As zimmerfrei said, it allows one webserver to connect to another (e.g. a load balancer, with a certificate, to connect to a backend webserver) and present that cert to the server it is connecting to.
Without the client EKU bit, a conforming TLS implementation would reject the connection.
Without the client EKU bit, a conforming TLS implementation would reject the connection.