Why not simply add this a rule to the firewall for your own access when you install the routers ?
I'm sure there is more to it but I'm not sure I would want users making changes to firewall rules.
You could always setup a script I suppose for the user to run that logged into the router and allowed the necessary access temporarily and then removed it once you didn't need it any more but that seems a lot of trouble to go to when you could simply allow that access from the WAN anyway.
In addition if whatever you setup doesn't work for some reason then you are stuck basically.
It's not going to give the LAN users any access to the WAN.
Perhaps if you could clarify why you need it to be done this way ?
Jon