Palo Alto Networks Knowledgebase: Discard Session Rematch

Discard Session Rematch

4747
Created On 02/07/19 23:46 PM - Last Updated 02/07/19 23:46 PM
Content Release Deployment
Resolution

Symptom

A session is in the DISCARD state and a new policy is then added to allow that particular traffic. However, with "Rematch Session" enabled, that session does not change state from DISCARD to ACTIVE.

Screen Shot 2013-08-14 at 1.57.09 PM.png

 

Cause

The session will still stay in the DISCARD state, as the current logic will only rematch ALLOW sessions. PAN-OS will not process and change the DISCARD state of the existing session. Any future sessions will be allowed and will not be discarded.

 

Resolution

If the packets are still hitting the existing DISCARD session, clear that session to allow the new one with the following command:

> clear session <session id>

 

See Also

How Session Rematch Works

 

owner: kalavi



Attachments
Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClrKCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Attachments
Choose Language