you created NAT rule so internet can connect to you on port 20. this is not what you want
.
what you want is go to options, Proxy/Firewall/Ident tab, and enable "Limit Local port range to:", set some port range(must be above 1025)
then create NAT rule for that port range.