sk184530 - Incorrect zone assignment occurs when NAT rulebase returns HOLD
Incorrect zone assignment occurs when NAT rulebase returns HOLD
Product
Security Gateways
Version
R81.20, R82, R82.10
Symptoms
- NAT rulebase includes objects requiring domain resolution, causing HOLD state.
- Traffic is NATed (source or destination modified).
- After NAT, policy using zone-based classification miscalculates zones.
- Expected rule is skipped because zones are calculated on pre-NAT IP.
- Logs or debug show incorrect zones. The kernel debug output for NRB module shows the following lines:
@;13594.37801;21Dec2025 8:48:19.412211;[vs_0];[tid_0][fw4_0];fwconn_key_lookup_app_opaque: conny.y.y.y:443 IPP 6> found in connections table (id=18);
@;13594.37802;21Dec2025 8:48:19.412222;[vs_0];[tid_0];[fw4_0];1:{session}nrb_handle_set_connkey: received INzone = External OUTzone = External (SYN 0);
In this example, traffic from x.x.x.x arrives from the internet and tries to access y.y.y.y which is a static publish IP of an internal server with a private IP that was NATed publicly. Since it is an internal server, the zone calculation should have been INzone =External OUTzone =Internal
Cause
When NAT rulebase triggers HOLD (connection paused for domain resolution), the gateway calculates zones based on pre-NAT IP and does not recalculate after resume.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 19
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General Status: Approved by TAC Date Created: 2026-01-15 Last Modified: 2026-07-23