.
  • Click Inbound Rules in the left pane, then New Rule in the right actions menu.
  • Select Port as the rule type, click Next.
  • Choose TCP, enter 21 in the Specific local ports field, click Next.
  • Select Allow the connection, click Next.
  • Leave all network profiles checked (Domain, Private, Public—adjust if needed for your environment), click Next.
  • Name the rule FTP Control Port (21) and click Finish.

For Passive FTP (most clients use this)

  • Go back to IIS Manager, select your FTP site, then double-click FTP Firewall Support in the middle pane.
  • Enter a port range for passive connections (e.g., 50000-50100) in the Data Channel Port Range field, then click Apply.
  • Create another inbound firewall rule for this port range: follow the same steps above, but enter 50000-50100 instead of 21, name it FTP Passive Ports (50000-50100).

5. Access the FTP Server from Other Devices

Using Windows File Explorer

  • Open File Explorer, type ftp://[your-server-ip] in the address bar (replace [your-server-ip] with your server’s actual IP).
  • You’ll be prompted to enter your Windows username and password. If using a self-signed certificate, you’ll get a security warning—click Yes to trust the certificate and proceed.
  • You’ll now see the files in your FTP directory and can download them like any other file.

Using a Third-Party Client (e.g., FileZilla)

  • Open FileZilla, click File > Site Manager.
  • Click New Site, name it something like Thesis FTP Server.
  • Under Protocol, select FTP - File Transfer Protocol.
  • Under Encryption, select Require explicit FTP over TLS.
  • Enter your server’s IP in the Host field, leave port as 21.
  • Enter your Windows username and password in the relevant fields.
  • Click Connect. If using a self-signed certificate, you’ll need to confirm trust for the certificate in the popup.

Quick Troubleshooting Tips

  • Permission Errors: Make sure the Windows user account has Read NTFS permissions on the FTP physical path (right-click the folder > Properties > Security tab).
  • Certificate Trust: For self-signed certs, clients will get warnings—you can install the certificate on client machines to avoid this, or use a trusted CA cert for production.
  • Passive Mode Issues: If clients can connect but can’t see files, double-check the passive port range and firewall rules.

内容的提问来源于stack exchange,提问作者Dimitrios Gkizanis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:12:36