https://www.howtoforge.com/tutorial/install-proftpd-with-tls-on-ubuntu-16-04/
http://doxfer.webmin.com/Webmin/ProFTPD_Server
In passive mode, the router and firewall on the server side need to be configured to accept and forward incoming connections. On the client side however, only outgoing connections have to be allowed, which will already be the case most of the time.
In active mode, the router and firewall on the client side need to be configured to accept and forward incoming connections. On the server side, only outgoing connections have to be allowed.
Since usually one server provides a service for many users, it is far easier to just configure the router and firewall on the server side once for passive mode, than to configure the client's router/firewall for each individual client in active mode. That is why passive mode is recommended.