/ip service
set ftp port=1899
/ip firewall filter
add action=accept chain=input dst-port=1899 in-interface-list=WAN protocol=tcp
/ip firewall service-port
set ftp disabled=no ports=1899
/user group
add name=FTP policy="ftp,web,!local,!telnet,!ssh,!reboot,read,write,!policy,\
!test,!winbox,!password,!sniff,!sensitive,!api,!romon,!dude,!tikapp"