So you weren't running into the issue of the base license not allowing
DMZ initiated traffic to the inside network?

"With the Base platform, communication between the DMZ VLAN and the
Inside VLAN is restricted: the Inside VLAN is permitted to send traffic
to the DMZ VLAN, but the DMZ VLAN is not permitted to send traffic to
the Inside VLAN."

http://cisco.com/en/US/docs/security...html#wp1101628

Anthony

chris mr wrote:
> Thanks for your help...
>
> I had to add another static into the ASA and ACL on DMZ in.
>
> mail.domain.com = 12.x.x.x
> EXCHANGE1 = natted ip of Exchange on inside
>
> static (inside,DMZ) tcp 12.x.x.x smtp EXCHANGE1 smtp netmask 255.255.255.255
>
>
> __________________________________________________ __________________________________
> Don't let your dream ride pass you by. Make it a reality with Yahoo! Autos.
> http://autos.yahoo.com/index.html
>
>
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailma...rewall-wizards
>
>


_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailma...rewall-wizards