- firewall > rules > LAN :
Action Pass, protocol ipv4 tcp, source LAN net, Port Any, Destination VLAN20, Port 22
- firewall > rules > VLAN20:
VLAN20 does not need opening of SSH port.
I would suggest:
Delete/disable first firewall rule because it makes no sense.
Change your second firewall rule...