Yes, my example of passive FTP is the correct way to deal with this. It will also be userfriendly when your customers themselves sits behind NAT that allows for outbound connections but not incoming connections.
When you configure the portrange you make sure that no other app on the server will listen to the same portrange so the security isnt affected. Your security is broken the moment you let anything speak to the cmd-channel of the FTP server.
The ALG’s is and always have been broken no matter what the vendor is.