When setting up a load balancer in front of a Cornerstone cluster, passive FTP is not working.  Wireshark captures indicate a client issued TCP Reset occurring.  Cornerstone logs indicate the correct IP being used in response to the PASV request.  The issue is the rule in the load balancer.  If incorrectly set, it will return an incorrect IP address to the client causing the client drop the connection (TCP RST).  


The resolution is to create a LB rule to use the IP address of the CS server rather than the load balanced IP or the NAT'ed server IP.  


The link below further describes and details the issue and the solution.


https://devcentral.f5.com/questions/passive-ftp-failing-f5-send-tcp-rst-after-receiving-entering-passive-mode-from-server