If anyone stumbles on this thread now, the fix to OP is within the firewall config file (/etc/config/firewall).
Within the "wan" zone, change:
option input REJECT
to:
option input ACCEPT
I believe the factory config is a security feature, not a bug. Makes sense to deny attempted connections on the target (ethernet) side.