Hi:
As I understand, your problem is the internet access from lan.
I need more data about your network topology, but as I can see your clients on the lan net have access to internet by the wan interface, and in the wan interface you have one router that is NATing ports.
In that case you need configure the firewall as transparent mode and configure the lan and wan interfaces of the firewall and the router interface in the same subnet with different ip, and the gateway ip must be the router ip.
If this is not as I tell you please, give more data.
Regards