# FTP in traefik v2.10

**URL:** <https://community.traefik.io/t/ftp-in-traefik-v2-10/20757>\
**Category:** Traefik v2\
**Tags:** docker, tcp\
**Created:** [December 13, 2023, 12:49pm UTC](https://community.traefik.io/t/ftp-in-traefik-v2-10/20757 "2023-12-13T12:49:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nonodev96](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/nonodev96/32/7949_2.png) [@nonodev96](https://community.traefik.io/u/nonodev96)\
**Post date:** [December 13, 2023, 12:49pm UTC](https://community.traefik.io/t/ftp-in-traefik-v2-10/20757/1 "2023-12-13T12:49:22Z")

</div>

Hello, I am trying to create an orchestration for my organization but when defining a route for my TCP (ftp) traffic, Trafik does nothing, I have already purged the logs and I have no information about what is happening.

.ENV

```auto
PROJECT_NAME=c_server_project
PROJECT_BASE_URL=server.docker.localhost
PROJECT_PORT_FTP=21
TRAEFIK_TAG=v2.10

```

In the `docker-compose.yml` I have multiples services, a website, a ftp.

```auto
services:
  traefik:
    image: traefik:$TRAEFIK_TAG
    container_name: "${PROJECT_NAME}_traefik"
    ports:
      - "8080:8080" # Dashboard
      - "${PROJECT_PORT}:80"
      - "${PROJECT_PORT_SSL}:443"
      - "${PROJECT_PORT_FTP}:21"
    command:
      - --log.level=DEBUG
      - --api.insecure=true
      - --providers.docker=true
      - --providers.docker.network=internal
      - --entrypoints.web.address=:80
      - --entrypoints.websecure.address=:443
      - --entrypoints.ftp.address=:21
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro

  ftp-server:
    image: lhauspie/vsftpd-alpine
    container_name: "${PROJECT_NAME}_website_ftp"
    environment:
      - FTP_USER=user
      - FTP_PASS=pass
    ports:
      - 20-22:20-22
      - 21100-21110:21100-21110
      - 990:990
    volumes:
      - ./Apps/website/website:/home/vsftpd/website
    labels:
      - "traefik.enable=true"
      - "traefik.tcp.routers.${PROJECT_NAME}_website_ftp.rule=HostSNI(`ftp.${PROJECT_BASE_URL}`)"
      - "traefik.tcp.routers.${PROJECT_NAME}_website_ftp.entrypoints=ftp"
      - "traefik.tcp.services.${PROJECT_NAME}_website_ftp.loadbalancer.server.port=21"

```

I am trying with the command ftp and with the localhost it works but with the host defined it does not connect

The localhost:21 works, because the port 21 is mapped with 21 of the container, but a want to use traefik.

```bash
ftp -p localhost 21

```

Not work with the host

```bash
ftp -p ftp.server.docker.localhost 21

```

And the next question is how to do this but with TLS, everything is very confusing.

---

<div class="post-metadata">

**Author:** ![bluepuma77](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bluepuma77](https://community.traefik.io/u/bluepuma77)\
**Post date:** [December 13, 2023, 5:49pm UTC](https://community.traefik.io/t/ftp-in-traefik-v2-10/20757/2 "2023-12-13T17:49:14Z")

</div>

FTP is kind of obsolete, in general I would recommend to use a different protocol (like scp), that does not require a lot of open ports.

You are mixing to expose ports to Traefik and your FTP server, not sure if that is desirable.

Sidenote: I think when using FTP with command `passive`, it is only using the main connection, no additional TCP ports.

---

<div class="post-metadata">

**Author:** ![Papina](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/papina/32/7939_2.png) [@Papina](https://community.traefik.io/u/Papina)\
**Post date:** [December 14, 2023, 3:52am UTC](https://community.traefik.io/t/ftp-in-traefik-v2-10/20757/3 "2023-12-14T03:52:10Z")

</div>

TCP requests like ftp can't use redirect rules, thats only for HTTP type requests, they use `.rule=HostSNI(`\*`)` and just rely on the port being available

traefik-docker-compose.yml

```auto
version: "3.7"
services:

  traefik:
    image: traefik:latest
    container_name: "traefik"
    volumes:
      # Traefik requires access to docker.sock to read docker labels
      - /var/run/docker.sock:/var/run/docker.sock:ro # Access to Docker
    ports:
      - "${PROJECT_PORT}:80"
      - "${PROJECT_PORT_SSL}:443"
      - "${PROJECT_PORT_FTP}:21"
    command:
      # Traefik settings to get a Dashboard and log settings
      - "--api.dashboard=true"
      - "--api=true"
      - "--api.insecure=true"
      - "--log.filePath=/logs/traefik.json"
      - "--log.format=json"
      - "--log.level=INFO"
      # EntryPoints web ports
      - "--entryPoints.web.address=:${PROJECT_PORT}"
      - "--entryPoints.websecure.address=:${PROJECT_PORT_SSL}"
      # Redirect http to https
      - "--entryPoints.web.http.redirections.entryPoint.to=websecure"
      - "--entryPoints.web.http.redirections.entryPoint.scheme=https"
      # EntryPoints for TCP/UDP Traffic
      - "--entryPoints.tcp-ftp.address=:${PROJECT_PORT_FTP}" # Expose FTP Port 
      # Setup the docker provider, and basic rules to grab the docker service name as the host name
      - "--providers.docker=true"
      - "--providers.docker.endpoint=unix:///var/run/docker.sock"
      - "--providers.docker.exposedByDefault=true"
      - "--providers.docker.defaultRule=HostRegexp(`{{ index .Labels \"com.docker.compose.service\" }}.{anydomain:.*}`)"
      # Setup the file provider so we can add dynamic rules as YAML files, eg OAUTH middleware chains
      - "--providers.file.directory=/rules"
      - "--providers.file.watch=true"
    labels:
      - "traefik.http.routers.traefik-rtr.service=api@internal"

```

ftp-docker-compose.yml

```auto
version: "3.7"
services:

  ftp-server:
    image: lhauspie/vsftpd-alpine
    environment:
      - FTP_USER=user
      - FTP_PASS=pass
    volumes:
      - ./Apps/website/website:/home/vsftpd/website
    labels:
      - "traefik.tcp.services.ftp-server-svc.loadbalancer.server.port=21"
      - "traefik.tcp.routers.ftp-server.entrypoints=tcp-ftp"
      - "traefik.tcp.routers.ftp-server.rule=HostSNI(`*`)"
      - "traefik.tcp.routers.ftp-server.tls=false"

```

test the ftp process:

```auto
C:\>ftp -d <ftp ip address, eg 127.0.0.1>
Connected to 127.0.0.1.
220 Welcome to FTP Server
---> OPTS UTF8 ON
200 Always in UTF8 mode.
User (127.0.0.1:(none)): user
---> USER user
331 Please specify the password.
Password:
---> PASS pass
230 Login successful.
ftp>

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [December 17, 2023, 3:53am UTC](https://community.traefik.io/t/ftp-in-traefik-v2-10/20757/4 "2023-12-17T03:53:09Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
