Hi,
Can someone help me translate the following from the 'show session table' please?
(ARUBA3600) #show datapath session verbose
Datapath Session Table Entries
------------------------------
Flags: F - fast age, S - src NAT, N - dest NAT
D - deny, R - redirect, Y - no syn
H - high prio, P - set prio, T - set ToS
C - client, M - mirror, V - VOIP
Q - Real-Time Quality analysis
I - Deep inspect, U - Locally destined
E - Media Deep Inspect, G - media signal
r - Route Nexthop
Session Index, Route/Cache Index, Agg. Version Number[SIDX SRTI SRCI SRTRCV]
Source IP Destination IP Prot SPort DPort Cntr Prio ToS Age Destination TAge Packets Bytes SIDX SRTI SRCI SRTRCV UsrIdx UsrVer AclVer NhIdx NhVer Flags
--------------- --------------- ---- ----- ----- -------- ---- --- --- ----------- ---- --------- --------- -------- ---- -------- -------- -------- -------- -------- -------- -------- ---------------
F4:0F:1B:F3:7F:03 2000 0/0 0 0 0 1/1 2 0 0 1bfe5 0 0 0 8 e94 0 0 0 F
This is the MAC address of a switch interface connected to an untrusted port on an Aruba controller within a lab enviroment. This MAC address keeps showing up in Clearpass every 5 - 10 minutes within the access tracker and I'm trying to find out why as the same problem is also occuring with our production Clearpass implementation.

Cheers
Shaun