What setting do I need on vFirewall for a FTP communication?

For a passive FTP connection, please open port 21 as a destination port on vFirewall.
However, vFirewall opens a temporary port automatically for an inbound connection.
Stateful inspection is enabled on vFirewall, which examines packets that traverses all interfaces of the vFirewall and opens ports if they are valid, and closes ports if they are invalid, therefore preventing illegal access to the network.
Note: You cannot disable this function.

[Reference] -Enterprise Cloud Functional Description

