No that is incorrect, it's not working together. If the port is changed via port setting, you don't need to remove 22 either in CSF. I also got both 22 and custom port open to trick attackers into the firewall. Port is not an addition to 22 but replacement. A connection to 22 wil just be refused...