Hi @MattMiller4305 ,
First of all, FTP is difficult program to filter, firstly because it uses two connections, ans secondly because it may use the data connection in PASSIVE mode.
The filter you show is almost correct if you are NOT using passive mode FTP (i.e. ACTIVE mode)
But you need to change the destination port in the data filter to unspecified.
If you are using FTP passive mode, you need to change the source AND destination port in the data filter to unspecified, and (recommended) set the filter to staeful. (I.e. open all TCP ports from the consumer to the provider EPG). Which, by the way shows a MASSIVE drawback of ACI - for all the song-and-dance made about it being an APPLICATION centric infrastructure, when it comes down to it, it knows nothing about applications apart for TCP/UDP port numbers (and protocol numbers for IP, ethertype for all others).
And FWIW, you COULD make the control filter stateful if you want, but the data filter (for non-passive) needs to be not stateful.
I hope this helps
Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem
RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.