I have one requirement where need to allow communication to all prots on ASA in dmz.Looking forward so that can place my printer/scanner that can be placed in dmz and can be used from inside network as well as over the internet on all the ports.Also like to have icmp access to and from dmz.
I tried looking at some examples but couldn't got it working.
Find attached the config for your reference.
"I made changes still no internet in dmz."
Make sure client in DMZ has 172.20.40.1 as default gateway, and it has a valid DNS server. For testing purposes, assign 188.8.131.52 as preferred DNS server.
add the following
access-list dmz_in extended permit tcp 172.20.40.0 255.255.255.0 any eq www
access-list dmz_in extended permit tcp 172.20.40.0 255.255.255.0 any eq 53
access-list dmz_in extended permit udp 172.20.40.0 255.255.255.0 any eq 53
The connectivity issue from inside to dmz makes no sense. Try this
no static (dmz,inside) 172.20.40.10 172.20.40.10 netmask 255.255.255.255
access-list inside_nat0_outbound permit ip 192.168.0.0 255.255.0.0 172.20.40.0 255.255.255.0
nat (inside) 0 access-list inside_nat0_outbound
clear local all
Do not ignore clear commands. After ading above, please run the same packet tracer and post the result.