Ok - I was able to solve the problem by placing the following line in the post-firewall
Where x.x.x.x is the external ip you are accessing the router from.iptables -I INPUT -i ppp0 -s x.x.x.x -p tcp --dport 22 -j ACCEPT
So the my current post-firewall looks like this
Is this the best approach - I took this from the russian forum - but my russian is not great - actually I know none at all - Da!#!/bin/sh
#SSH and FTP access from WAN
iptables -D INPUT -j DROP
iptables -I INPUT -i ppp0 -s x.x.x.x -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -t nat -A PREROUTING -i vlan1 -p tcp --dport 22 -j DNAT --to-destination $4:22
iptables -t nat -A PREROUTING -i vlan1 -p tcp --dport 21 -j DNAT --to-destination $4:21
iptables -A INPUT -j DROP