There was an SK that explained this nicely (sk108057: What does the box "Interface leads to DMZ" control in interface topology?), but it seems to be gone now. The short answer is that the checkbox causes the interface to be treated as "External", even though it is designated "Internal". Here is an excerpt from my upcoming Max Power 2026 book:
But if it is selected, what does the "Interface leads to DMZ" checkbox actually do? When enabled, this checkbox means that the interface will be treated as "External" in Access Control & Threat Prevention policies. It has a significant impact on how the special object “Internet” is calculated when used in Access Control policies, including APCL/URLF, Content Awareness, and HTTPS Inspection. For example, if "Interface leads to DMZ" is set on a DMZ network interface, and your APCL/URLF policy layer rules utilize the object "Internet" as the matching destination, web and application traffic from the inside network to the DMZ will be inspected by APCL/URLF in the Medium Path! Normally, we would only want to perform this level of inspection on traffic heading to the Internet via an External interface; performance both to and from the DMZ will definitely be impacted!
This setting can also directly affect which traffic the Threat Prevention blades Anti-Virus & Threat Emulation will inspect, which once again can imapct performance:


Additionally, the DMZ designation is considered a possible restriction for where the Captive Portal can be displayed:
Finally, various VoIP Domain object definitions include configuration options such as "Call Manager in the DMZ" & "SIP Proxy in DMZ" & "H.323 Gatekeeper/Gateway in DMZ"; these *may* also be influenced by the "Interface Leads to DMZ" setting, but this relationship is not entirely clear.
Max Power 2026 Book Now Available!
https://www.maxpowerfirewalls.com