Session Table Troubleshooting

Use the session table when policy, NAT, or routing changes appear correct but existing traffic still behaves as before.

Filter sessions

diagnose sys session filter clear
diagnose sys session filter src 10.0.0.10
diagnose sys session filter dst 203.0.113.10
diagnose sys session list

Filter by destination port:

diagnose sys session filter dport 443
diagnose sys session list

Clear matching sessions

Clear only the filtered sessions:

diagnose sys session clear

Then clear the filter:

diagnose sys session filter clear

What to look for

  • Source and destination NAT fields.
  • Incoming and outgoing interfaces.
  • Policy ID.
  • Offload flags.
  • Reply direction counters.

If counters increase only in one direction, check routing and return path symmetry.