In addition, when you are trying to match for sessions that are source translated, 1) The "show session all filter source <ip>", where <ip> is one of the "Source Nated IP from the pool", will not show us any results. This is because the session is initiated from the original source, whose IP later gets translated to one of the IPs from the pool. This command is valid for pre-translated source IP addresses and not the post translated IP addresses. 2) On similar lines, the command "show session all filter destination <xlate-source>", wouldnt work for post translated source IP addresses, because from the PANFWs standpoint the destination is the real IP address and not the translated IP address. ( this command would however work for pre translated destination NAT IP address ) Hence for both the cases, you will never see any sessions, and this is an expected behavior.
... View more