In your NAT settings, you might try adding an accept rule for src-address of pppoe interface IP range to dst-address of DMZ interface IP range. That will bypass the other NAT rules.