Couldn't tell you why yours isn't working, but I can tell you that, if I disable port forwarding of the 55536-55663 range through the firewall and on to my DNS-323, when I try to connect with Filezilla, FTPES, active or passive mode, Filezilla gives an error: "Server sent passive reply with unroutable address. Using server address instead."
If I turn right back around and re-enable the port forwarding on that range, it works perfectly fine.
This was the whole problem in the last two FW versions, D-Link didn't bother to let anyone know what passive port range needed to be forwarded, along with whatever traditional FTP port you chose to use, to allow the SSL/TLS communication to work.
You are still forwarding your active FTP server port through the firewall in addition to this passive port range, right?