You will need a static translation, you can use either your interface ip or another ip address if you have a pool of addresses.
ip nat inside source static tcp 192.168.1.1 21 interface FastEthernet0/0 21 or
ip nat inside source static tcp 192.168.1.1 21 2.2.2.2 21
192.168.1.1 would be your ftp server. You can then restrict traffic inbound on the outside interface assuming you know the ip addresses that will be accessing the ftp server.
Hope this helps.