I would run tcpdump on the interface you think it answering and look at the packets, and then probe with telnet to the port (vs nmap) and then use the ftp command. I would also use npfctl to examine the rules to make sure the source rules correspond to the parsed rules, the rules you think are loaded are loaded etc.