NAT and ACLs Together on ASA 8.3+: Real IPs, Not Mapped IPs
Since ASA 8.3, interface ACLs reference the real, post-translation IP, never the mapped one. A before-and-after on one flow, allowed with a real-IP rule and dropped with a mapped-IP rule, settles the most misunderstood ASA behavior.