"Additional NAT Rule" appearing in a log card indicates that a second NAT rule was matched for the same connection. This is only possible if "bi-directional NAT" is set in the NAT Global Properties (it is set by default), and one automatically-generated NAT rule matches the source IP address of the packet, and another automatically-generated NAT rule matches the destination IP address on the packet. In this case both source IP and destination IP for the connection are NATted simultaneously. Most common NAT operations only change either source or destination but not both; this condition is an exception to that and certainly possible.
Note that this can only happen for two automatically-generated rules; if a manual NAT rule is matched first, only that one NAT rule can be matched, and an additional NAT rule match is impossible. It is also not possible to have an automatically-generated rule match one element of the packet (say source IP address) and a manual rule then match a destination IP address. Only one manual NAT rule can be matched for a connection, period.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com