You are doing it right, you want to use
https://fqdn.myserver.domain (whatever matches your certificate's URL). You should always use this unless you want to enable unsecure Web Interface connections. You do this through DMZ settings though.
Absolutely leave IIS on 444 only for it's SSL, you must give CSG 443. It will pass the session to the Web Interface based on your configuration. You can uncheck 'require ssl even, I don't think it will help or hurt CSG.