06-02-2009 07:21 AM
One-armed designs are fine in most of the cases and you are not going to loose any features.
Limitations start as soon as you go to deploy DSR in a one-armed design. Features requiring the ServerIron to work in proxy mode do not work anymore in a one-armed DSR design (SSL offload, l7 switching, application firewalling, syn-proxy...).
A source-nat based one-armed design should not result in any feature problem except the fact that you are replacing the source-ip.