English
+370 5 205 5502 sales@monovm.com

What is SFTP Port Number? [Secure File Transfer Protocol]

Do you know what is SFTP port number? Why it is important to know about it, During this article you will know about SFTP Port or SFTP Port Number.

16 Jun, 22 by Susith Nonis 15 min Read

List of content you will read in this article:

Today, the internet has become more prone to threats and hacker attacks, thus making it challenging to transfer crucial data. SFTP reduces the risks and has made it more accessible for people to transmit high-end and critical data from one server to another. Several protocols ensure secured file transfer; one commonly used protocol is SFTP, also popularly known as SSH file transfer protocol. You can either use its GUI wizard to transmit or execute command-line SFTP commands to serve the same purpose.

In this article, we will be focusing on what SFTP (client/server) is, how it works, its features, advantages, disadvantages, how it is different from FTP, how to change the default SFTP port number, and some commonly used SFTP client software. Not only this, we will cover some of the frequently used SFTP commands that will help you to transfer data without actually logging into the server manually.

SFTP refers to SSH file transfer protocol or secure file transfer protocol. This protocol is used at the network layer to securely access, manage the files, and transmit the data within the network. It allows two users to share data within a client-server architecture securely.

The data connection used for transmission should be protected with appropriate authentication standards and passwords. The SFTP generally uses the TCP port number 22 by default (also known as the SSH default port), but you can change it to another port number available to assign. SSH-2 version is incorporated into the SFTP, ensuring an encrypted and secured transport layer where the user can run the SFTP commands to transfer the data.

SFTP is used on both the client and server sides, and we also need to understand them. It works much faster than the simple file transfer protocol because it is a packet-based protocol. Also, with SFTP, the mainstream connection is used to transmit the data, thus not requiring a separate connection as required in FTP for file transfer.

As we have mentioned above, the secure file transfer protocol is based on the client-server architecture; it will require one client program and one server software.

To set up the SFTP server connection, the user will require a web server with proper Internet support with SFTP port number 22, essential for your system’s secure file transfer protocol server.

Whenever you install the SFTP server software on your system, it will generate the SSH key for the host that will allow the user to create and grant permissions to the other users and groups to access the system for transferring the data. The SFTP is supported by all operating systems, such as Windows, Linux, Mac OSX, and other operating system.

The SFTP client can be a graphical interface or command-line software allowing you to connect to the SFTP server and perform various tasks. Using this software, the user can connect, authenticate, and transmit the data securely within an encrypted network. By default, the SFTP server will have a port number of 22.

You can consider the below image showing the SSH session for communicating and exchanging data between the server and the client.

But, before you connect to the SFTP server via the SFTP client, you need to configure the following settings on the desktop for your SFTP client.

  • The hostname of the server- hostname or IP address of the server.
  • Port number- specify the TCP port on which the client will connect; the default SFTP port number is 22.
  • Security protocol- you can choose your security protocol to make the connection, such as SFTP/TCP/SC.
  • username- specifies the username of the SFTP client through which you want to establish the connection to the server.
  • Password- it is the password of the particular username that you use.

Suppose you establish the connection to a specific server for the first time. In that case, the server will generate a host key and provide it for the transfer to the client to authenticate the connection. After that, whenever you connect to that server, the connection will establish without confirmation.

The default SFTP port number is 22; while establishing a secured connection between the client and the server. But if you want to change the port settings to another port number, you can change the default settings accordingly. We will see the sites later in this article.

SFTP uses TCP, a connection-oriented protocol allowing both the devices to verify the connection before sending or receiving the files over the network. TCP ensures this using the three-way handshaking process. This process requires two systems, where one sends the data, and the other receives the data. 

The handshaking process involves the following steps-

  • The sending device starts by sending an SYN message.
  • After that, the receiver will acknowledge that message back to the sender.
  • Then the sender device will again send an acknowledgment received message to the receiver.

This process ensures that both devices are ready to make the transfer. Other steps are performed by establishing an SSH connection to secure this transfer. Below are the standard steps to establish an SSH connection.

  • By default, the SSH will use port 22, and the client starts the connection by verifying the server’s identity. Either the client is connecting to the server for the first time, requiring manual verification of the server’s public key. Another case is the client has already established the connection without user involvement.
  • Both the devices agree on the session key to encrypt and decrypt the data. The key is randomly generated.
  • The server will use the SSH key pair to authenticate the client. The critical pair combines the public key (known to both the parties) and the private key (known to the right client).

Check here to fix the SSL handshake failed error if you get an error message. 

Some fantastic features make SFTP more secure than FTP. SFTP comes with two different authentication methods, such as securing data using ID and password or SSH keys; it is up to you what method you want to apply SFTP adds another security level by encrypting the authentication credentials and data. 

Also, your SFTP server generates a public-private key combination shared with the client. 

SFTP does not only solve your purpose of transferring the files but also for accessing remote servers. As a result, SFTP clients help to resume interrupted transfers, access directory listings, etc.

SFTP comes with the support for IPv6 HTTP, TMUX, etc. you can also get enhanced functionality to upload and download the data. 

Not only this, SFTP allows the user to execute commands locally or on the remote server. You can transmit the data by compressing it to exceed the transfer limit.

Below is the usage of SFTP.

  • You can use SFTP to transfer sensitive data between two devices/hosts/servers, such as sharing data within institutions, government bodies, etc.
  • You can also use it to run and share the audit report across several organizations and regulatory bodies.
  • You can also use the SFTP tool for creating, deleting, importing, and exporting files and directories. You can leverage its capability of storing and sharing big data files along with the flexibility to access them from anywhere using appropriate credentials.
  • SFTP is widely used within cloud computing via applications, such as SEEBURGER and Cyberduck.
  • Some commonly used SFTP clients are Filezilla and WinSCP, which are very popular among organizations for managing and sharing files.
  • You can even share files secretly between two hosts by adding an extra security level to authenticate the processes.

Implementing SFTP within your organization has several advantages to securing your data transmission.

  • With SFTP, the users’ credentials are encrypted, making it more secure.
  • SFTP ensures key-based authentication to add another level of security using usernames and passwords, making SFTP more secure.
  • SFTP ensures security by only using one server connection to transfer data without opening other server ports.
  • It provides you with detailed information about the files being transferred, such as date, time, and size, helping you with debugging process.

Using SFTP is not all about its advantages; you also have to face some limitations while using SFTP. Below are some that you must consider.

  • Managing SSH keys is not as easy as it seems.
  • You need to store the private keys on the device you are transferring the files to protect them against theft or loss.
  • You will require a system administrator for setting the SSH keys.
  • You need to know how SSH works and execute the right commands on the command-line terminal.

Parameter

FTP

SFTP

Stands For

File Transfer Protocol

Secure or SSH File Transfer Protocol

Meaning 

Open-source protocol to transfer the file between the two hosts.

It offers a secure SSH channel to transfer the file securely between client and server.

Encryption

Do not support encryption.

It supports encryption by generating the encryption key before the data transfers.

Channel Used

Two different channels are used, one for control and another for transferring the data.

It uses the same channel for both control and data transmission.

Port Used

by default TCP port number is 21

by default TCP port is 22, but you can configure it on 2222 or 2200.

Architecture Used

Based on Client-server architecture.

The SSH architecture is used.

File transfer topology

It uses a direct file transfer methodology between the hosts and between clients.

It uses the tunneling topology to transfer files between the host and server machine and the encryption method.

By default, the value of the SFTP port number is 22. But, if you change this default value to another, it will make it difficult for hackers to hack your data transmission and reduce the risk. You can go through the following steps to change the port number. 

Step 1: Choose a New Port Number

In a Linux machine, you cannot use the port numbers below 1024 as they are reserved for well-known services. You can use a port number within the range of 1-1024 for the SSH service, but it is recommended to choose a value above 1024.

In the below example, we use the value 4433 for the SFTP port. You can choose any other number if 4433 is already taken.

Step 2: Adjusting Firewall

But before you change the SFTP port number, make sure to open a new port in your firewall. If you are using a UFW firewall, you can use the following command to open a new port.

Ubuntu machine-

sudo ufw allow 4433/tcp

CentOS machine (firewall management tool is FirewallD)-

sudo firewall-cmd --permanent --zone=public --add-port=4433/tcp

sudo firewall-cmd --reload

You also have to adjust the SELinux rules to add a new SSH port using the below command for the CentOS machine.

sudo semanage port -a -t ssh_port_t -p tcp 4433

Step 3: Configure SFTP/SSH

The SSH server configuration file is stored in the /etc/ssh/sshd_config file. For making changes, you need to open the file with your text editor:

sudo vim /etc/ssh/sshd_config

Then look for port 22. Remove the # from the beginning and enter the new SSH port number as shown below.

Port 4433

Step 4: Restart the SSH service

Once you are done with the required changes, you need to restart the SSH services to make the change in effect. You can run the following command to restart the SSH server.

sudo systemctl restart ssh

In CentOS, the SSH service is named SSHD, follow the below-listed centos command.

sudo systemctl restart sshd

Step 5: Verify that the SSH daemon is listening on the new port:

ss -an | grep 4433

There are several SFTP client tools that you can use to connect to the remote SSH server securely and perform various tasks, such as copying, deleting, pasting, uploading, and downloading files. We have mentioned some of the commonly used SFTP clients below for your reference.

1. FileZilla

Filezilla is a free and GUI-based FTP client software. You can use this software on various operating systems, such as Windows, Linux, and Mac OS, but the server is only compatible with Windows. It comes with FTP, SFTP, and IPv6 protocols. You can pause and resume the file transfer as per the requirement. It comes with the drag and drops feature for quick uploading and downloading files. 

2. WinSCP

Windows Secure Copy (WinSCP) is available as a free SFTP and FTP client for Windows operating system. You can simply use this software to transfer the files between the host computer and the remote server. Similar to FileZilla, WinSCP also has drag and drop features for quick uploading and downloading files. You can integrate this software with the PuTTY authentication agent to support SSH.

3. Solarwinds FTP Voyager Client

It is another free and open-source FTP client for securely transferring the file via FTP, SFTP, and FTPS. It lets you connect to multiple servers simultaneously to transfer files and thus handle multiple processes using a single instance. It helps synchronize the folders automatically and schedule file transfer with allocated time.

SFTP has secured all the communication across the network. It adds another security level by authenticating the credentials of the logging client or using SSH keys. Understanding the needs of the SFTP is essential for the business dealing with the transmission of critical and personal data. Implementing and setting SFTP requires technical knowledge and command-line commands. In this article, you have received a lot of information about the default SFTP port number or what is SFTP port, and how to change the default SFTP port number. Also, you can easily choose from the most commonly used SFTP clients to establish a secure connection to the SSH remote server and perform tasks accordingly. we have also given you a little bit of information about the best SFTP client software available in the market, if you have any other suggestions about the SFTP port number you can comment in the comment box. we also offer SSH server you can buy them from MonoVM.

 People also read: 

Susith Nonis

I'm fascinated by the IT world and how the 1's and 0's work. While I veture into the world of Technology I try to share what I know in the simplest way possible. Not a fan of coffee, a sweet addict and a self accredited 'master chef'.