That connection tracking link gives some good detail on how to get passive mode FTP working with iptables.