Stumbled across some great articles about FTP, SSL and Active/Passive settings made by Alun Jones (Security MVP).
- How FTP Data Connections Work Part 1 (OR: Don’t Open Port 20 in your Firewall!)
- How FTP Data Connections Work Part 2 (OR: Fun With Port 20)
- FTP 7.5 + SSL + Non-default port / AspNetAuth
Thanks to Steve Schofield for the reference.