To /etc/config/firewall
add:
config rule
option name Allow-SSH-WAN
option src wan
option proto tcp
option dest_port 22
option target ACCEPT
option family ipv4
Then:
/etc/init.d/firewall restart