This is definitely not an ISP issue because it works direct w/o monowall.
That's not true, and leads me to another suggestion.
If you're using a different machine on that IP, and then switch it out for m0n0wall, you're going to be stuck for a few hours with virtually all ISPs because of the ARP cache on their routers. Cisco's default is 4 hours, in that case you'll have to wait 4 hours after disconnecting the previous machine before it'll work on m0n0wall.