Because of how CloudStack configures the firerwall on the router VM, you need to allow traffic to the private port instead of the public port.
Because of how CloudStack configures the firerwall on the router VM, you need to allow traffic to the private port instead of the public port.