That package has ZERO to do with passive.. Its Active Client Proxy.. Ie client using active connection to server outside pfsense.
When connection in passive mode the internal IP address is given to the client thru the WAN interface
Yeah setup your server to give out your actual public..
here
https://docs.netgate.com/pfsense/en/latest/nat/ftp-without-a-proxy.html
BTW - not related to your ftp problem, but you should be on p3