To answer the question on dual SSID or dual routers - the AT&T Gateway/router is set to DMZ (i.e. it passes through). The Asus router get the WAN IP directly from AT&T - NOT from the gateway. The WAN IP shown in the Asus router is: 2X.XXX.XXX.252. The Wi-Fi is turned off on the gateway. Also everything is hardwired through CAT6 per the OP.
The single piece of equipment missing from the OP is a TP-Link 24-Port Gigibit Switch.
The reason I am using the Asus router is because it is a much better piece of equipment than the AT&T unit (Pace something); particularly for wifi for our tablets and phones and configuration ability within the router
All firmware/software is up to date.
Everything has been shut down, unplugged, rebooted, etc. multiple times.
A router isn't supposed to see the public IP address, it's supposed to receive a private IP address from the modem. Any other connection to the outside world is done through port forwarding/VPN. ATT uses gateways as their way to control their network and in theory, decrease problems. They do not support our quest for more advanced connections and real world use of the internet, they are there to provide basic streaming, e-mail and web browsing. It's a more simple existence for them and for many customers, it works. For the rest of us, it's a royal PITA.
I would recommend turning off the radio in the gateway and use only the ASUS- it avoids many issues. Change the 5Gb band's encryption key to something that will prevent anyone using it- in my ATT gateway, it can't be turned off- only 2.4 can be disabled. One thing that might make me use the ATT WiFi is the fact that it's .ac-enabled, but the rest of my equipment isn't and I prefer to hard-wire everything but the devices that have no ethernet port. I used a Luxul router for WiFi, but turned off NAT and put it in Bridge mode- it worked great and I didn't use DMZ for the two Roku units. Never had the problems you are, either. Now that the new ATT gateway is here, I really haven't needed to use something else for WiFi because the new hardware is much better- ask if you can upgrade, but refuse to pay for anything. Cable providers don't charge a full price for their equipment, ATT shouldn't, either. I would prefer that they offer a simple modem, but U-Verse isn't the same as simple DSL, according to their upper tier support.
If you want to use a simple modem, you'll need to change providers.
Why, again, are you using the DMZ?
Didn't see the smiley after the question about unplugging, eh?