Thanks LR and AJ for your answers. As far as I understand, I can use the tcp_outgoing_address directive to explicitly specify a different outgoing address for each client subnet. However, what if I would like that the Cisco ASA sees directly the private IP address of the requesting client (kind of having a super-transparent Squid)? I understand this may require some hack, as at the network layer it *is* the Squid which handles the HTTP connections, but would it be possible? Best regards, L.