优化 Linux 上的 FTP 服务器配置,通常可以从性能、安全性、稳定性和可维护性几个方面入手。下面以最常见的 vsftpd(Very Secure FTP Daemon)为例,兼顾 ProFTPD / Pure-FTPd 的思路,给你一套实用的优化建议。
常见 FTP 服务:
# 查看是否已安装
which vsftpd
# 安装
yum install vsftpd -y # CentOS
apt install vsftpd -y # Ubuntu
编辑 /etc/vsftpd/vsftpd.conf:
max_clients=500
max_per_ip=10
max_clients:总并发连接数max_per_ip:单 IP 连接数(防恶意占用)# 关闭 DNS 反向解析(加速连接)
reverse_lookup_enable=NO
# 启用异步 IO(大文件优化)
async_abor_enable=YES
# 允许断点续传
allow_resume=YES
FTP 被动模式对防火墙最友好:
pasv_enable=YES
pasv_min_port=30000
pasv_max_port=31000
防火墙需放行:
firewall-cmd --add-port=30000-31000/tcp --permanent
firewall-cmd --reload
anonymous_enable=NO
chroot_local_user=YES
allow_writeable_chroot=YES
防止用户访问系统其他目录。
避免直接使用系统账号:
# 使用 PAM + 虚拟用户
guest_enable=YES
guest_username=ftpuser
ssl_enable=YES
rsa_cert_file=/etc/ssl/certs/vsftpd.pem
rsa_private_key_file=/etc/ssl/private/vsftpd.key
force_local_logins_ssl=YES
force_local_data_ssl=YES
ulimit -n 65535
永久生效:
/etc/security/limits.conf
* soft nofile 65535
* hard nofile 65535
# /etc/sysctl.conf
net.core.somaxconn = 65535
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_max_syn_backlog = 8192
sysctl -p
xferlog_enable=YES
xferlog_std_format=YES
log_ftp_protocol=YES
配合:
tail -f /var/log/vsftpd.log
如果可接受:
✅ 被动端口固定
✅ 匿名关闭
✅ chroot 限制
✅ TLS 加密
✅ 文件描述符足够
✅ 日志开启
如果你愿意,可以告诉我:
我可以给你一份直接可用的配置文件。