We are using "nat-control" on existing FWSM, and will migrate to ASA5585X v9.1.On the new ASA code, "nat-control" is gone, I got that. And traffics from higher security interface to a lower security interface will be allowed by default, furthermore, ...