Most people who manage firewalls have locked themselves out of the firewall after pushing new rules at least once. I'll be the first to admit that it has happened to me on more than one occasion.
Firewall Builder includes a neat feature where you can define an IP address or IP network that should always have SSH access to the firewall. This gets installed as a rule above the rest of the regular user defined rules to ensure that you don't lose access after pushing changes to the firewall.
This short video shows you how to configure which address or network should always have access to the firewall.