sounds like you have your head on straight, for your IP rules see below.
wan_to_dmz - See the basic port forward FAQ, this is no different than normal.
dmz_to_wan - copy the lan_to_wan folder for immediate success.
on your local rules I am going to write something that just does wide open routing, and you can make it secure later.
lan_to DMZ - Source: LAN / LAN_Net Destination: DMZ / DMZ_Net Service: all-services Action: Allow
dmz_to_lan - Source: DMZ / DMZ_Net Destination: LAN / LAN_Net Service: all-services Action: Allow