Suppose I have an FTP server behind a IPF firewall. Is there an IPNAT proxy mode for /incoming/ passive-mode FTP connections? I.e. is there a more intelligent way to allow passive mode than giving a portrange in ftpd.conf and a corresponding port >< rule in ipf.conf?