I have the same type of setup (DSL+OpenWRT), with the exception of
having a static IP address.  I forward port 22 connections on the
external interface to my Linux box behind the firewall.  I only allow
SSH port 22 connections TO my firewall from BEHIND the firewall.
Works out nicely. ;-)  I do want to put in OpenVPN at some point,
though.

-- 
Chad Walstrom <chewie at wookimus.net>           http://www.wookimus.net/
           assert(expired(knowledge)); /* core dump */