Firewall:NAT:Port ForwardInterface:WANDestination: WAN addressDest Port: 22 sshRedirect target IP: 192.168.1.101Redirect target port: 22 ssh
NAT reflection: system default = disabledFilter rule association: Add associated filter rule
In the firewall rule the destination must be WAN_Address.
Would you mind enabling the log option in the port forward? It would help with debugging.Cheers,Franco
Testing from the directly attached WAN can be tricky. Go to Firewall: Settings: Advanced and check "Disable reply-to on WAN rules". It should work without an additional rule then?