sk184336 - Hitcount of NAT Rule Base fails after Security Management Server upgrade
Hitcount of NAT Rule Base fails after Security Management Server upgrade
Solution ID
sk184336
Technical Level
Basic
Symptoms
- After upgrading a Security Management Server to R82, NAT rule hitcounts in SmartConsole no longer increase.
- The Last Hit field in NAT Policy > Rule shows a date before the upgrade.
- On the Security Gateway where NAT occurs, traffic captures show that NAT is applied correctly.
These commands on the Security Gateway do not show NAT entries in the hitcount table:
stattest gettable 1.3.6.1.4.1.2620.1.45.5 1 2 3 4 5 6 7
# fw tab -t nrb_hitcount_table -u
- SmartConsole does not display NAT XLATE information for NATed traffic coming from older Security Gateway or Cluster versions.
- NAT logs intermittently do not appear, although traffic passes and other firewall logs are visible.
Cause
A version-compatibility issue between upgraded Security Management Servers (R82/R82.10) and connected Security Gateways prevents complete processing of NAT hitcount and XLATE information. As a result, the Management Server does not fully index NAT counters and translation metadata from older Gateway versions, causing missing hitcount updates and incomplete NAT log fields in SmartConsole.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 6
- Jumbo Hotfix Accumulator for R82 starting from Take 103
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-11-18
Last Modified: 2026-05-26