Besides changing admin ports from ssh 22 and https 443 try this if you
have and available public ip. Create a new interface on your firewall
making it a loopback interface. Use a private ip /32 host. Example
172.16.1.1/32 or 192.168.1.1. Allow https ...