Well, you will have to set up firewall rules permitting the traffic your DMZ machines will need. Port 80 and 443 for fetching updates (unless you run a local mirror server in your network) are commonly needed as destination ports.
Yes. That’s just a checkbox to enable for the firewall rules in question.