I have an ASA 5505 and an XP box in the DMZ. The XP box host IIS FTP and HTTP using one NIC with two IP's. Two public IP's are static NAT'd to the private IP's and the FTP site and HTTP site both work. The problem is I can't browse the Internet from the XP host and I can't ping the external DNS servers from the XP host. In the ASDM log, I get "Deny udp src dmz:my private IP/49126 dst outside:external dns IP/53 by access-group "dmz_access_in".