just verified that a host using "XP" desktop using it's CMD in a network created on a 5510 ... say a DMZ ... is not able to FTP out to the Internet. ACL for this DMZ interface is allowing any any outbound. Would the current "ftp mode passive" statement effect this type of request?
All ftp connections should negotiate a passive port if a DATA channel can not be opened, if the FTP server is configured for passive connections.
Check your config and check the logs.