I don't understand why your lan/wan manager may not want to make a route to your PIX. What's there point ? This is an efficient solution.
I'd prefer add a route than trying to fool with a second IP address on a server.
Install 2 nic's (1 inside and 1 in DMZ) is not a best practice in security. Why can't you install your WEB server in a DMZ. This is the place where it belongs. Use a switch to plug your server to your pix. If you don't have one I'm not sure but you may have to use a cross-over cable.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...