I am trying to fix a similar situation.
I need the "Masters" to review my configs so I can share the knowledge.
I can get to the Internet from the DMZ and the inside interfaces.
I'm trying to allow the inside interface to be able to access anything in the DMZ.
I would like to be able to browse the webpages.
Also I am trying to allow remote desktop into the DMZ...I want to keep the DMZ limited to the access rules and ports defines.
I've got several public IPs that go to go to the DMZ and Inside depending on the port and service.
I've attached a clean detailed config.
My first thought is to cut back on your ACLs
access-group outside_access_in in interface outside
access-group inside_access_in in interface inside
access-group inside_access_out out interface inside
access-group DMZ_access_in in interface DMZ
access-group DMZ_access_out out interface DMZ
I would take all of the ones that are outbound off, leaving only the inbound access lists.
When you did your statics, did you clear your xlate table? (clear xlate ) Generally the port translation error comes from the translation not being recognized, and you have to clear the table, or reboot the device, before they'll be seen.