I have a customer who is adding a second internet T1. The ISP delivers the Internet as ethernet via their CSU/DSU. It seems the ASA cannot load balance two outside interfaces so I seem to have to add a router between the ASA and both ISP connections. Can I just do a 1:1 NAT from the 831 and ASA (their interfaces to each other being on a seperate subnet). This client does run VPN and have inbound translations, which I assume I would just change on the ASA to accept from the router, with the router accepting all traffic. Any advice?