> Source: [sk184914](https://support.checkpoint.com/results/sk/sk184914)

# sk184914 - Unexpected rule match caused by automatic NAT objects

| Property | Value |
|----------|-------|
| Solution ID | sk184914 |
| Date Created | 2026-05-21 |
| Last Modified | 2026-05-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Unexpected rule match for network traffic. The source or destination network object does not contain the expected IP address.

* The source or destination IP does not belong to the configured network object, but to the network of the automatic NAT object.

## Cause

This behavior occurs when a network object configured with automatic NAT is used in the rule base.  
During policy evaluation, the Security Gateway considers the NATed network range associated with the object. As a result, traffic destined to an IP address within the NATed range can match the rule, even if the original object definition does not explicitly include that IP.  

For example, A network object Net_10.0.0.0_24 is defined as 10.0.0.0/24 with an automatic static NAT to 192.168.100.0/24.  
A connection from 10.1.1.1 to destination 192.168.100.50 on port 80 matches this object because the destination IP falls within the NATed range.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184914/network202605050848582.png)  
![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184914/nat202605050849133.png)  

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
