sk176846 - "You cannot use the Network Group [Group Name] as the Original source" validation error when adding a network group to a NAT rule
"You cannot use the Network Group [Group Name] as the Original source" validation error when adding a network group to a NAT rule
Product Security Management
Version R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS)
Last Modified 2026-01-21
Symptoms
- This validation error appears when the user tries to add a network group to a NAT rule:
Error: NAT rule XXX: You cannot use the Network Group (XXXX) as the Original source.
The Network Group is only valid if the value of the matching translated column is
'Original' or if the translated source is 'Host'/'Address Range' and the Method is
'Hide'.
Cause
This validation error is expected when you use static NAT, which translates only one address.
Solution
This problem was fixed. The fix is included starting from:
- Jumbo Hotfix Accumulator for R82 starting from Take 25
Check Point recommends to always upgrade to the Recommended version ( Security Gateway / VSX / Security Management Server / Multi-Domain Security Management Server / SmartConsole).
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Workaround: Use Hide NAT
If you do not want to download the Jumbo Hotfix Accumulator, you can use the Hide NAT option to hide a network or a network object.
- Right-click on the translated source object in the NAT policy.
- Select NAT Method > Hide.
- Install policy.
Important: Be careful when you use this option. Too many hosts could cause NAT Port Exhaustion.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level General
Status Approved by TAC
Date Created 2021-12-08
Last Modified 2026-01-21