Yes it is different , it is stateless , the MX doesn't keep track of any 'sessions' at all. It must re-evaluate every packet , so when you delete the rule it is effective instantly. I deleted a TCP allow 443 rule in the past and I was getting syslogs that people were still hiting that rule despite the rule being deleted 3-4 weeks ago. Support told me that in every case an active session was still 'active' so the flow was allowed. I had to reboot a couple of MX to purge the session table. I agree with you , it doesn't make any sense at all , but it seems to be 'working as expected'.
... View more