Network and System AdministrationUnit 814 min read
File Transfer Protocols: FTP, SFTP, TFTP, HTTP/HTTPS, NFS, SCP
Unit 8 of Network and System Administration explores file transfer protocols, their working principles, security mechanisms, and real-world applications in data exchange, remote administration, and cloud services. This note covers FTP (File Transfer Protocol), its variants (SFTP, FTPS), TFTP, HTTP/HTTPS, NFS, and SCP,
TAKEAWAYS:
- Understand FTP’s architecture (client-server, control/data channels, port 20/21) and its anonymous vs. authenticated modes.
- Compare FTP variants (SFTP, FTPS, FTPS-ES) by security, encryption, and use cases (e.g., SFTP for eSewa’s KYC uploads).
- Trace TFTP’s simplicity (UDP, no authentication, port 69) and its role in booting routers or IoT device firmware updates.
- Analyze HTTP/HTTPS as application-layer protocols for web file transfers, with TLS handshakes and Daraz’s checkout process as examples.
- Differentiate NFS (network-attached storage) and SCP (Secure Copy Protocol) for Linux-based file transfers, using NTC’s server logs as a case study.
- Apply bandwidth and latency trade-offs in file transfers, e.g., compressing large files for Pathao’s driver app updates.
Core Concepts: File Transfer Protocols
File transfer protocols enable reliable, structured movement of files between systems over networks. They operate at the application layer (Layer 7) of the OSI model but rely on lower layers (TCP/UDP, IP) for delivery. Below are the key protocols covered in this unit, categorized by security, use case, and underlying transport mechanism.
Layered Model for File Transfers
┌───────────────────────────────────────────────────┐
│ Application Layer (File Transfer) │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ FTP │ │ SFTP │ │ HTTP/HTTPS│ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ TFTP │ │ NFS │ │ SCP │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└───────────────────────────────────────────────────┘
┌───────────────────────────────────────────────────┐
│ Transport Layer (TCP/UDP) │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ TCP │ │ UDP │ │ (Reliable)│ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└───────────────────────────────────────────────────┘
┌───────────────────────────────────────────────────┐
│ Internet Layer (IP) │
└───────────────────────────────────────────────────┘
Key Idea: FTP and HTTP use TCP (reliable, connection-oriented), while TFTP uses UDP (faster, no handshake).
1. File Transfer Protocol (FTP)
FTP is the oldest and most basic protocol for transferring files between a client and server. It uses two separate channels:
- Control channel (port 21): Sends commands (e.g.,
USER,PASS,RETR,STOR). - Data channel (port 20): Transfers actual file data.
How FTP Works: A Step-by-Step Trace
sequenceDiagram
participant Client as FTP Client (e.g., FileZilla)
participant Server as FTP Server (e.g., Daraz's inventory server)
Client->>Server: 1. Connect to port 21 (control channel)
Server-->>Client: 2. Send 220 "Service ready" banner
Client->>Server: 3. USER anonymous (or username)
Server-->>Client: 4. 331 "Password required"
Client->>Server: 5. PASS (password or email for anonymous)
Server-->>Client: 6. 230 "Login successful"
Client->>Server: 7. SYST (check OS type)
Client->>Server: 8. TYPE I (binary transfer)
Client->>Server: 9. PORT 192,168,1,2,5,6 (data channel IP:port)
Client->>Server: 10. RETR file.txt (download)
Server->>Client: 11. Open data channel (port 20) and send file
Client->>Server: 12. QUIT
Server-->>Client: 13. 221 "Goodbye"FTP Packet Format (Control Channel)
┌───────────────────────────────────────────────────┐
│ Command (e.g., "RETR filename.txt") │
├───────────────────────────────────────────────────┤
│ Response Code (e.g., 226 "Transfer complete") │
└───────────────────────────────────────────────────┘
Example: When you download a file from an FTP server, the RETR command triggers the data transfer.
Anonymous FTP
- Uses
anonymousas username and email as password (often just a placeholder likeuser@example.com). - Restricted to read-only access in most cases.
- Real-world use: Old university courseware repositories or public software archives.
Advantages and Disadvantages
| Advantages | Disadvantages |
|---|---|
| Simple to implement | No encryption (passwords/credentials sent in plaintext) |
| Supports large file transfers | Port 21/20 often blocked by firewalls |
| Works across platforms | No built-in security (requires FTPS/SFTP) |
2. Secure FTP Variants
FTP’s lack of encryption led to three secure alternatives:
A. SFTP (SSH File Transfer Protocol)
- Runs over SSH (port 22), encrypting both control and data channels.
- Uses public-key cryptography for authentication.
- Command example:
sftp user@server.example.com put localfile.txt remote/ - Real-world example: eSewa uses SFTP to securely upload KYC documents (citizen photos, citizenship certificates) from mobile apps to their servers.
B. FTPS (FTP Secure)
- Extends FTP with TLS/SSL (ports 990 for explicit, 21 for implicit).
- Two modes:
- Explicit FTPS: Client initiates TLS after connecting to port 21.
- Implicit FTPS: Server forces TLS on port 990.
- Real-world example: Banks like NMB use FTPS to transfer large transaction logs between branches.
C. FTPS-ES (FTP over TLS with Explicit Start)
- Similar to explicit FTPS but optimized for high-speed transfers (used in cloud backups).
- Example: Daraz’s warehouse management system uses FTPS-ES to sync inventory files with suppliers.
Comparison Table
| Feature | FTP | SFTP | FTPS (Explicit) | FTPS (Implicit) |
|---|---|---|---|---|
| Encryption | ❌ | ✅ (SSH) | ✅ (TLS) | ✅ (TLS) |
| Port | 21 | 22 | 21 (then 990) | 990 |
| Authentication | Plaintext | SSH keys/Password | TLS certs | TLS certs |
| Firewall-friendly | ❌ (ports 20/21) | ✅ (port 22) | ❌ (dynamic ports) | ✅ (port 990) |
| Use Case | Legacy systems | Secure Linux transfers | Enterprise file sharing | Legacy FTP upgrades |
3. Trivial File Transfer Protocol (TFTP)
- UDP-based (port 69), no authentication, no directory listing.
- Used for small files (e.g., booting routers, IoT firmware updates).
- Packet format:
┌───────────────────────────────────────────────────┐ │ Opcode (1 or 2) | Filename (max 512 bytes) │ │ 0 Pad | Mode (e.g., "octet", "netascii") │ └───────────────────────────────────────────────────┘ - Example: A Cisco router downloads its IOS image via TFTP from a server.
TFTP Workflow
sequenceDiagram
participant Client as Router (TFTP Client)
participant Server as TFTP Server (e.g., NTC's firmware repo)
Client->>Server: 1. RRQ (Read Request): filename=ios.bin, mode=octet
Server-->>Client: 2. ACK (Block 0)
Server->>Client: 3. DATA (Block 0, 512 bytes)
Client-->>Server: 4. ACK (Block 0)
Server->>Client: 5. DATA (Block 1, ...)
Client-->>Server: 6. ACK (Block 1)
...
Server->>Client: N. DATA (Last block, <512 bytes)
Client-->>Server: N+1. ACK (Last block)When to Use TFTP
- Pros: Fast (no handshake), low overhead.
- Cons: No security, no resume capability.
- Real-world use: Ncell’s base stations fetch configuration files via TFTP during nightly updates.
4. HTTP/HTTPS for File Transfers
While HTTP/HTTPS are primarily for web content, they are also used for file transfers:
- HTTP (port 80): Unencrypted (e.g., old software download links).
- HTTPS (port 443): Encrypted with TLS (e.g., Google Drive downloads).
TLS Handshake for HTTPS File Downloads
sequenceDiagram
participant Client as Browser (e.g., downloading a PDF)
participant Server as Web Server (e.g., NEPSE's annual report)
Client->>Server: 1. ClientHello (TLS version, cipher suites)
Server-->>Client: 2. ServerHello + Certificate
Client->>Server: 3. Key Exchange (pre-master secret)
Client->>Server: 4. Finished (encrypted)
Server-->>Client: 5. Finished (encrypted)
Client->>Server: 6. GET /reports/2023.pdf HTTP/1.1
Server-->>Client: 7. 200 OK + File (encrypted)Real-world Example: Daraz’s Checkout Process
- User adds items to cart → HTTP request to Daraz’s server.
- Server responds with HTTPS (encrypted) for payment gateway (eSewa/Khalti).
- After payment, Daraz sends a download link (HTTPS) for the order confirmation PDF.
5. Network File System (NFS)
- Linux/Unix protocol for shared file systems over a network.
- Uses RPC (Remote Procedure Call) and port 2049.
- Example: NTC’s central logging server exports
/var/logto all regional offices via NFS.
NFS Mount Command
mount -t nfs server.example.com:/shared/folder /local/mount/point
NFS vs. FTP/SFTP
| Feature | NFS | FTP/SFTP |
|---|---|---|
| Protocol | RPC over UDP/TCP | TCP |
| Use Case | Shared home directories | One-off file transfers |
| Performance | High (cached metadata) | Moderate (per-file overhead) |
| Security | Kerberos/RPCSEC_GSS | SSH/TLS |
6. Secure Copy Protocol (SCP)
- SSH-based file transfer (port 22).
- Command example:
scp file.txt user@server:/remote/path/ - Real-world use: NTC engineers use SCP to copy configuration files from a central server to remote switches.
SCP vs. SFTP
| Feature | SCP | SFTP |
|---|---|---|
| Protocol | SSH (single command) | SSH (interactive session) |
| Use Case | Scripted transfers | Interactive file management |
| Speed | Faster (no session overhead) | Slower (per-command SSH) |
In the Real World
eSewa’s KYC Uploads
- Protocol: SFTP (over SSH).
- How it works: When you upload your citizenship certificate, your phone app encrypts the file with SFTP and sends it to eSewa’s servers. The server verifies the file hash before processing.
- Why SFTP? Ensures no third party can intercept your sensitive documents during transfer.
Daraz’s Inventory Sync
- Protocol: FTPS-ES (FTP over TLS).
- How it works: Daraz’s warehouses run scripts nightly to upload inventory CSV files to their cloud servers. FTPS-ES ensures the files are encrypted in transit, even though the data is large (millions of rows).
- Challenge: Daraz had to configure firewalls to allow dynamic data ports (FTPS uses temporary ports >1024).
NTC’s Network Configuration Backups
- Protocol: SCP.
- How it works: Every midnight, NTC’s central server pushes updated router configurations to all regional offices using
scp. This ensures all devices have the latest routing tables for traffic optimization. - Why SCP? Simpler than SFTP for automated, scripted transfers.
Pathao Driver App Updates
- Protocol: HTTP/HTTPS (for app binaries) + TFTP (for small config files).
- How it works:
- Drivers download the main app update via HTTPS (encrypted).
- Small configuration tweaks (e.g., fare matrix updates) are fetched via TFTP during idle periods to save bandwidth.
- Trade-off: TFTP is faster for tiny files but unencrypted; HTTPS is slower but secure.
Worked Example: Calculating FTP Transfer Time
Scenario: A Daraz warehouse needs to upload a 500 MB inventory file to their cloud server. The network has:
- Bandwidth: 10 Mbps (1.25 MB/s).
- FTP overhead: 10% (due to acknowledgments and retries).
- Latency: 50 ms (round-trip time).
Steps:
Calculate effective bandwidth: .
Time for data transfer: .
Add latency overhead:
- Each FTP packet (e.g., 1460 bytes) requires an ACK, adding per packet.
- Number of packets: packets.
- Total latency overhead: .
- Note: This is an overestimation because modern FTP uses parallel transfers (multiple data channels). With 10 parallel channels, the latency overhead drops to ~59 minutes.
Real-world fix: Daraz uses compression (e.g., gzip) to reduce file size by 30%, cutting transfer time to ~5 minutes.
Common Pitfalls and Best Practices
Firewall Rules:
- FTP’s dynamic data ports (20) often get blocked. Use passive mode (
PASV) where the client connects to the server’s data port. - SFTP/SCP (port 22) and FTPS (port 990) are easier to firewall.
- FTP’s dynamic data ports (20) often get blocked. Use passive mode (
Security:
- Never use plain FTP for sensitive data (e.g., medical records, financial files).
- Prefer SFTP for Linux environments or FTPS for Windows/enterprise setups.
Performance:
- For large files, use compression (e.g.,
gzip) or parallel transfers (FTP’sPORTcommand). - TFTP is not suitable for files >1 MB due to packet loss risks.
- For large files, use compression (e.g.,
Automation:
- Use
rsyncover SSH for incremental backups (faster than full SCP transfers). - Example:
rsync -avz -e ssh /local/backup/ user@server:/remote/backup/
- Use
Exam Tip
This unit is conceptual and application-based. Expect:
- Short definitions:
- "Explain FTP’s control and data channels."
- "Differentiate between SFTP and FTPS."
- Scenario-based questions:
- "Why would a bank use FTPS instead of FTP for transferring transaction logs?"
- "How would you configure an FTP server to allow anonymous downloads but restrict uploads?"
- Packet traces:
- Draw a sequence diagram for an SFTP file upload or an FTP
RETRcommand.
- Draw a sequence diagram for an SFTP file upload or an FTP
- Comparison tables:
- Compare TFTP vs. FTP vs. HTTP for a given use case (e.g., router boot files).
- Real-world applications:
- "How does Daraz ensure secure file transfers between warehouses and their cloud servers?"
High-scoring strategies:
- Draw diagrams: Always include a sequence diagram for protocol handshakes (e.g., FTP login, TLS handshake).
- Use examples: Tie answers to Nepalese companies (e.g., "NTC uses SCP for router configs").
- Mention ports: FTP (21/20), SFTP (22), FTPS (990), TFTP (69), HTTP/HTTPS (80/443).
- Security focus: Emphasize encryption (SFTP/FTPS) vs. plaintext (FTP/TFTP).
Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 8.
Discussion
Loading…