This really helped me too! I actually had "ip access-group 100 out" on the WAN side and this caused big problems. I was loosing hours of troubleshooting NAT..and then I just removed it...the more specified ACL did it for me too...WOW...what a relief....