Hi,
You can do any combination of the above.
If you have a public IP on one interface of the ASA (outside or DMZ) and is reachable via Internet, then you can terminate the VPN on either interface.
Then, with or without NAT you can access resources on any other interface. I have done it a lot of times.
Please explain a little bit better what are you trying to do.
Federico.