> Source: [sk184998](https://support.checkpoint.com/results/sk/sk184998)

# sk184998 - Default Office Mode pool object reappears with Automatic Hide NAT after Security Management upgrade, causing unintended NAT

| Property | Value |
|----------|-------|
| Solution ID | sk184998 |
| Date Created | 2026-06-04 |
| Last Modified | 2026-06-08 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS) |

## Symptoms

- After upgrading the Security Management Server, the network object **CP_default_Office_Mode_addresses_pool** appears (or reappears) in SmartConsole.

* The object has Automatic Hide Network Address Translation (NAT) enabled by default.
* Installing the policy creates an automatic Hide NAT rule that references this object.
* Production traffic is unexpectedly translated using Hide NAT.
* This occurs when the Office Mode pool overlaps with internal network ranges.

## Cause

The **CP_default_Office_Mode_addresses_pool** is a default system object used by Remote Access Virtual Private Network (VPN) Office Mode.

During the the upgrade:

* The migration process checks for required system objects.
* If the object is missing, the system restores it automatically.
* The restoration enables Automatic Hide NAT by default.

If the configured Office Mode network overlaps with internal networks:

* The system generates a Hide NAT rule during policy installation.
* Traffic that matches the overlapping subnet is translated.
* This leads to unintended NAT of production traffic.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
