you but whether it's the best as your firewall depends on your need.

Most rule-based firewall (built-in or third party) let you configure which items to allow (port and I'm sure you know already.. the passive or active ftp ports).

If you have router... the better.