I've created an ACL to my internet facing VLAN and configured a DST-NAT rule to allow RDP to an inside host.
This is working just fine when I use "localip" as destination, but I would like to use another IP on the WAN-subnet for this kind of traffic. But I can't get the WLC to respond to the traffic. I believe this is an issue with proxy ARP.
ip access-list session ACL_WAN
any alias localip tcp 3389 dst-nat ip 10.103.10.23 3389 log