its not required to nat if its a directly connected network, http://www.cisco.com/warp/public/556/nat-cisco.shtml route add would be enough..this might help u.renil
hi u mean to say 192.168.149.1 should be goin online with object-group USER-SERVICE rite, then this would help#access-list inside_out extended permit tcp host 192.168.149.1 any object-group USER-SERVICEthanks