I dont think you need to worry about ISP routing or adding ARP entry. The policy log indicates that the packet indeed reached the box, got translated to the right IP on port 81.
You might want to look at the internal network.
- Does the server listen on port-81?
- Is the Firewall its default gateway?
- Can you enable src-NAT on the policy (use egress interface IP) and test?
- If you still dont see your IP in the policy logs, debugs will help