Configure an FTP Export Destination Safely in QC Backup Manager
QCBM supports plain FTP for environments that cannot provide SFTP or FTPS, but plain FTP does not encrypt the username, password, or backup data in transit. QCBM therefore blocks FTP use until an administrator explicitly acknowledges that transport risk.
Prefer SFTP whenever possible. Use plain FTP only when you understand the network exposure and have no safer supported transport for the destination.
Understand the FTP Risk Before Enabling It
With plain FTP, credentials and Recovery Package data travel without transport encryption. Anyone able to observe the network path may be able to read that traffic. A strong QCBM backup package does not make an unencrypted transport private.
QCBM requires the destination option I understand plain FTP sends credentials and backup data without transport encryption. Without that acknowledgement, QCBM refuses to open the FTP export session.
Create the FTP Destination
- Open Settings > Export Destinations and choose Add New.
- Enter a destination name and choose FTP.
- Enter the remote host, port, username, password, and remote folder.
- Choose whether to use passive mode. It is enabled by default and is commonly required through NAT/firewalls.
- Read the plain-FTP warning and select the insecure-transport acknowledgement only when you intend to accept that risk.
- Enable the destination and save it.
The default FTP port is 21 unless your server uses another port. QCBM protects the saved remote password in encrypted storage tied to the Joomla site secret; that protects the stored credential, not the unencrypted FTP network session.
Test Before Sending a Backup
Use Test from the destination list. QCBM connects and authenticates, prepares the configured remote folder, uploads a small temporary object, confirms a non-zero remote size, and removes the test object.
If the test fails, fix the reported connection, authentication, folder, or data-channel problem rather than simply toggling the security acknowledgement.
Why SFTP Is Usually the Better Choice
SFTP uses SSH and QCBM requires an independently verified SSH host-key SHA-1 fingerprint before it trusts the remote server. That protects both the transport and the server identity in a way plain FTP does not.
If the same destination offers SFTP, create an SFTP destination instead of FTP. FTPS is also preferable to plain FTP when the provider supports it.
Verify a Real Export
After the FTP destination passes its Test, manually export one completed Backup Set and confirm the export result. QCBM rechecks the Backup Set's package health before starting the transfer.
Do not delete the local recovery point merely because the small destination test passed. Confirm the actual Recovery Package transfer first.
When to Stop Using FTP
Move away from plain FTP when the provider adds SFTP/FTPS support, when the network path becomes less trusted, or when organizational policy requires encrypted transport. Disable the FTP destination while migrating so new jobs do not continue to use it.
Community Discussion
Want to compare workflows, share practical tips, or discuss how you use this QCBM feature? Visit the QC Backup Manager Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.