hi .. for access from Internet to internal hosts you need a static NAT and and access-list allowing that traffic
access-list 101 extended permit tcp any host xx.xxx.xxx.xxx eq www
access-group 101 in interface Untrust
static (Trust,Untrust) xx.xxx.xxx.xxx 192.168.1.231 netmask 255.255.255.255 dns
for allowing access from trust to outside you need a combination of global and nat. and you can create an access-list for controlling the traffic
access-list Trust-Outside extended permit ip any any
access-group Trust-Outside in interface trust
nat (trust) 10 0 0
global (untrust) 10 interface
To allow access to Internet from the wireless zone you have done it already.
to allow access betwen wireless and trust you can use static nat and access-list to control traffic
static (trust,wireless) x.x.x.0 x.x.x.0 netmask 255.255.255.0
where x.x.x.0 is the range of the trust segment
access-list wireless extended permit ip any any
access-group wireless in interface wireless
I hope it helps .. please rate it if it does !!!!