Bridging OPT1 with WAN was what I did and its, by far, one of the simplest configurations. Be aware that this will make it impossible to configure CARP fail over.
Alternatively you could use Proxy Arp, which would require some minor configuration of your DMZ machines. This (I think) will also break CARP fail over, and frankly, I can't think of any good reason to use this solution verus bridging the two interfaces.
Finally, you could alias a bunch of IP addresses to WAN and use 1:1 NAT. This is the most intrusive solution in terms of configuring your DMZ machines, but it means you can use CARP failover without drama and would allow you to obscure the actual IP addresses of your DMZ machines.