You'll have to use the table for nat and there are two ports envolved.
First step is a destination nat
if you try to reach your public ip on port 21 (the control-channel) forward it to your FTP Server.
You also need the state ESTABLISHED to let things back out.
Then you need the state RELATED for the data channel (port 20) so that your firewall knows to let that port through as well.
Since I don't know the syntax by heart:
http://stackoverflow.com/questions/1...nd-passive-ftp