Something you perhaps misunderstand, given what you describe:
when configuring FW, rules apply at "input" level, not "output".
This means that is you want to, e.g. grant access to DMZ from internet, you will have to configure rules at WAN interface, source being, most likely, "*", destination being your DMZ.