The main thing here is you are showing 2 different session in 2 different directions and from both sessions you only show half the communication, specially missing in the first part is the line similar to this one:
Response: 227 Entering Passive Mode (192,139,152,155,237,68).
What we advise with FTP servers is to use passive mode and to use a fixed range of max 500 ports, when less busy use a range of 100 ports.
Most of the FTP servers nowadays use TLS also, causing the communication to fail as the FW cannot see the PASV command
anymore. Therefore just allowing the FTP port and the range will still allow the traffic and still be reasonable secure.
Regards, Maarten