>You are correct.  NAT will not pass standard FTP sessions.

That's right. By the way, the Linux IP masqerading won't either.

Your solution ...

>                                                            Most FTP
>clients and servers now support the "passive" option.  This makes FTP use
>the control channel instead of opening a separate data channel for passing

... is correct, but the explanation is not really correct. There's still
a separate data connection, but it's opened by the client instead of
being opened by the server. (And thus there's no need for translating
the address of the client's listening socket as in the usual mode.)

Regards, Felix.