"Linux Firewall" module & PASF ProFTPd issue

When I go to the “Linux firewall” module in the “Networking” group, it ak s me te setup he firewall. I choose “Block all except ports used for virtual hosting, on interface:” on eth0. But when I activate that firewall a client ftp can’t login until he set the client to use active. I know this is a firewall rule I have to add but what one?
Pls help me!!

This might help you explain to your client why he has to use active or you can find out which port you need to open.