A naso mi sembra che queste regole siano incomplete

$IPTABLES -A FORWARD -i $WAN
$IPTABLES -A FORWARD -o $WAN
$IPTABLES -A FORWARD -i $WLAN -o $LAN -j ACCEPT
Io farei tipo

$IPTABLES -A FORWARD -i $WAN -o $WLAN -j ACCEPT
$IPTABLES -A FORWARD -o $WAN -i $WLAN -j ACCEPT
$IPTABLES -A FORWARD -i $WAN -o $LAN -j ACCEPT
$IPTABLES -A FORWARD -o $WAN -i $LAN -j ACCEPT
$IPTABLES -A FORWARD -i $LAN -o $WLAN -j ACCEPT
$IPTABLES -A FORWARD -o $LAN -i $WLAN -j ACCEPT