Networking · Concept · 9 min read

Port 21, and the Second Connection Nobody Expects

Commands go over port 21 and files do not. That split is why FTP breaks through firewalls and NAT when nothing else does, and why the fix is a mode rather than a rule.

Written by Marko Ristic, Editor Updated Sep 17, 2026
2Connections per FTP session, and only one of them is port 21
20The data port, defined by RFC 959 as adjacent to the control port
425The reply code that means the second connection failed
4Connections used to list a directory and fetch three files
Short answer

Port 21 is the control channel for FTP, and the word control is the whole story. Commands and replies go over port 21; the files themselves travel on a completely separate connection, opened per transfer, on port 20 or on a high numbered port depending on the mode.

That split is why FTP is the protocol that breaks through firewalls and NAT when nothing else does. It is also plaintext, credentials included, which is why finding port 21 open on a business network is usually the discovery of a problem rather than a service.

  • Port 21 carries commands and replies, never the file data
  • The data arrives on a second connection, port 20 or a high port
  • Active and passive differ only in who opens that second connection
  • FTP sends credentials and file contents in the clear
  • FTPS and SFTP are different protocols, and SFTP is not FTP at all
On this page

What uses itWhat runs on port 21

An FTP session starts with a client opening a TCP connection to port 21 on the file server. Over that connection the client authenticates and then issues commands, in plain text, and the server answers with numeric reply codes.

Nothing else happens on that connection. It is a conversation about files rather than a channel for transferring them.

When a file actually needs to move, a second TCP connection to the server is opened for that transfer alone, and it closes when the transfer ends. The next file opens another one. A session that lists a directory and downloads three files uses one control connection and four data connections.

That design is unusual and it is the source of every practical difficulty with the protocol. It is also why the answer to which port does FTP use is not one number.

RFC 959, the File Transfer Protocol specification, defines the server data port as the port adjacent to the control connection port. Control is 21, so data is 20. The number nobody can ever remember is not arbitrary; it is derived.

A session is readable because the replies are numbered, and the numbers are worth knowing because they say which of the two connections failed.

ReplyRFC 959 meaningWhat it tells you
220Service ready for new userThe control connection reached the server
331User name okay, need passwordThe name was accepted, so far so ordinary
230User logged in, proceedAuthentication is done and nothing has moved yet
227Entering passive modeThe server has just named the data port
200Command okayThe command was understood
425Cannot open data connectionThe second connection failed, not the first
426Connection closed, transfer abortedThe data connection died mid transfer
530Not logged inCredentials, or an anonymous login that is disabled
550File unavailablePermissions or a path, on a working session

Everything above 500 that people report as an FTP problem is usually one of the last two, which are ordinary. The pair worth recognizing on sight is 425 and 426, because both mean the control channel is healthy and the data channel is not.

FirewallsWhy a firewall has to understand FTP

Most protocols use one connection to one known port, and a firewall can permit that with a single rule. The File Transfer Protocol cannot be described that way, because the port of the second connection is negotiated inside the first one in plain text.

Firewalls therefore ship an FTP helper: it reads the control conversation, notices the port being agreed, and opens exactly that pinhole for exactly that transfer. This is one of the few places where a stateful firewall deliberately inspects application content in order to do its job.

Two consequences follow.

The first is that file transfers break in exactly the situations where the helper is missing or confused: through a NAT device that does not rewrite the addresses inside the control channel, or through any device that cannot read the conversation.

The second is the part that matters more. Once the control channel is encrypted, as it is with FTPS, the helper cannot read it, and cannot open the pinhole.

Encrypting FTP breaks the mechanism that made FTP work through firewalls, which is why FTPS deployments end with a fixed passive port range configured by hand on both the server and the firewall.

The four namesFTP, FTPS, SFTP and TFTP

Four names, and only two of them are the same protocol.

NamePortConnectionsEncryptedActually FTP
FTP21, plus dataTwoNoYes
FTPS21 or 990, plus dataTwoYes, TLSYes, wrapped
SFTP22OneYes, SSHNo
TFTPUDP 69OneNoNo

Read the last column. Two of these four are FTP and the two people confuse most are not the same protocol at all.

FTP is the original File Transfer Protocol, on port 21, with nothing secure anywhere in it.

FTPS is FTP with TLS added, still using port 21 with an explicit upgrade or port 990 for the implicit form, and still using two channels. It is FTP with a wrapper.

SFTP, the SSH File Transfer Protocol, is not FTP. It is a subsystem of SSH on port 22, and it uses a single connection to the server for everything. The similarity is entirely in the name, which is why an instruction to open port 21 for SFTP is a good sign that somebody has confused the two protocols.

TFTP, the Trivial File Transfer Protocol, is not FTP either. It is a minimal protocol on UDP port 69 with no authentication at all, used for network device configuration and PXE boot, and it belongs on a management segment and nowhere else.

The practical rule is short. If somebody needs to transfer files today, they want SFTP, which is one connection to one server on one port, secure by default, and already permitted wherever SSH is.

What to doWhat to do about port 21 on a network you run

Find out what is listening. Port 21 open on a server usually predates whoever is asking. The question is which clients still connect to it and why.

Assume the credentials are compromised if it faces the internet. FTP sends the username and password in plaintext. Any device on the path has had them.

Move the file transfers to SFTP. One connection, no helper, no passive range, secure by default, and it inherits the SSH access controls that already exist.

If FTPS is genuinely required, fix the passive port range on the file server, allow that exact range on the firewall, and document both. The alternative is a helper that cannot read the channel and a service that fails intermittently.

Never leave TFTP reachable. No authentication is not an exaggeration; it is the specification.

PitfallsWhere people go wrong

Opening port 21 and expecting file transfers to work. The control channel connects, authentication succeeds and the data channel is somewhere else entirely. This is the most common FTP support call there is.

Confusing SFTP with FTPS. Different protocols, different ports, different security models. Only one of them is FTP.

Encrypting FTP and keeping the firewall helper. The helper reads plaintext. Encrypt the control channel and it is blind, and the fix is a fixed port range rather than a setting.

Using active mode from behind NAT. The server cannot reach back. Passive mode exists for this reason and is the default in every modern client.

Treating port 21 as a legacy curiosity. It is still in scanner output, still in old appliances and still in scheduled file transfer jobs nobody owns, and it is still plaintext.

Assuming a VPN makes FTP safe. It protects the traffic on the tunnel. The credentials are still plaintext at both ends and still stored in whatever script is calling it.

WHY THE LOGIN WORKS AND THE LISTING HANGSTwo connections, and only one of them changes direction.Activethe old defaultClientServerNATfirewallcontrol, to port 21data, from port 20, inboundblocked herePassivethe modern oneClientServerNATfirewallcontrol, to port 21data, to a high port, outboundpermitted, like everything elseThe login succeeds in both, because the login happens on the control connection.
One arrow changed direction between the panels. That is the entire difference between active and passive FTP, and the entire reason one of them stopped working.

ComparisonActive and passive FTP, and who opens the second connection

CriterionActive modePassive mode
Who opens the data connectionThe serverThe client
To which portA port the client namedA port the server named
Server source port20A high port
Works from behind NATNoYes
Works through a client firewallNo, it is an inbound connectionYes
Needs an open range on the serverNoYes
The modern defaultRarelyAlmost always

The two modes differ in a single decision: who opens the data connection. Read the fourth row, because it is the reason passive mode won. In active mode the server connects back to the client to deliver the file.

A client behind NAT or a firewall has no reachable address for the server to reach, so the transfer stalls after the control channel said everything was fine. That is the classic FTP fault: a login that works, a directory listing that hangs.

In passive mode the client makes both connections, which any firewall permits outbound, and the burden moves to the file server: it must publish a range of high ports and the firewall in front of the server must allow them.

FAQFrequently asked questions

What is port 21 used for?

The FTP control channel. Commands and replies travel over it; the files themselves use a separate connection to the server, opened for each transfer.

Does FTP use port 20 or 21?

Both, in active mode. Port 21 carries the commands and port 20 is the server source port for data. In passive mode the data connection uses a high numbered port instead.

What is the difference between active and passive FTP?

Who opens the data connection. In active mode the server connects back to the client, which fails through NAT. In passive mode the client opens both, which is why it is the modern default.

Why does my FTP login work but the file listing hang?

Almost always a data channel problem. The control connection on port 21 succeeded and the second connection did not, usually because active mode is in use behind NAT or a firewall.

Is FTP secure?

No. Credentials and file contents travel in plaintext, so anything on the path can read both. Nothing about the File Transfer Protocol is secure, and that is a property of the protocol rather than a configuration mistake.

What is the difference between FTPS and SFTP?

FTPS is FTP with TLS, still two channels, still on port 21 or 990. SFTP is a subsystem of SSH on port 22 with a single connection. Only the first one is FTP.

Should I still use FTP?

Not for anything new. SFTP transfers the same files over one secure connection to the same server, on a port that is already open where SSH is allowed.

Why does the File Transfer Protocol need special firewall handling?

Because the port of the data connection is negotiated inside the control conversation. A firewall has to read that conversation to know which port to open, which is why FTP helpers exist.

What happens to the FTP helper when I use FTPS?

It stops working, because the control channel it was reading is now encrypted. Fixing a passive port range and allowing it explicitly is the standard answer.

What port does SFTP use?

Port 22, the same as SSH, because SFTP is part of SSH rather than a variant of FTP.

What is TFTP and what port does it use?

The Trivial File Transfer Protocol, on UDP port 69. It has no authentication and is used for device configuration and network boot, which is why it belongs only on a management network.

Can I change the FTP port?

The control port can be moved, and clients then have to be told. It changes nothing about the plaintext credentials or the second connection, so it solves neither real problem.

Is port 21 open by default anywhere?

Not on modern operating systems. It appears on old network appliances, on legacy application servers, and in vendor images nobody audited, which is where scanners tend to find it.

How do I check whether port 21 is open?

A port scan from outside answers it for the internet facing case, and the listening socket list on the host answers it locally. The follow up question, what still uses it, takes longer to answer than the scan.

What is the state of FTP security?

Plain FTP has none: the username, password and files all cross the network unencrypted. FTP security comes from replacing it with SFTP, which runs over SSH on port 22, or FTPS, which adds TLS to FTP. SFTP is usually easier because it needs one port and passes through firewalls cleanly.

Read next · Protocols Telnet, Why SSH Replaced It, and the One Job It Kept The same story on a different port: a plaintext protocol from the same era, replaced by an SSH one for the same reason. Open this next9 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.