Thanks !
To do what you want, stateful inspection would have to be turned and that is probably not a good idea, even if it's done at a granular level. When I look at how I install firewalls for this type of use case, I typically have an outside (WAN) interface, and inside (LAN) interface and a DMZ or multiple DMZ interfaces (OPT). The inside interface has no hosts and is connected to the inside router like you have, and my DMZ hosts are on a dedicated interface so I don't encounter this issue and it's a model I find works well.
Would you consider adding another NIC for your DMZ hosts ?
Thats probably the best way to go about this ... my problem is my M0n0wall is now a plane flight away from me ... although next time I am out that way I will add another nic to the box. In the mean time is there a way to disable stateful inspection for specified traffic? The alternative is to push local routes on the boxes which bypasses the M0n0wall any how.