I appears that your router has all the necessary functions (looks like a pretty good one), please read the manual in full and check this page
http://www.portforward.com/ as well.
I reccomend a static LAN IP configuration - select a private IP address outside the LAN DHCP IP pool of the router, use the virtual server to port forward the directplay ports 47624TCP and 2300-2400TCP&UDP to your static LAN IP, disable UPnP and the preset triggering settings (Application Level Gateway - the one for AOE is the same as OP), disable the DoS settings if enabled.
Alternatively you can leave it as you have it set up for the DMZ, but disable the DoS settings if enabled and be aware that your DHCP assined LAN IP may change requiring you to update your DMZ setting appropriately. For security disable the DMZ when not playing.
Using port forwarding and a statlic LAN IP is the more secure option. You may also be able to leave the DoS setting on and just allow the ICMP requests, but not knowing the UDP packet frequency required for directx gameplay offhand I'd reccomend disabling the DoS settings altogether.
Read that stuff over and just give us a shout if you're still stuck.