How to Set Up a Personal FTP Server on Windows 11 With FileZilla

Ā·
8 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

If running your own file-transfer server from a Windows 11 machine has ever crossed your mind, FileZilla Server is worth a look. It’s free, actively maintained in 2026, and can have you sharing files in under 20 minutes. Plain FTP sends credentials in cleartext, so this guide focuses on FTPS (FTP over TLS), which encrypts the connection from end to end.

What You’ll Need

  • A Windows 10 or Windows 11 PC with local administrator rights
  • A stable local IP address; configure a DHCP reservation on your home router or set a static IP directly on the server machine
  • For external access: port-forwarding control on your router, and a heads-up that some ISPs block inbound connections on port 21

What Is FileZilla Server?

FileZilla Server is the server-side companion to the well-known FileZilla Client. It runs as a Windows service, lets you create named user accounts with per-folder permissions, and accepts FTPS or plain FTP connections from clients on your LAN or over the internet. It’s free, open-source, and available from the FileZilla Project website.

Step 1: Download and Install FileZilla Server

  1. Go to the FileZilla Project website and download the latest FileZilla Server installer for Windows.
  2. Run the installer. When asked for the setup type, choose Full installation.
  3. On the startup settings screen, decide how the service runs:

– Automatic (start at Windows boot): best for a machine that’s always on. – Manual: starts only when you open the interface, which is more sensible for occasional personal use.

  1. Set the administration interface port (the default in current 1.x releases is 14148; the old 0.9.x server used 14147). This port is for managing the server only, not for FTP client connections.
  2. Finish the installation and launch FileZilla Server Interface.
FileZilla Server installer showing the Startup settings screen with service start type options and administration port field highlighted
  1. On the connection dialog, Host will be prefilled as localhost or 127.0.0.1 and the port will match what you chose in step 4. Click Connect.
  2. When prompted, set an administration password. Don’t leave it blank on a shared machine.
FileZilla Server initial connection dialog with localhost host and admin port prefilled, Connect button visible

After connecting, the main status console appears and shows the server’s activity log.

FileZilla Server main interface showing the server status log after a successful local connection

Step 2: Configure the Server Listener

This tells FileZilla Server which IP address and port to accept incoming FTP connections on.

  1. Click Server in the menu bar, then select Configure… (or press Ctrl + F).
  2. In the left panel, select Server listeners. A new install already has a listener on port 21.
  3. Set the Address:

– 0.0.0.0 to listen on all IPv4 interfaces, which is fine for most setups. – Or your server’s local IP (e.g., 192.168.1.10) for tighter control.

  1. Set the Port:

– 21 is the standard FTP/FTPS port. – If your ISP blocks port 21, try 2121 instead. Update your router’s port-forwarding rule and tell clients which port to use.

  1. In the Protocol column, keep Require explicit FTP over TLS, which is the default on new installs. Avoid Explicit FTP over TLS and insecure plain FTP unless an old device genuinely can’t use TLS.
  2. Click OK or Apply.
FileZilla Server Configure dialog open to Connection / Server Listeners with Address set to 0.0.0.0 and Port set to 21

Step 3: Enable FTPS Encryption

Plain FTP is acceptable for a quick test on a local LAN you control, but use it beyond that at your own risk. FTPS with Explicit TLS encrypts both login credentials and file data, making it the smooth, practical choice for home setups.

  1. In Configure…, go to Protocol settings > FTP and FTP over TLS (FTPS) and open the Connection security tab.
  2. Set the minimum TLS version to TLS 1.2 or higher.
  3. FileZilla Server creates a self-signed certificate during installation. To make a fresh one, click Generate new and enter your server’s hostname or local IP when asked.
  4. Check that your listener from Step 2 still says Require explicit FTP over TLS. Clients connect on port 21, then negotiate TLS encryption before logging in. This is the setting that actually makes the server secure: no TLS, no login.
  5. Click OK or Apply.
FileZilla Server FTP over TLS settings panel with Enable FTPS checked, Explicit TLS selected, Disallow plain unencrypted FTP checked, and certificate path fields visible

Self-signed certificate warning: Clients will see a certificate warning the first time they connect. That’s expected. Accept the certificate in your FTP client and it won’t prompt again.

Step 4: Set Up Passive Mode

Passive mode is what makes FTP actually work through NAT and firewalls, which covers nearly every home setup. Without it, clients connect but directory listings hang.

  1. In Configure…, go to Protocol settings > FTP and FTP over TLS (FTPS) and open the Passive mode tab.
  2. Check Use custom port range and enter a range for passive data connections. The default is 49152–65534, but a smaller range like 30000–31000 is plenty for home use.
  3. If clients will connect from outside your LAN, enter your public IP address in the external IP field. FileZilla can retrieve it automatically if you prefer.
  4. Click OK or Apply.
  5. On your home router:

– Forward TCP port 21 (or your chosen FTP port) to your server’s local IP address. – Forward the passive port range (e.g., TCP 30000–31000) to the same local IP.

FileZilla Server Passive mode settings panel with port range 30000-31000 entered and external IP address field visible

Step 5: Create Users and Assign Shared Folders

  1. In Configure…, go to Rights management > Users.
  2. Click Add and enter a username.
  3. Set a strong password for the account.
FileZilla Server user management panel showing the Add button and username entry field
  1. Under Mount points, click Add. Enter / as the Virtual path (the folder the user sees when they log in) and the folder you want to share as the Native path, such as D:\FTPRoot\username or a dedicated folder on an external hard drive.
  2. Set the Access mode for the mount point:

– Read only: lets the user list and download files without changing anything. – Read + Write: also lets the user upload, rename, and delete files. – Uncheck Writable directory structure if the user shouldn’t create, rename, or delete folders.

FileZilla Server shared folders panel showing a selected folder with Read, Write, Append, and Delete permission checkboxes
  1. In the Speed Limits section, set per-user download and upload caps if you don’t want FTP transfers saturating your connection.
FileZilla Server Speed Limits panel with upload and download speed limit fields
  1. Enable IP filters to whitelist or block specific IP addresses from connecting.
FileZilla Server IP filter panel showing separate allow-list and deny-list fields for IP addresses
  1. Click OK to save.

Step 6: Open Windows Defender Firewall

Don’t disable Windows Defender Firewall entirely. A targeted inbound rule is all you need.

  1. Open Start, search for Windows Defender Firewall with Advanced Security, and open it.
  2. Click Inbound Rules in the left panel, then New Rule… on the right.
  3. Select Port and click Next.
  4. Choose TCP and enter your FTP port (21 or custom) plus your passive port range (e.g., 21, 30000-31000) in the port field.
  5. Select Allow the connection and click Next.
  6. Check Domain and Private. Uncheck Public unless you specifically need external internet inbound traffic on this rule.
  7. Name the rule, something like FileZilla FTP Server, and click Finish.
Windows Defender Firewall with Advanced Security showing the New Inbound Rule wizard on the Protocol and Ports step with TCP selected and port 21 plus passive range 30000-31000 entered

Step 7: Connect and Test

Browsers dropped FTP support years ago, so you need a proper FTP client. FileZilla Client from the FileZilla Project website is the obvious pick.

  1. Open FileZilla Client and go to File > Site Manager…, then click New Site.
  2. Configure the connection:

– Protocol: FTP – Host: your server’s local IP (for LAN testing) or public IP (for internet access) – Port: 21 or your custom port – Encryption: Require explicit FTP over TLS, which matches what you set in Step 3 – Logon Type: Normal – User / Password: the credentials you created in Step 5

  1. Click Connect.
  2. Accept the self-signed certificate when prompted.
  3. Confirm the shared folder’s contents appear in the right pane.
FileZilla Client Site Manager showing FTP protocol, host and port filled, Require explicit FTP over TLS encryption option selected, and Normal logon type with username field

If the directory listing loads and you can drag a test file in and see it appear, the server is working.

Troubleshooting Common Issues

Connection times out or refuses

  • Firewall rule missing or incomplete: Confirm the inbound rule covers both port 21 and the full passive range.
  • Router port forwarding wrong: Check that TCP 21 and the passive range both point to the correct local IP of the server machine.
  • ISP blocking port 21: Switch to an alternative port like 2121, update the port-forwarding rule on your router, and update the port in FileZilla Server’s listener settings and in your client’s site profile.

Login succeeds but directory listing hangs

Passive mode is misconfigured. Confirm the passive port range in FileZilla Server matches what you forwarded on the router, and that the external IP field in passive mode settings shows your actual public IP, not a local address.

Can log in but can’t upload or delete

Two places to check:

  • FileZilla user permissions: The mount point’s Access mode must be Read + Write in the user settings.
  • NTFS permissions: Right-click the shared folder in File Explorer, go to Properties > Security, and confirm the account running FileZilla Server has write access to that folder.

Self-signed certificate error won’t clear

Accept the certificate in FileZilla Client’s Site Manager and check the option to always trust it. If the warning persists, click Generate new on the Connection security tab and reconnect; the client will prompt you to accept the new one.

Works on LAN but fails from outside

Test from a mobile phone on its cellular data connection (not your Wi-Fi) to rule out router NAT loopback. If that still fails, recheck port forwarding. If your ISP uses CGNAT (carrier-grade NAT), inbound port forwarding won’t work at all, so contact your ISP or consider routing through a VPS.

Alternatives Worth Knowing

FileZilla Server fits LAN environments, lab setups, and hardware like IP cameras or NAS devices that require FTP specifically. For general secure file sharing, two other options are worth bookmarking:

  • OpenSSH Server (built into Windows 10/11): Enables SFTP over SSH, which is simpler to firewall than FTPS. Go to Settings > System > Optional features, select View features (Add a feature on Windows 10), and search for OpenSSH Server.
  • Cloud storage: For sharing files with people who aren’t comfortable with FTP clients, a cloud service handles access control and encryption without any port-forwarding headaches.

Conclusion

Steps 1–5 get you an FTPS server that actually works, using a free, actively maintained tool. If connections drop or listings hang, passive mode (Step 4) and the matching router port-forwarding rules fix it almost every time. It’s a good fit if you’re hitting cloud storage limits or want self-hosted file sharing on your own hardware.