BIT451 Network and System Administration

Network and System AdministrationUnit 814 min read

File Transfer Protocols: FTP, SFTP, TFTP, HTTP/HTTPS, NFS, SCP

Unit 8 of Network and System Administration explores file transfer protocols, their working principles, security mechanisms, and real-world applications in data exchange, remote administration, and cloud services. This note covers FTP (File Transfer Protocol), its variants (SFTP, FTPS), TFTP, HTTP/HTTPS, NFS, and SCP,

TAKEAWAYS:

  • Understand FTP’s architecture (client-server, control/data channels, port 20/21) and its anonymous vs. authenticated modes.
  • Compare FTP variants (SFTP, FTPS, FTPS-ES) by security, encryption, and use cases (e.g., SFTP for eSewa’s KYC uploads).
  • Trace TFTP’s simplicity (UDP, no authentication, port 69) and its role in booting routers or IoT device firmware updates.
  • Analyze HTTP/HTTPS as application-layer protocols for web file transfers, with TLS handshakes and Daraz’s checkout process as examples.
  • Differentiate NFS (network-attached storage) and SCP (Secure Copy Protocol) for Linux-based file transfers, using NTC’s server logs as a case study.
  • Apply bandwidth and latency trade-offs in file transfers, e.g., compressing large files for Pathao’s driver app updates.

Core Concepts: File Transfer Protocols

File transfer protocols enable reliable, structured movement of files between systems over networks. They operate at the application layer (Layer 7) of the OSI model but rely on lower layers (TCP/UDP, IP) for delivery. Below are the key protocols covered in this unit, categorized by security, use case, and underlying transport mechanism.

Layered Model for File Transfers

   ┌───────────────────────────────────────────────────┐
   │                Application Layer (File Transfer)   │
   │  ┌─────────────┐  ┌─────────────┐  ┌─────────────┐  │
   │  │   FTP       │  │   SFTP      │  │   HTTP/HTTPS│  │
   │  └─────────────┘  └─────────────┘  └─────────────┘  │
   │  ┌─────────────┐  ┌─────────────┐  ┌─────────────┐  │
   │  │   TFTP      │  │   NFS       │  │   SCP       │  │
   │  └─────────────┘  └─────────────┘  └─────────────┘  │
   └───────────────────────────────────────────────────┘
   ┌───────────────────────────────────────────────────┐
   │                Transport Layer (TCP/UDP)          │
   │  ┌─────────────┐  ┌─────────────┐  ┌─────────────┐  │
   │  │   TCP       │  │   UDP       │  │   (Reliable)│  │
   │  └─────────────┘  └─────────────┘  └─────────────┘  │
   └───────────────────────────────────────────────────┘
   ┌───────────────────────────────────────────────────┐
   │                Internet Layer (IP)                │
   └───────────────────────────────────────────────────┘

Key Idea: FTP and HTTP use TCP (reliable, connection-oriented), while TFTP uses UDP (faster, no handshake).


1. File Transfer Protocol (FTP)

FTP is the oldest and most basic protocol for transferring files between a client and server. It uses two separate channels:

  • Control channel (port 21): Sends commands (e.g., USER, PASS, RETR, STOR).
  • Data channel (port 20): Transfers actual file data.

How FTP Works: A Step-by-Step Trace

sequenceDiagram
    participant Client as FTP Client (e.g., FileZilla)
    participant Server as FTP Server (e.g., Daraz's inventory server)
    Client->>Server: 1. Connect to port 21 (control channel)
    Server-->>Client: 2. Send 220 "Service ready" banner
    Client->>Server: 3. USER anonymous (or username)
    Server-->>Client: 4. 331 "Password required"
    Client->>Server: 5. PASS (password or email for anonymous)
    Server-->>Client: 6. 230 "Login successful"
    Client->>Server: 7. SYST (check OS type)
    Client->>Server: 8. TYPE I (binary transfer)
    Client->>Server: 9. PORT 192,168,1,2,5,6 (data channel IP:port)
    Client->>Server: 10. RETR file.txt (download)
    Server->>Client: 11. Open data channel (port 20) and send file
    Client->>Server: 12. QUIT
    Server-->>Client: 13. 221 "Goodbye"

FTP Packet Format (Control Channel)

┌───────────────────────────────────────────────────┐
│  Command (e.g., "RETR filename.txt")              │
├───────────────────────────────────────────────────┤
│  Response Code (e.g., 226 "Transfer complete")    │
└───────────────────────────────────────────────────┘

Example: When you download a file from an FTP server, the RETR command triggers the data transfer.

Anonymous FTP

  • Uses anonymous as username and email as password (often just a placeholder like user@example.com).
  • Restricted to read-only access in most cases.
  • Real-world use: Old university courseware repositories or public software archives.

Advantages and Disadvantages

Advantages Disadvantages
Simple to implement No encryption (passwords/credentials sent in plaintext)
Supports large file transfers Port 21/20 often blocked by firewalls
Works across platforms No built-in security (requires FTPS/SFTP)

2. Secure FTP Variants

FTP’s lack of encryption led to three secure alternatives:

A. SFTP (SSH File Transfer Protocol)

  • Runs over SSH (port 22), encrypting both control and data channels.
  • Uses public-key cryptography for authentication.
  • Command example:
    sftp user@server.example.com
    put localfile.txt remote/
    
  • Real-world example: eSewa uses SFTP to securely upload KYC documents (citizen photos, citizenship certificates) from mobile apps to their servers.

B. FTPS (FTP Secure)

  • Extends FTP with TLS/SSL (ports 990 for explicit, 21 for implicit).
  • Two modes:
    1. Explicit FTPS: Client initiates TLS after connecting to port 21.
    2. Implicit FTPS: Server forces TLS on port 990.
  • Real-world example: Banks like NMB use FTPS to transfer large transaction logs between branches.

C. FTPS-ES (FTP over TLS with Explicit Start)

  • Similar to explicit FTPS but optimized for high-speed transfers (used in cloud backups).
  • Example: Daraz’s warehouse management system uses FTPS-ES to sync inventory files with suppliers.

Comparison Table

Feature FTP SFTP FTPS (Explicit) FTPS (Implicit)
Encryption ❌ ✅ (SSH) ✅ (TLS) ✅ (TLS)
Port 21 22 21 (then 990) 990
Authentication Plaintext SSH keys/Password TLS certs TLS certs
Firewall-friendly ❌ (ports 20/21) ✅ (port 22) ❌ (dynamic ports) ✅ (port 990)
Use Case Legacy systems Secure Linux transfers Enterprise file sharing Legacy FTP upgrades

3. Trivial File Transfer Protocol (TFTP)

  • UDP-based (port 69), no authentication, no directory listing.
  • Used for small files (e.g., booting routers, IoT firmware updates).
  • Packet format:
    ┌───────────────────────────────────────────────────┐
    │  Opcode (1 or 2) | Filename (max 512 bytes)          │
    │  0 Pad           | Mode (e.g., "octet", "netascii")    │
    └───────────────────────────────────────────────────┘
    
  • Example: A Cisco router downloads its IOS image via TFTP from a server.

TFTP Workflow

sequenceDiagram
    participant Client as Router (TFTP Client)
    participant Server as TFTP Server (e.g., NTC's firmware repo)
    Client->>Server: 1. RRQ (Read Request): filename=ios.bin, mode=octet
    Server-->>Client: 2. ACK (Block 0)
    Server->>Client: 3. DATA (Block 0, 512 bytes)
    Client-->>Server: 4. ACK (Block 0)
    Server->>Client: 5. DATA (Block 1, ...)
    Client-->>Server: 6. ACK (Block 1)
    ...
    Server->>Client: N. DATA (Last block, <512 bytes)
    Client-->>Server: N+1. ACK (Last block)

When to Use TFTP

  • Pros: Fast (no handshake), low overhead.
  • Cons: No security, no resume capability.
  • Real-world use: Ncell’s base stations fetch configuration files via TFTP during nightly updates.

4. HTTP/HTTPS for File Transfers

While HTTP/HTTPS are primarily for web content, they are also used for file transfers:

  • HTTP (port 80): Unencrypted (e.g., old software download links).
  • HTTPS (port 443): Encrypted with TLS (e.g., Google Drive downloads).

TLS Handshake for HTTPS File Downloads

sequenceDiagram
    participant Client as Browser (e.g., downloading a PDF)
    participant Server as Web Server (e.g., NEPSE's annual report)
    Client->>Server: 1. ClientHello (TLS version, cipher suites)
    Server-->>Client: 2. ServerHello + Certificate
    Client->>Server: 3. Key Exchange (pre-master secret)
    Client->>Server: 4. Finished (encrypted)
    Server-->>Client: 5. Finished (encrypted)
    Client->>Server: 6. GET /reports/2023.pdf HTTP/1.1
    Server-->>Client: 7. 200 OK + File (encrypted)

Real-world Example: Daraz’s Checkout Process

  1. User adds items to cart → HTTP request to Daraz’s server.
  2. Server responds with HTTPS (encrypted) for payment gateway (eSewa/Khalti).
  3. After payment, Daraz sends a download link (HTTPS) for the order confirmation PDF.

5. Network File System (NFS)

  • Linux/Unix protocol for shared file systems over a network.
  • Uses RPC (Remote Procedure Call) and port 2049.
  • Example: NTC’s central logging server exports /var/log to all regional offices via NFS.

NFS Mount Command

mount -t nfs server.example.com:/shared/folder /local/mount/point

NFS vs. FTP/SFTP

Feature NFS FTP/SFTP
Protocol RPC over UDP/TCP TCP
Use Case Shared home directories One-off file transfers
Performance High (cached metadata) Moderate (per-file overhead)
Security Kerberos/RPCSEC_GSS SSH/TLS

6. Secure Copy Protocol (SCP)

  • SSH-based file transfer (port 22).
  • Command example:
    scp file.txt user@server:/remote/path/
    
  • Real-world use: NTC engineers use SCP to copy configuration files from a central server to remote switches.

SCP vs. SFTP

Feature SCP SFTP
Protocol SSH (single command) SSH (interactive session)
Use Case Scripted transfers Interactive file management
Speed Faster (no session overhead) Slower (per-command SSH)

In the Real World

  1. eSewa’s KYC Uploads

    • Protocol: SFTP (over SSH).
    • How it works: When you upload your citizenship certificate, your phone app encrypts the file with SFTP and sends it to eSewa’s servers. The server verifies the file hash before processing.
    • Why SFTP? Ensures no third party can intercept your sensitive documents during transfer.
  2. Daraz’s Inventory Sync

    • Protocol: FTPS-ES (FTP over TLS).
    • How it works: Daraz’s warehouses run scripts nightly to upload inventory CSV files to their cloud servers. FTPS-ES ensures the files are encrypted in transit, even though the data is large (millions of rows).
    • Challenge: Daraz had to configure firewalls to allow dynamic data ports (FTPS uses temporary ports >1024).
  3. NTC’s Network Configuration Backups

    • Protocol: SCP.
    • How it works: Every midnight, NTC’s central server pushes updated router configurations to all regional offices using scp. This ensures all devices have the latest routing tables for traffic optimization.
    • Why SCP? Simpler than SFTP for automated, scripted transfers.
  4. Pathao Driver App Updates

    • Protocol: HTTP/HTTPS (for app binaries) + TFTP (for small config files).
    • How it works:
      • Drivers download the main app update via HTTPS (encrypted).
      • Small configuration tweaks (e.g., fare matrix updates) are fetched via TFTP during idle periods to save bandwidth.
    • Trade-off: TFTP is faster for tiny files but unencrypted; HTTPS is slower but secure.

Worked Example: Calculating FTP Transfer Time

Scenario: A Daraz warehouse needs to upload a 500 MB inventory file to their cloud server. The network has:

  • Bandwidth: 10 Mbps (1.25 MB/s).
  • FTP overhead: 10% (due to acknowledgments and retries).
  • Latency: 50 ms (round-trip time).

Steps:

  1. Calculate effective bandwidth: .

  2. Time for data transfer: .

  3. Add latency overhead:

    • Each FTP packet (e.g., 1460 bytes) requires an ACK, adding per packet.
    • Number of packets: packets.
    • Total latency overhead: .
    • Note: This is an overestimation because modern FTP uses parallel transfers (multiple data channels). With 10 parallel channels, the latency overhead drops to ~59 minutes.

Real-world fix: Daraz uses compression (e.g., gzip) to reduce file size by 30%, cutting transfer time to ~5 minutes.


Common Pitfalls and Best Practices

  1. Firewall Rules:

    • FTP’s dynamic data ports (20) often get blocked. Use passive mode (PASV) where the client connects to the server’s data port.
    • SFTP/SCP (port 22) and FTPS (port 990) are easier to firewall.
  2. Security:

    • Never use plain FTP for sensitive data (e.g., medical records, financial files).
    • Prefer SFTP for Linux environments or FTPS for Windows/enterprise setups.
  3. Performance:

    • For large files, use compression (e.g., gzip) or parallel transfers (FTP’s PORT command).
    • TFTP is not suitable for files >1 MB due to packet loss risks.
  4. Automation:

    • Use rsync over SSH for incremental backups (faster than full SCP transfers).
    • Example:
      rsync -avz -e ssh /local/backup/ user@server:/remote/backup/
      

Exam Tip

This unit is conceptual and application-based. Expect:

  1. Short definitions:
    • "Explain FTP’s control and data channels."
    • "Differentiate between SFTP and FTPS."
  2. Scenario-based questions:
    • "Why would a bank use FTPS instead of FTP for transferring transaction logs?"
    • "How would you configure an FTP server to allow anonymous downloads but restrict uploads?"
  3. Packet traces:
    • Draw a sequence diagram for an SFTP file upload or an FTP RETR command.
  4. Comparison tables:
    • Compare TFTP vs. FTP vs. HTTP for a given use case (e.g., router boot files).
  5. Real-world applications:
    • "How does Daraz ensure secure file transfers between warehouses and their cloud servers?"

High-scoring strategies:

  • Draw diagrams: Always include a sequence diagram for protocol handshakes (e.g., FTP login, TLS handshake).
  • Use examples: Tie answers to Nepalese companies (e.g., "NTC uses SCP for router configs").
  • Mention ports: FTP (21/20), SFTP (22), FTPS (990), TFTP (69), HTTP/HTTPS (80/443).
  • Security focus: Emphasize encryption (SFTP/FTPS) vs. plaintext (FTP/TFTP).

Based on the TU BIT syllabus for Network and System Administration (BIT451), unit 8.

Discussion

Loading…