Thanks. I should have said, this is an Asus RT-AX56U running Asuswrt-Merlin
I have SSH set up, and when I open the port (not using 22 :) to the WAN via the settings in the web admin interface, it works.
But if I leave it set to local-only in the web interface, and then add those iptables rules...