Because of how CloudStack configures the firerwall on the router VM, you need to allow traffic to the private port instead of the public port.