That's correct - since you've set up a 1:1 NAT for an IP address that isn't m0n0wall's own (WAN) IP address, and there is also no upstream router that sends traffic for 10.6.6.9 to m0n0wall, you need proxy ARP so that m0n0wall will "claim ownership" of 10.6.6.9 via ARP.
Yeah, and as a matter of fact, when I create a 1:1 NAT, there's the default checked option of "Auto-add a proxy ARP..." at the bottom.
But is there any 1:1 NAT situation where this proxy ARP
should not be set? I mean, if such situation doesn't exist, maybe a proxy ARP entry
must always be created (and hidden) to make it more transparent and easier to understand; so user doesn't have to scratch his head (and tear his hairs

) to think if any upstream router would route traffic to it.
I notice that in
Interfaces > LAN and
Interfaces > DMZ, there're
Secondary IPs tabs. But there's no such tab for
Interfaces > WAN. Maybe it would be easier, and clearer, if such function also exists for WAN?
I don't know if this is a bug in this version, or if this is a new "feature"... anyway, this isn't documented in the manual...
m0n0wall has always separated NAT and firewall rules, so it's correct and normal that you need to set up both a NAT and a firewall rule in this case. The auto-add feature for normal inbound NAT mappings (checkbox) is only there for convenience.
OK. In that case, it is then necessary to change the doc to reflect such decision. You see, I first followed the "Quick start guide" for generic PC at
http://doc.m0n0.ch/quickstartpc/I've actually followed all 5 chapters to set up a two-NIC m0n0wall. Everything's OK up to here.
Then I jumped to the manual on the part where it's explaining how to set up DMZ:
http://doc.m0n0.ch/handbook/examples.htmlSince I use
1:1 NAT, I've especially read the section on
Using 1:1 NAT and
Test the 1:1NAT Configuration. But after that, DMZ web server just doesn't work as expected. This is very frustrating to new users. Myself, I had to re-read everything, from A to Z, to see where I had missed something, but I just couldn't see what I had missed out. I was about to give up m0n0wall that I told myself "what if I set up a rule??" and that's how I
discovered the lack of such important information in the manual...