Resolved! Proper way to implement DMZ
We currently have an ASA with internal, DMZ and outside interfaces/zones. The DMZ hosts (web servers, ftp server etc etc) tie into the switching infrastructure on an unrouted VLAN. All DMZ hosts have public IPs only. There are no internal IP address...