FW_LOAD_MODULES="ip_nat_ftp"
That fixed it. After a little research, I see these kernel modules are directly applicable to netfilter / iptables. Is there somewhere that they are well documented? I searched http://www.netfilter.org/ for a while and couldn't find any clear detail on ip_nat_ftp and ip_conntrack_ftp or if there's even any other modules that might be useful.
If you want to know more about the innerdepths of netfilter, maybe you should subscribe to one of their mailinglists. But on the site is quite a lot of documentation. I did not search it for ip_nat_ftp, so I do not know if there is something in there already. IPtables is a work in progress, new modules getting born from time to time.
Try http://www.netfilter.org/documentation/HOWTO//netfilter-extensions-HOWTO.htm l