Hi there,
Sorry to bother you with silly questions
Can you ping WAN1 from the internet?
Do you have default route to the internet through Wan1?
Is the route through wan1 appearing under Router =>Monitor?
Do you have policy based routes for incoming traffic?
I have noticed if the default gateway is wrong users can go out to the internet but you will not be able to get to the external interface from outside.
If you cant ping Wan1 from outside clear that first. If you can ping then there could be firewal policy issues.
Lastly you did not specify whether NAT is enabled or not for Wan1 => DMZ
hezvo uko