>The guys that put socks on our firewall say they've configured it to refuse
>all incoming tcp connections. (I don't have personal knowledge of that though).
If the governing router filters out incoming tcp connections to the
firewall host, then indeed you would need to use the PASV mode for ftp.
But that would apply to your regular ftp as well. So, if you can use
ftp on the firewall host without PASV, you won't need that in your
SOCKSified ftp either. Otherwise you would really need PASV mode.