If running your own file-transfer server from a Windows 11 machine has ever crossed your mind, FileZilla Server is worth a look. Itās free, actively maintained in 2026, and can have you sharing files in under 20 minutes. Plain FTP sends credentials in cleartext, so this guide focuses on FTPS (FTP over TLS), which encrypts the connection from end to end.
What Youāll Need
- A Windows 10 or Windows 11 PC with local administrator rights
- A stable local IP address; configure a DHCP reservation on your home router or set a static IP directly on the server machine
- For external access: port-forwarding control on your router, and a heads-up that some ISPs block inbound connections on port 21
What Is FileZilla Server?
FileZilla Server is the server-side companion to the well-known FileZilla Client. It runs as a Windows service, lets you create named user accounts with per-folder permissions, and accepts FTPS or plain FTP connections from clients on your LAN or over the internet. Itās free, open-source, and available from the FileZilla Project website.
Step 1: Download and Install FileZilla Server
- Go to the FileZilla Project website and download the latest FileZilla Server installer for Windows.
- Run the installer. When asked for the setup type, choose Full installation.
- On the startup settings screen, decide how the service runs:
ā Automatic (start at Windows boot): best for a machine thatās always on. ā Manual: starts only when you open the interface, which is more sensible for occasional personal use.
- Set the administration interface port (the default in current 1.x releases is 14148; the old 0.9.x server used 14147). This port is for managing the server only, not for FTP client connections.
- Finish the installation and launch FileZilla Server Interface.
- On the connection dialog, Host will be prefilled as
localhostor127.0.0.1and the port will match what you chose in step 4. Click Connect. - When prompted, set an administration password. Donāt leave it blank on a shared machine.
After connecting, the main status console appears and shows the serverās activity log.
Step 2: Configure the Server Listener
This tells FileZilla Server which IP address and port to accept incoming FTP connections on.
- Click Server in the menu bar, then select Configure⦠(or press
Ctrl + F). - In the left panel, select Server listeners. A new install already has a listener on port 21.
- Set the Address:
ā 0.0.0.0 to listen on all IPv4 interfaces, which is fine for most setups.
ā Or your serverās local IP (e.g., 192.168.1.10) for tighter control.
- Set the Port:
ā 21 is the standard FTP/FTPS port. ā If your ISP blocks port 21, try 2121 instead. Update your routerās port-forwarding rule and tell clients which port to use.
- In the Protocol column, keep Require explicit FTP over TLS, which is the default on new installs. Avoid Explicit FTP over TLS and insecure plain FTP unless an old device genuinely canāt use TLS.
- Click OK or Apply.
Step 3: Enable FTPS Encryption
Plain FTP is acceptable for a quick test on a local LAN you control, but use it beyond that at your own risk. FTPS with Explicit TLS encrypts both login credentials and file data, making it the smooth, practical choice for home setups.
- In Configureā¦, go to Protocol settings > FTP and FTP over TLS (FTPS) and open the Connection security tab.
- Set the minimum TLS version to TLS 1.2 or higher.
- FileZilla Server creates a self-signed certificate during installation. To make a fresh one, click Generate new and enter your serverās hostname or local IP when asked.
- Check that your listener from Step 2 still says Require explicit FTP over TLS. Clients connect on port 21, then negotiate TLS encryption before logging in. This is the setting that actually makes the server secure: no TLS, no login.
- Click OK or Apply.
Self-signed certificate warning: Clients will see a certificate warning the first time they connect. Thatās expected. Accept the certificate in your FTP client and it wonāt prompt again.
Step 4: Set Up Passive Mode
Passive mode is what makes FTP actually work through NAT and firewalls, which covers nearly every home setup. Without it, clients connect but directory listings hang.
- In Configureā¦, go to Protocol settings > FTP and FTP over TLS (FTPS) and open the Passive mode tab.
- Check Use custom port range and enter a range for passive data connections. The default is 49152ā65534, but a smaller range like 30000ā31000 is plenty for home use.
- If clients will connect from outside your LAN, enter your public IP address in the external IP field. FileZilla can retrieve it automatically if you prefer.
- Click OK or Apply.
- On your home router:
ā Forward TCP port 21 (or your chosen FTP port) to your serverās local IP address. ā Forward the passive port range (e.g., TCP 30000ā31000) to the same local IP.
Step 5: Create Users and Assign Shared Folders
- In Configureā¦, go to Rights management > Users.
- Click Add and enter a username.
- Set a strong password for the account.
- Under Mount points, click Add. Enter
/as the Virtual path (the folder the user sees when they log in) and the folder you want to share as the Native path, such asD:\FTPRoot\usernameor a dedicated folder on an external hard drive. - Set the Access mode for the mount point:
ā Read only: lets the user list and download files without changing anything. ā Read + Write: also lets the user upload, rename, and delete files. ā Uncheck Writable directory structure if the user shouldnāt create, rename, or delete folders.
- In the Speed Limits section, set per-user download and upload caps if you donāt want FTP transfers saturating your connection.
- Enable IP filters to whitelist or block specific IP addresses from connecting.
- Click OK to save.
Step 6: Open Windows Defender Firewall
Donāt disable Windows Defender Firewall entirely. A targeted inbound rule is all you need.
- Open Start, search for Windows Defender Firewall with Advanced Security, and open it.
- Click Inbound Rules in the left panel, then New Rule⦠on the right.
- Select Port and click Next.
- Choose TCP and enter your FTP port (21 or custom) plus your passive port range (e.g.,
21, 30000-31000) in the port field. - Select Allow the connection and click Next.
- Check Domain and Private. Uncheck Public unless you specifically need external internet inbound traffic on this rule.
- Name the rule, something like FileZilla FTP Server, and click Finish.
Step 7: Connect and Test
Browsers dropped FTP support years ago, so you need a proper FTP client. FileZilla Client from the FileZilla Project website is the obvious pick.
- Open FileZilla Client and go to File > Site Managerā¦, then click New Site.
- Configure the connection:
ā Protocol: FTP ā Host: your serverās local IP (for LAN testing) or public IP (for internet access) ā Port: 21 or your custom port ā Encryption: Require explicit FTP over TLS, which matches what you set in Step 3 ā Logon Type: Normal ā User / Password: the credentials you created in Step 5
- Click Connect.
- Accept the self-signed certificate when prompted.
- Confirm the shared folderās contents appear in the right pane.
If the directory listing loads and you can drag a test file in and see it appear, the server is working.
Troubleshooting Common Issues
Connection times out or refuses
- Firewall rule missing or incomplete: Confirm the inbound rule covers both port 21 and the full passive range.
- Router port forwarding wrong: Check that TCP 21 and the passive range both point to the correct local IP of the server machine.
- ISP blocking port 21: Switch to an alternative port like 2121, update the port-forwarding rule on your router, and update the port in FileZilla Serverās listener settings and in your clientās site profile.
Login succeeds but directory listing hangs
Passive mode is misconfigured. Confirm the passive port range in FileZilla Server matches what you forwarded on the router, and that the external IP field in passive mode settings shows your actual public IP, not a local address.
Can log in but canāt upload or delete
Two places to check:
- FileZilla user permissions: The mount pointās Access mode must be Read + Write in the user settings.
- NTFS permissions: Right-click the shared folder in File Explorer, go to Properties > Security, and confirm the account running FileZilla Server has write access to that folder.
Self-signed certificate error wonāt clear
Accept the certificate in FileZilla Clientās Site Manager and check the option to always trust it. If the warning persists, click Generate new on the Connection security tab and reconnect; the client will prompt you to accept the new one.
Works on LAN but fails from outside
Test from a mobile phone on its cellular data connection (not your Wi-Fi) to rule out router NAT loopback. If that still fails, recheck port forwarding. If your ISP uses CGNAT (carrier-grade NAT), inbound port forwarding wonāt work at all, so contact your ISP or consider routing through a VPS.
Alternatives Worth Knowing
FileZilla Server fits LAN environments, lab setups, and hardware like IP cameras or NAS devices that require FTP specifically. For general secure file sharing, two other options are worth bookmarking:
- OpenSSH Server (built into Windows 10/11): Enables SFTP over SSH, which is simpler to firewall than FTPS. Go to Settings > System > Optional features, select View features (Add a feature on Windows 10), and search for OpenSSH Server.
- Cloud storage: For sharing files with people who arenāt comfortable with FTP clients, a cloud service handles access control and encryption without any port-forwarding headaches.
Conclusion
Steps 1ā5 get you an FTPS server that actually works, using a free, actively maintained tool. If connections drop or listings hang, passive mode (Step 4) and the matching router port-forwarding rules fix it almost every time. Itās a good fit if youāre hitting cloud storage limits or want self-hosted file sharing on your own hardware.