I'll give that a go... Why do you need an additional IP though? Why not just NAT the inside IP to the web interface?I use additional IP addresses for this because I have many such DNAT solutions, and I assign a DNS name to each on our internal DNS server.
How does ASL know to route to the private IP?(Web interface).ASL will route to any address. Just create your host/network derfinitions, and configure your SNAT or route.