where are you running nmap from?
If it's from a host on the inside, then it's working as expected, as it will be the "LAN_LOCAL" firewall (default = accept) that is allowing the packets through, rather than the "WAN_LOCAL" firewall that you want to be testing.