Linux centos7 搭建 ftp 服务
安装 FTP
yum install -y vsftpd
安装过程如下:
Loaded plugins: fastestmirror, security
Determining fastest mirrors
* base: mirrors.163.com
* extras: mirrors.163.com
* updates: mirrors.163.com
base | 3.7 kB 00:00
extras | 3.4 kB 00:00
extras/primary_db | 26 kB 00:00
updates | 3.4 kB 00:00
updates/primary_db | 1.9 MB 00:00
Setting up Install Process
Resolving Dependencies
--> Running transaction check
---> Package vsftpd.x86_64 0:2.2.2-24.el6 will be installed
--> Finished Dependency Resolution
Dependencies Resolved
=============================================================================================================================================================================================================================================
Package Arch Version Repository Size
=============================================================================================================================================================================================================================================
Installing:
vsftpd x86_64 2.2.2-24.el6 base 156 k
Transaction Summary
=============================================================================================================================================================================================================================================
Install 1 Package(s)
Total download size: 156 k
Installed size: 340 k
Downloading Packages:
vsftpd-2.2.2-24.el6.x86_64.rpm | 156 kB 00:00
Running rpm_check_debug
Running Transaction Test
Transaction Test Succeeded
Running Transaction
Installing : vsftpd-2.2.2-24.el6.x86_64 1/1
Verifying : vsftpd-2.2.2-24.el6.x86_64 1/1
Installed:
vsftpd.x86_64 0:2.2.2-24.el6
Complete!
然后切入到 cd /etc/vsftpd/ 目录下:有四个和核心文件,
-rw-------. 1 root root 125 10月 31 2018 ftpusers 黑名单目录,此目录下的用户不允许访问 FTP 服务器
-rw-------. 1 root root 361 10月 31 2018 user_list 百名单目录,是运行访问 FTP 服务器的用户列表
-rw-------. 1 root root 5275 11月 26 15:12 vsftpd.conf 核心配置文件
-rwxr--r--. 1 root root 338 10月 31 2018 vsftpd_conf_migrate.sh FTP 服务
以上信息参考:https://www.cnblogs.com/Wang352051443/p/9805980.html
ftpusers 文件(黑名单目录):
# Users that are not allowed to login via ftp
root
bin
daemon
adm
lp
sync
shutdown
halt
mail
news
uucp
operator
games
nobody
~
~
user_list 文件(白名单目录):
该文件顶部也有提示,vsftpd.conf文件中的userlist_deby默认为YES,如果vsftpd.conf文件中的userlist_deby等于NO,则仅允许在user_list中的用户使用ftp登陆,如果userlist_deby等于YES,则永远不允许在user_list中的用户,甚至都不能输入密码。注意,默认情况下vsftpd还检查ftpusers文件里有哪些用户被拒绝。
# vsftpd userlist
# If userlist_deny=NO, only allow users in this file
# If userlist_deny=YES (default), never allow users in this file, and
# do not even prompt for a password.
# Note that the default vsftpd pam config also checks /etc/vsftpd/ftpusers
# for users that are denied.
root
bin
daemon
adm
lp
sync
shutdown
halt
mail
news
uucp
operator
games
nobody
~
~
以上信息参考:https://blog.csdn.net/w8827130/article/details/90742623
vsftpd.conf 文件(核心配置)
进入vim vsftpd.conf 文件中 如下:
# Example config file /etc/vsftpd/vsftpd.conf
#
# The default compiled in settings are fairly paranoid. This sample file
# loosens things up a bit, to make the ftp daemon more usable.
# Please see vsftpd.conf.5 for all compiled in defaults.
#
# READ THIS: This example file is NOT an exhaustive list of vsftpd options.
# Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's
# capabilities.
#
# Allow anonymous FTP? (Beware - allowed by default if you comment this out).
anonymous_enable=NO
#
# Uncomment this to allow local users to log in.
# When SELinux is enforcing check for SE bool ftp_home_dir
local_enable=YES
#
# Uncomment this to enable any form of FTP write command.
write_enable=YES
#
# Default umask for local users is 077. You may wish to change this to 022,
# if your users expect that (022 is used by most other ftpd's)
local_umask=022
#
# Uncomment this to allow the anonymous FTP user to upload files. This only
# has an effect if the above global write enable is activated. Also, you will
# obviously need to create a directory writable by the FTP user.
# When SELinux is enforcing check for SE bool allow_ftpd_anon_write, allow_ftpd_full_access
#anon_upload_enable=YES
#
# Uncomment this if you want the anonymous FTP user to be able to create
# new directories.
#anon_mkdir_write_enable=YES
#
# Activate directory messages - messages given to remote users when they
# go into a certain directory.
dirmessage_enable=YES
.....
.....
需要改几个 配置 (有些配置,在 vsftpd.conf 是没有的,那就在最后面加上就可以了)
anonymous_enable=NO 是否允许匿名访问FTP 服务
local_root=/usr/local/src/ftp/data FTP 文件存放路径
listen_port=6662 更改FTP 端口 默认(21)
reverse_lookup_enable=NO 如果客户端登录vsftp很慢,加上reverse_lookup_enable=NO表示不查找dns服务器(这是我 springboot 整合 ftp 遇到的问题)
其他配置 目前没改过
FTP 更改默认端口
除了 在 vsftpd.conf 中 添加 listen_port=端口号 外,还需要在 /etc/service 中将 ftp 更改成 listen_port 指定的端口号。
编辑 /etc/services 文件
vim /etc/services
信息如下:tcp 默认端口 为21 注释上 也说明了
# are included, only the more common ones.
#
# The latest IANA port assignments can be gotten from
# http://www.iana.org/assignments/port-numbers
# The Well Known Ports are those from 0 through 1023.
# The Registered Ports are those from 1024 through 49151
# The Dynamic and/or Private Ports are those from 49152 through 65535
#
# Each line describes one service, and is of the form:
#
# service-name port/protocol [aliases ...] [# comment]
tcpmux 1/tcp # TCP port service multiplexer
tcpmux 1/udp # TCP port service multiplexer
rje 5/tcp # Remote Job Entry
rje 5/udp # Remote Job Entry
echo 7/tcp
echo 7/udp
discard 9/tcp sink null
discard 9/udp sink null
systat 11/tcp users
systat 11/udp users
daytime 13/tcp
daytime 13/udp
qotd 17/tcp quote
qotd 17/udp quote
msp 18/tcp # message send protocol (historic)
msp 18/udp # message send protocol (historic)
chargen 19/tcp ttytst source
chargen 19/udp ttytst source
ftp-data 20/tcp
ftp-data 20/udp
# 21 is registered to ftp, but also used by fsp
ftp 6662/tcp
重启 ftp 服务
service vsftpd restart
查看是否成功(出现如下信息就表示成功了。
[root@system vsftpd]# netstat -utlpn | grep vsftp
tcp6 0 0 :::6662 :::* LISTEN 6679/vsftpd
添加新账号
其实账号也不用特意指定,当前 linux 账号也可以进行访问。
useradd ftpuser 添加一个用户叫 ftpuser 的用户
passwd ftpuser 为 ftpuser 设置密码
chown -R ftpuser /usr/local/src/ftp/data/ 为 ftpuser 赋予 该路径的权限(上面有说明)
可以将 新创建 的账号 加入到白名单中
开放端口:
如果你也是 CentOS 7 的话 可以参考我另一篇博客
或者
# iptables -A INPUT -ptcp --dport 8099 -j ACCEPT
# service iptables save
FTP 服务 运行相关命令:
参考博客 https://www.cnblogs.com/cqlb/p/9510214.html
1. 查看ftp 服务器状态
#service vsftpd status
2. 启动ftp服务器
#service vsftpd start
3. 重启ftp服务器
#service vsftpd restart
连接测试:
查看 ip 是否能 ping 通
[C:\~]$ ping 192.168.154.45 正在 Ping 192.168.154.45 具有 32 字节的数据: 来自 192.168.154.45 的回复: 字节=32 时间<1ms TTL=64 来自 192.168.154.45 的回复: 字节=32 时间<1ms TTL=64 来自 192.168.154.45 的回复: 字节=32 时间<1ms TTL=64 来自 192.168.154.45 的回复: 字节=32 时间<1ms TTL=64 192.168.154.45 的 Ping 统计信息: 数据包: 已发送 = 4,已接收 = 4,丢失 = 0 (0% 丢失), 往返行程的估计时间(以毫秒为单位): 最短 = 0ms,最长 = 0ms,平均 = 0ms
登录 FTP
[C:\~]$ ftp 192.168.154.45 6662 #连接 ftp 命令 , 需要用 空格隔开
Connecting to 192.168.154.45:6662...
Connection established.
To escape to local shell, press 'Ctrl+Alt+]'.
220 (vsFTPd 3.0.2)
Name (192.168.154.45:Administrator): ftpuser #账号
331 Please specify the password.
Password: #密码是看不到的,但是输出你填写的密码即可
230 Login successful.
# 上面指定的目录
ftp:/usr/local/src/ftp/data>
若要看 目录下的文件 只需要用 ls 命令即可,但是需要指定为 被动模式 (passive)
ftp:/usr/local/src/ftp/data> ls
227 Entering Passive Mode (192,168,154,45,49,87).
ftp:/usr/local/src/ftp/data>
指定为 被动模式,即可查看该目录下有具体有那些文件。
ftp:/usr/local/src/ftp/data> passive
Passive mode off.
ftp:/usr/local/src/ftp/data> ls
200 PORT command successful. Consider using PASV.
150 Here comes the directory listing.
Test_Notify_20191119152800_0000.xml
Test_Result_20191121100750_0000.xml
226 Directory send OK.
ftp:/usr/local/src/ftp/data>
FileZilla连接测试:
若没有下载 FileZilla ,请前往 官网 下载


到此为止,FTP 算是搭建好了(这些东西,让我搞了一个上午),
若出现 错误: 20 秒后无活动,连接超时 解决方案参考https://www.jianshu.com/p/667aa525d6d0?tdsourcetag=s_pcqq_aiomsg
具体操作如下:
[root@system vsftpd]# iptables -I INPUT -p tcp --dport 20000:30000 -j ACCEPT
[root@system vsftpd]# service iptables save
iptables: Saving firewall rules to /etc/sysconfig/iptables:[ 确定 ]
[root@system vsftpd]# service vsftpd restart
Redirecting to /bin/systemctl restart vsftpd.service
[root@system vsftpd]#
设置FTP 开机自启动
只需要 输入 chkconfig vsftpd on 命令即可
# chkconfig vsftpd on
到此为止 Linux 搭建 FTP 服务器就结束了, 以上步骤是我今天一上午亲自测试过的,把能遇到的问题都写到上面了。

浙公网安备 33010602011771号