Done!
I had listed it out under excluded addresses, but it's easier just to remove it from the pool.
I've also gone back into the ATT gateway and re-enabled IP Passthrough (family is in bed). Everything is still working, even after a reboot and refresh of IP lease
Apparently, adding the DNS IP address was the key to making this all work. I didn't do that last night, and if I remove the DNS IP address now, I lose internet.
I think the next thing I want to do is enable LAG for the WAP, or should I work on VLANS?
Either way, I'm done for tonight. Early baseball games tomorrow
Seriously, I can't thank you enough for all the help so far.