Further to the below mail, another thing that was observed is as follows: The ACLXX is used for dynamic nat. This includes only some IP's. Any ip that does not match this acl will not get natted. When u inlcude a permit any statement in the acl, all ...