If a right-click in a rule, I see this option "CONFIGURE RPC PROTOCOL POLICY", and in the description, it is said: "If this is not enabled, the filter will allow aditional RPC type protocols, such as DCOM.
I disabled it so as to allow that DCOM traffic between my DMZ and my LAN, but nothing doing.
My pc's in the DMZ don't get certificates from the CA , placed in the LAN network.
To get certificates, as far as I see on google, that DCOM traffic is needed.