An administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions that are active on the firewall. The administrator wants to see details such as source and destination IP addresses, application, and security policy applied. Which CLI command should the administrator use?
The 'show session all' command displays all active sessions on the firewall, including source and destination IP addresses, application, security policy, and other details. It is the primary command for viewing the session table. This command provides a comprehensive list, which can be filtered further if needed. Therefore, it meets the administrator's requirement to view current sessions with the specified details.
Why this answer
The 'show session all' command is the correct CLI command to display all active sessions on a Palo Alto Networks firewall, including source and destination IP addresses, application, and the security policy applied. It provides the detailed session information the administrator needs to troubleshoot or monitor current traffic.
Exam trap
The trap here is confusing similar-sounding commands like 'show session info' with 'show session all', where the former only provides summary statistics and not detailed session listings.