When you tried your own DNAT and firewaill rules, on the firewall rule that opened port 22 did you also include the address 192.168.4.1 along with the port in the destination part of the rule? I am not sure if this will work but it seems like it should.
↧