Created On 02/07/19 23:46 PM - Last Updated 02/07/19 23:46 PM
A session is in the DISCARD state and a new policy is then added to allow that particular traffic. However, with "Rematch Session" enabled, that session does not change state from DISCARD to ACTIVE.
The session will still stay in the DISCARD state, as the current logic will only rematch ALLOW sessions. PAN-OS will not process and change the DISCARD state of the existing session. Any future sessions will be allowed and will not be discarded.
If the packets are still hitting the existing DISCARD session, clear that session to allow the new one with the following command: