firewall rule LAN -> any -> WAN -> any -> all service allow, log if you wish to. The rule should created in both FWs. There is a default NAT created so you do not need to create another NAT.
That will not work unless your modem is in router mode, if bridge mode you will need to change your external address so that it picks up a real routeable address.