The topology you described indicates the new wireless router (I guess this is the one that will run the hotspot) is connected directly to the modem. “Another port from the DSL Modem would go directly to the new wireless router.” In that case I don’t understand what you mean by “Public wireless router LAN IP” is NATed to 192.168.100.1? I understand the firewall would do the NATing, not the modem? In either case, the hotspot should still work fine as long as it gets internet. If you place the router behind the firewall you would need to open the folowing ports, as per this article: http://hotspotsystem.com/deskpro/kb_article.php?ref=3580-WCBN-3010

2 The router needs to be in AP mode for the hotspot to function, don’t use repeater mode, and don’t plug any repeaters behind the router as the hotspot won’t work properly!

3 You should consider the differences between the two firmwares. DDwrt gives you more management options, while open mesh gives you cloudtrax, an easy to use, but restricted web based interface. Open mesh is easier to install then ddwrt, and there is a strict method to configuring the routers when used in a chain, especially with WDS.

4 By design firewalls block incoming connection from the public interface, unless it is traffic in response to a connection that was initiated from the secure network. See context based access control: http://en.wikipedia.org/wiki/Context-based_access_control