pass in log quick on em0 reply-to (em0 xxx.xxx.xxx.xxx) inet proto tcp from any to xxx.xxx.xxx.xxx port = ssh flags S/SA keep state label "USER_RULE: Remote SSH Admin"
I noted that you said this is for a lab environment. That almost always means private IP address used on the WAN interface. Please double check on the WAN interface settings that the "Block Private Networks" option is not checked. Otherwise it would block all traffic coming into the WAN interface.
Click System>Settings>Administration>...about the middle of the page you have options -Enable Secure Shell-Permit root user login-Permit password loginBelow is the -SSH Port (blank) -enter 22Thats it..no firewal rule...but will be added auto...
I still had a VM that I used after a hardware change to test this with. Confirmed as working. The redacted IP is the LAN IP of the firewall.Bart...