firewall/router that is in front of that 2021 server needs to have some port range open for data connections. pick some unique range(different from range used by server on port 21), IIS instructions found
here and then forward that same range in your firewall/router