# "You cannot use the Network Group \[Group Name\] as the Original source" validation error when adding a network group to a NAT rule

**Product** Security Management  
**Version** R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS)  
**Last Modified** 2026-01-21

## Symptoms

- This validation error appears when the user tries to add a network group to a NAT rule:

```
Error: NAT rule XXX: You cannot use the Network Group (XXXX) as the Original source.

The Network Group is only valid if the value of the matching translated column is
'Original' or if the translated source is 'Host'/'Address Range' and the Method is
'Hide'.
```

## Cause

This validation error is expected when you use static NAT, which translates only one address.

## Solution

This problem was fixed. The fix is included starting from:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 25

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ( [Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

**Workaround: Use Hide NAT**

If you do not want to download the Jumbo Hotfix Accumulator, you can use the **Hide NAT** option to hide a network or a network object.

1. Right-click on the translated source object in the NAT policy.
2. Select **NAT Method** \> **Hide**.
3. Install policy.

**Important**: Be careful when you use this option. Too many hosts could cause NAT Port Exhaustion.

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level** General  
**Status** Approved by TAC  
**Date Created** 2021-12-08  
**Last Modified** 2026-01-21
