Please check AP-ROLE and make sure FTP is allowed there.
I would recommend you to open a TAC ticket to debug the issue.
To troubleshoot the issue, here is what I would check:
1. session on port 4500 from RAPs outer ip. You cn check this in datapath session table.
2. If session is there , that check for "show crypto isakmp sa" from CLI enable mode.
3. If it is there, check for "show crypto ipsec sa". Also check Inner ip-address of the RAP here.
4. Do "show user-table verbose" and see whether RAP is in the AP-Role or not.
5. From the inner IP address of the RAP. check datapath session on port 21 (FTP), 8209 (Sec-PAPI).
Hope this will help.