Questions

Is there any way to *force* SSL/TLS transport encryption for all connects?
Is the encrypted tunnel used for PORT data connections?
How do I verify that the transport layer is encrypted?

What's wrong with SSH/SCP/SFTP?