A friend of mine help with it. May be this will help others also, so I am posting this very easy solution: I am using iptables as firewall. So, to make your ftp working well just enable ip_conntrack_ftp module in iptables! It is located in section 2.2 Non-required modules. Just uncomment it and here we go - woirking ftp and NOTE you do no need passive ports opened in your firewall! FTP will work well without it even in passive mode!