Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Fix Passive FTP Problems on a Xen VPS (SolusVM)

If FTP connects but file lists hang or time out on your VPS, passive mode ports are probably blocked. This guide shows how to fix it. It needs root access.

Dedicated Servers2 min read3 steps

What is the problem?

FTP is a way to send files to your server. When you connect, you can log in, but the file list never shows, or the transfer freezes. You may see errors like "Entering Passive Mode" followed by a timeout.

FTP uses two kinds of connection. First, a control connection on port 21 handles your login and commands. A port is like a numbered door on the server. Then a second connection moves the files.

In passive mode, your computer opens that second connection to the server, on a random high port. If the firewall blocks those ports, the transfer fails.

SolusVM is a control panel used to manage virtual servers, and Xen is one type of virtualisation. Virtualisation means one big machine is split into many smaller virtual servers. This problem is about your firewall and FTP settings, not about Xen or SolusVM themselves. Xen is older software, and the same steps apply on newer systems.

Step 1: Choose a passive port range

Pick a small range of ports, such as 40000 to 40100. Ask Hostvento support if your plan has special network rules.

Step 2: Set the range in your FTP server

For vsftpd, open /etc/vsftpd/vsftpd.conf and add:

pasv_enable=YES
pasv_min_port=40000
pasv_max_port=40100

These lines turn on passive mode and limit it to your range.

For Pure-FTPd, add this line to its config file:

PassivePortRange 40000 40100

For ProFTPD, use PassivePorts 40000 40100.

If your server is behind NAT (its public address differs from its own), also set the public address. For vsftpd that is pasv_address=YOUR_PUBLIC_IP.

Step 3: Open the ports in the firewall

Back up your current rules first. With iptables:

iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 40000:40100 -j ACCEPT
service iptables save

These lines allow port 21 and your passive range, then save the rules. With CSF, add the ports to TCP_IN in /etc/csf/csf.conf (for example 21,40000:40100) and run csf -r.

Step 4: Load the FTP helper (if needed)

Some systems use a kernel helper to track FTP connections:

modprobe nf_conntrack_ftp

This loads the module that lets the firewall follow passive FTP.

Step 5: Restart and test

  1. Restart the FTP service, for example systemctl restart vsftpd.
  2. Connect again with your FTP program, such as FileZilla.
  3. Try a file list.

If it still fails, switch your FTP program to active mode as a test. In FileZilla, look under Edit, Settings, Connection, FTP. Active mode is less friendly to home routers, so use it only to test.

Tip: Plain FTP sends passwords without hiding them. Use SFTP when you can. It uses a single port, so it avoids this problem.

Need help? Open a ticket at https://secure.hostvento.com/submitticket.php.

Quick recap

  • Passive FTP uses extra high ports for file transfers.
  • Set a passive port range in your FTP server.
  • Open port 21 and that range in the firewall.
  • Restart the FTP service and test.
  • Prefer SFTP for safer, simpler transfers.