Palo Alto Session Troubleshooting
Use session checks when traffic matched a rule once and then continues behaving unexpectedly after a policy, route, or NAT change.
Find sessions
show session all filter source 10.0.0.10 destination 203.0.113.10
show session all filter destination 203.0.113.10
show session all filter application sslInspect a session
show session id <session-id>Look for:
- Ingress and egress zones.
- NAT source and destination.
- Application and rule name.
- Packet counters in each direction.
- End reason for closed sessions.
Clear a matching session
clear session all filter source 10.0.0.10 destination 203.0.113.10Use narrow filters before clearing sessions on production firewalls.