Port 20: FTP data
TCP 20 is the port for File Transfer Protocol (data channel, active mode). Avoid. FTP sends credentials and data unencrypted.
| Service | File Transfer Protocol (data channel, active mode) |
|---|---|
| Protocol | TCP |
| Exposure risk | High: do not expose to the internet |
| Secure alternative | SFTP (port 22) or FTPS (990) |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 20 does
In active-mode FTP the server opens a connection from port 20 back to the client to send file contents and directory listings. Passive mode, which almost every modern client uses, replaces this with a high port negotiated on port 21.
Should port 20 be open?
Avoid. FTP sends credentials and data unencrypted. Where you can, use SFTP (port 22) or FTPS (990) instead.
Find what's listening on port 20
- Linux:
sudo ss -tulpn | grep :20 - macOS:
sudo lsof -nP -i :20 - Windows:
netstat -ano | findstr :20, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 20/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=20/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 20" -Direction Inbound -Protocol TCP -LocalPort 20 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 20
What is port 20 used for?
File Transfer Protocol (data channel, active mode). In active-mode FTP the server opens a connection from port 20 back to the client to send file contents and directory listings. Passive mode, which almost every modern client uses, replaces this with a high port negotiated on port 21.
Is port 20 TCP or UDP?
TCP. FTP data uses TCP port 20.
Is it safe to open port 20?
High: do not expose to the internet. Avoid. FTP sends credentials and data unencrypted. Secure alternative: SFTP (port 22) or FTPS (990).
How do I check if port 20 is open?
Use the checker on this page: it connects to your host on TCP 20 from the internet. Locally, run
nc -vz host 20 (macOS/Linux) or Test-NetConnection host -Port 20 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :20 (Linux) or netstat -ano | findstr :20 (Windows).