I had a post with a 6.3(4) referring to the same issue, so now Ive treid the same with an ASA.
ip add 172.20.1.1
ip add 10.10.10.1
nat (dmz) 1 192.168.4.0 255.255.255.0
global (inside) 1 interface
nat (inside) 2 172.20.1.0 255.255.255.0
global (outside) 2 10.10.10.2
ACL's on inside and dmz permit ip any any and permit icmp any any
I want to be able to access inside&outside and I cant.Only one works at a time: either from dmz to inside or dmz from outside, depending on how you play with the NAT.
PS: Static is out of question as I have around 20-25 networks on the inside to be accessed from the dmz.