I'm guessing (and purely a guess) that coming in the LAN of the RT is different, either NAT, Firewall, or otherwise, than coming in through the WAN. Once in the LAN of the RT, going out the WAN is transparent. I am knowledgeable about networking, but by no means a pro. A side benefit of doing it this way is one can "manage" the RT through a normal IP address since it's on the same subnet.

My RT is running 1.25.00.

/c