You are not able to access an FTP server running on a control port other than 21 over the proxy; the data channel is not getting open.
This issue is not directly caused by the ProxySG appliance. The appliance understands the request as FTP and provides the access for both passive and active modes based on the policy/configuration. The issue occurs mainly due to an upstream firewall that does not understand the traffic as FTP. From the firewall's point of view, the request is just a TCP connection and the subsequent data connection could be denied. If we provide any-any access to the Proxy’s IP address, access works for passive FTP because the firewall also allows the connection initiated on the data port.