An Azure network security service that is used to protect Azure Virtual Network resources.
For anyone looking for a solution to this problem, it seems to be related to the fact Passive FTP establishes different connections for control and data channels. Inbound connections on Azure Firewall are SNATed to one of the firewall private IP addresses to ensure symmetric routing. FTP might fail when data and control channels use different source IP addresses, depending on your FTP server configuration.
Microsoft are aware of the issue (https://docs.azure.cn/en-us/firewall/firewall-known-issues) but it needs upvoting to try to get something done about it.
Preserving the original source IP address is being investigated. In the meantime, you can configure your FTP server to accept data and control channels from different source IP addresses.
Seems a very simple thing to offer - FTP behind Azure Firewall.
https://feedback.azure.com/d365community/idea/590626a0-8fd7-ef11-95f5-6045bd80c60