For this external switch ( internet one side , firewall the other ) we are using vr vr-default ..
Thought the ip address of the switch for management is on vr-mgmt ..
So basically
I would disable ssh2 vr vr-default , enable ssh2 vr vr-mgmt ..
That should stop the external hits we are getting for ssh..