Palo Alto Session Troubleshooting

Use session checks when traffic matched a rule once and then continues behaving unexpectedly after a policy, route, or NAT change.

Find sessions

show session all filter source 10.0.0.10 destination 203.0.113.10
show session all filter destination 203.0.113.10
show session all filter application ssl

Inspect a session

show session id <session-id>

Look for:

  • Ingress and egress zones.
  • NAT source and destination.
  • Application and rule name.
  • Packet counters in each direction.
  • End reason for closed sessions.

Clear a matching session

clear session all filter source 10.0.0.10 destination 203.0.113.10

Use narrow filters before clearing sessions on production firewalls.