Using a policy with the policy-rematch flag enabled, what happens to the existing and new
sessions when you change the policy action from permit to deny?
A.
The new sessions matching the policy are denied. The existing sessions are dropped.
B.
The new sessions matching the policy are denied. The existingsessions, not being allowed
tocarry any traffic, simply timeout.
C.
The new sessions matching the policy might be allowed through if they match another policy.
The existing sessions are dropped.
D.
The new sessions matching the policy are denied. The existing sessions continue until they are
completed or their timeout is reached.