I want to run monowall for the captive portal functionality so even though it's behind a NAT router it will still do us some good.
Your advice is good but what bothers me about getting my ISP to switch to bridge mode is that if monowall fails then I'll be stuck with my network offline waiting for my ISP to switch my router back.
Monowall has the following option which suggests that its OK to run monowall with its WAN in a private address space.
Block private networks
When set, this option blocks traffic from IP addresses that are reserved for private networks as per RFC 1918 (10/8, 172.16/12, 192.168/16) as well as loopback addresses (127/8). You should generally leave this option turned on, unless your WAN network lies in such a private address space, too.
I just want to know why monowall doesn't work
consistently in a chained NAT situation like I described in the original post. It would be one thing if it didn't work at all - I would accept that. However, it works only for a short period of time then breaks. This
suggests a problem with monowall. It's this problem that I am trying to solve.