As a general rule, do those of you that administer a large number of users ( >1k ) and NAT them, do you have a single IP or a pool of IP addresses for general web access? I've run several thousand ...
ip nat inside source list 120 pool NAT-POOL:Internet overload ip nat inside source route-map NAT-INTERNET pool NAT-POOL:Internet access-list 120 deny ip 10.0.0.0 0 ...