# Incorrect zone assignment occurs when NAT rulebase returns HOLD

## Product
Security Gateways

## Version
R81.20, R82, R82.10

## Symptoms
- NAT rulebase includes objects requiring domain resolution, causing HOLD state.
- Traffic is NATed (source or destination modified).
- After NAT, policy using zone-based classification miscalculates zones.
- Expected rule is skipped because zones are calculated on pre-NAT IP.
- Logs or debug show incorrect zones. The kernel debug output for NRB module shows the following lines:

```
@;13594.37801;21Dec2025 8:48:19.412211;[vs_0];[tid_0][fw4_0];fwconn_key_lookup_app_opaque: conny.y.y.y:443 IPP 6> found in connections table (id=18);
@;13594.37802;21Dec2025 8:48:19.412222;[vs_0];[tid_0];[fw4_0];1:{session}nrb_handle_set_connkey: received INzone = External OUTzone = External (SYN 0);
```

In this example, traffic from x.x.x.x arrives from the internet and tries to access y.y.y.y which is a static publish IP of an internal server with a private IP that was NATed publicly. Since it is an internal server, the zone calculation should have been INzone =External OUTzone =Internal

## Cause
When NAT rulebase triggers HOLD (connection paused for domain resolution), the gateway calculates zones based on pre-NAT IP and does not recalculate after resume.

## Solution
This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2026-01-15
Last Modified: 2026-07-23
