I have a very simple setup but it seems puzzling to figure how to restrict ASA to proxy-arp only for NAT entries and not for the entire outside interface subnet. Currently in the sample config I have below where I am testing ASA5512 with 9.15x code,...