My customer has an ASA and has several VPN users. THey are currently using Split tunneling for local internet access. The customer want the VPN users to use his Internet Access (via the ASA) when they are up on the VPN. Since the VPN is on the outside interface as well as the Internet how do I perform the NAT going from private to public. The ASA will not allow me to add a NAT using the outside interface as both source and destination. Is this a valid application and if so what must be done to make it work.