I had a similiar problem. I was using a private address pool on the VPN (10.1.13.0)Got around this problem by :nat (inside) 6 10.1.13.0 255.255.255.0 0 0global (DMZ1) 6 10.1.13.1-10.1.13.254You can assign a different address range to the global state...