Ideally I'd like all traffic to route through the ASAv. I created a static route for specific traffic, and that worked, but that's not what I want. I've seen some people talking about setting up a Nat Gateway on the INSIDE VPC, but I'm not sure whether it's supposed to be public, or private, or how that solves the problem. My INSIDE ec2 Linux instances still show the default gateway for the subnet (xx.xx.xx.1). If you manually change it, it just pops back to the subnet default. I guess I could try changing the EC2 eth interface to a static setup, but I have a feeling that won't work. (I've tried changing other network parameters in the past, eg. resolv.conf, and they change right back).