We are looking for a "NAT" recipe for the ASA\PIX as it is becoming an issue every once in a while, and troubleshooting NAT's are troublesome for example:
1) NAT hosts or networks between different security level interfaces (inside to dmz, etc.). Do we use a static nat or just a nat (interfacename)
2) uni-directional vs. bi-directional traffic between different security level interfaces
3) managing and monitoring nat's
4) troubleshooting nat's with either a debug (asdm, etc.)
5) when we nat, does it have to follow an ACL to grant that traffic to a particular interface?
any suggestions?