BUT, that client management server has to be joined to AD. I made an offhand comment that, well, that's fine, just setup your ASA 5515X's DMZ to Inside ACL to allow that. The guy comes back and ...