It is required for antispoofing feature in your case and cose sometimes handy in other cases, like for example hide all traffic behind external gateway IP in with one checkbox.
Internal interface would mean that you have only specific networks behind it:
- Network defined by the interface IP and Net Mask - There is only one network that connects to this internal interface.
- Specific - There is more than one network that connects to this internal interface, select a group.
External interface - all other networks, not defined as internal ones or Sync.
Of course you can disable antispoofing at all and not think about it, which I would highly not recommend.
In my opinion, this is how to choose an external interface in this case - leading in the direction of internet connection (default route), all protected networks (for example networks with some specific servers) which you can define are behind other (internal) interfaces, in that direction there are many network, which cannot be easily defined and they are not part of protected scope of this gateway.