Application Control/URL Filtering drops traffic from internal web server
Application Control/URL Filtering has the host object that is automatically static NATed in the destination column.
Application Control/URL Filtering does not recognize the NAT IP address of the object in the Application Control/URL Filtering rulebase.
If inconsistancies may be present if an internal interface topology "leads to" a large subnet or group of subnets which would overlap with the topology of other interfaces - especially interfaces where "Interface leads to DMZ" is checked, as DMZ inclusion explicitly defines that interface as an External Zone.
Further inconsistancies may be present due to a "leads to" overlap as above, depending on the load order of the interfaces by the OS.