If I've understood you correctly, you're pinging your ISA server by name and the address being reported is the WAN address. Does this occur only when you establish a tunnel or immediatley after booting your 9x clients?
I would suggest you get hold of a copy of cyberkit - www.cyberkit.net -, install it on one of your 9x clients and have a nose around with nslookup to see what's happening in name resolution. Using tracert (also in cyberkit) to see what path you're using to your ISA server might help as well.
At a wild guess, I suspect you're not looking at your local DNS for initial name resolution.
Mike