sk176846 - "You cannot use the Network Group [Group Name] as the Original source" validation error when adding a network group to a NAT rule

"You cannot use the Network Group [Group Name] as the Original source" validation error when adding a network group to a NAT rule

Product Security Management
Version R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS)
Last Modified 2026-01-21

Symptoms

Error: NAT rule XXX: You cannot use the Network Group (XXXX) as the Original source.

The Network Group is only valid if the value of the matching translated column is
'Original' or if the translated source is 'Host'/'Address Range' and the Method is
'Hide'.

Cause

This validation error is expected when you use static NAT, which translates only one address.

Solution

This problem was fixed. The fix is included starting from:

Check Point recommends to always upgrade to the Recommended version ( Security Gateway / VSX / Security Management Server / Multi-Domain Security Management Server / SmartConsole).

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Workaround: Use Hide NAT

If you do not want to download the Jumbo Hotfix Accumulator, you can use the Hide NAT option to hide a network or a network object.

  1. Right-click on the translated source object in the NAT policy.
  2. Select NAT Method > Hide.
  3. Install policy.

Important: Be careful when you use this option. Too many hosts could cause NAT Port Exhaustion.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level General
Status Approved by TAC
Date Created 2021-12-08
Last Modified 2026-01-21