create access-list tcp destination any ip-port 21 source segment/mask ip-port any deny ports any precedence xxx
て感じ?