for (passive) ftp you will need to open all ports above 1024 to the server to get the data connection work. and in the case you NAT traffic to your server you have to to that for the data connection as well.
and of course open port 44 to your server for the control connection [:)]
as far as I know the responsible conntrack module is listening on port tcp/21 per default. Unfortunately I wasn't able to locate a script which loads 'ip_conntrack_ftp' on the firewall so I guess it is loaded directly from an Astaro module (would make sense since you can unload it in version 5). In version 4 it was possible to adjust a script called 'firewall_on.sh' or something like that....
...quick search....
....
....
I am not too bad :-)