Once u insert a dedicated FW, you are basically separating the functions that your One Box used to do.
With a dedicated FW, you should end up with: Plain-Modem–---FW-----AP.
You have what I call a Gateway, a 3/4-in-1 box: Modem+NAT+WIFI+4portSwitch. ISP loves to give u those because is easier to maintain one box than 3 or 4, but that construct doesn't work for people who want a dedicated FW, and you cannot disassemble, and often cannot disable part of the Gateway you don't want. For example I had an AT&T Gateway that I cannot disable its NAT. A dedicated FW will be doing NAT, so now you are double-NATing, not a good situation.
Want dedicated FW, you will be playing with the big boys$$.