- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello Team,
We are planning to test a NAT configuration on R81.20.
If I set a Network Group as the source, the following error is displayed.
"The Network group is only valid if the value of the matching translated colum is 'Original' or if the translated source is 'HOST' /Address Range and the Method is Hide."
I want to configure NAT for a Network Group. In this case, do I need to set up Hide NAT for each individual object separately?
Thank you for all the advice.
Hi @TSOL
The easiest way to set up a NAT on a specific network, if you set it on the object itself:
Here:
I hope it helps 🙂
Á
The network group is the Original Source? What did you set the Translated Source to?
Dear emmap
Thank you for the reply.
Yes, I want to set the Network Group as the Original Source and translate it to the IP address of the Out-side interface as the post-NAT IP address.
I believe that should work as long as you set the translated side to Hide NAT.
I mistakenly thought that I needed to add Hide NAT to the Network Group in the Original Source.
It turns out that I need to configure NAT for the object in the Translated Source instead.
Thanks!
Hi @TSOL
What I told about NAT that is an easy way. If you want to do manual NAT instead, feel free, and do it, the two solution is fully equivalent.
Akos
Hi @TSOL
The easiest way to set up a NAT on a specific network, if you set it on the object itself:
Here:
I hope it helps 🙂
Á
Thank you for the reply.
Does the response differ from the behavior when configuring NAT for the Translated Source?
Hi @TSOL
From the NAT point of view, this will act as a manual hide NAT.
As you configure on the network object, you will see it in the NAT table, but you can edit the rule by editing the host object.
Akos
In our scenario we cannot use the hide nat. There is a reason for it. I have a different scenario. We have different third-party networks connected to our datacentre through checkpoint firewall. each third-party zone will have different network. While accessing the different third-party destination IP or vice-versa we use different NAT based on the zone. If I am adding object group in the original source, adding a /32 IP object in the original destination and and adding a /32 object in the translated source it is giving the same error like above user mentioned. This was working prior to GAIA R81. I have even rules now in my firewall in the similar way that i have stated above. But now in GAIA R81.10 it is not allowing the same similar way of adding the NAT. Can you please help me by providing some inputs
As far as I know, this behavior hasn't changed.
Please provide a precise example, possibly with screenshots (sensitive details can be redacted).
The below answer came from our AI Copilot.
This is applicable if you want to use a manual NAT rule (versus using automatic NAT rules in the object):
The error you're encountering is expected when using static NAT, which translates only one address. To configure NAT for a Network Group, you should use the Hide NAT method. Here's how you can do it:
No | Original Source | Original Destination | Original Service | Translated Source | Translated Destination | Translated Service | Install On |
---|---|---|---|---|---|---|---|
1 | Network Group | Any | Any | Single IP/Range | Original | Original | All |
By following these steps, you can configure Hide NAT for a Network Group without setting up Hide NAT for each individual object separately. If you encounter any issues or need further assistance, feel free to ask!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
20 | |
18 | |
18 | |
11 | |
11 | |
7 | |
7 | |
7 | |
6 | |
5 |
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY