You would need to open a ton of ports. MS networking does not play nice with DMZs at all. I would recommend moving that machine off of the dmz. If you want it to be on the domain, you need to open udp/tcp 135-139, 445, and others. and you need to disable nat between the interfaces.