/ip service
set ftp port=1899 
 /ip firewall filter
add action=accept chain=input dst-port=1899 in-interface-list=WAN protocol=tcp 
 /ip firewall service-port
set ftp disabled=no ports=1899 
 /user group
add name=FTP policy="ftp,web,!local,!telnet,!ssh,!reboot,read,write,!policy,\
!test,!winbox,!password,!sniff,!sensitive,!api,!romon,!dude,!tikapp"