We have an ASA in AWS and it has 2 VPNs, 1 to AWS (subnet A) and 1 to Azure (Subnet B)All traffic from the ASA to subnet B is source NAT'ed, so we never have to change or add subnets when going to subnet B.Subnet Z is on the inside interface of the A...