L3 Networker

no, DMZ <-> Trust should not require a NAT.


As long as the routing is all square, you won't need anything beyond the security policy. With or without the policy in place, the traffic logs should confirm that.


