Session Table Troubleshooting
Use the session table when policy, NAT, or routing changes appear correct but existing traffic still behaves as before.
Filter sessions
diagnose sys session filter clear
diagnose sys session filter src 10.0.0.10
diagnose sys session filter dst 203.0.113.10
diagnose sys session listFilter by destination port:
diagnose sys session filter dport 443
diagnose sys session listClear matching sessions
Clear only the filtered sessions:
diagnose sys session clearThen clear the filter:
diagnose sys session filter clearWhat to look for
- Source and destination NAT fields.
- Incoming and outgoing interfaces.
- Policy ID.
- Offload flags.
- Reply direction counters.
If counters increase only in one direction, check routing and return path symmetry.