I have run into two ASA pre 8.3 Problems.

1) importing a deny security rule that had a destination port of 445, was changed to be all tcp ports ( that would be a small problem =D)

2) Importing routes pointed to the inside with a vpn on the outside that has a proxy ID (ACL with a remote destination) of the same inside route changed all of the static routes to no next hop and the tunnel interface as the dest interface. I understand the logic here, however it is flawed and should instead be a policy based forwarding rule that is based on the orginal ACLs source and dest IPs and zones.

