Yes, the rules are on the interface 'in'.
When looking at the states & sessions (after the schedule has expired and the Pass rule not effective) filtered to the single IP address on the device of the scheduled VLAN, there is no 'in' rule active, only the out rule.
BUT despite there being no IN rules associated with that VLAN / IP Address, traffic still flows.
The config on this device is a couple of years old now - we got the DEC750s with BE licences late 2023, so there have been many firmware updates since then.
As it's a fairly simple config, I'm just going to nuke, reinstall the BE firmware and reconfigure later today...
When looking at the states & sessions (after the schedule has expired and the Pass rule not effective) filtered to the single IP address on the device of the scheduled VLAN, there is no 'in' rule active, only the out rule.
BUT despite there being no IN rules associated with that VLAN / IP Address, traffic still flows.
The config on this device is a couple of years old now - we got the DEC750s with BE licences late 2023, so there have been many firmware updates since then.
As it's a fairly simple config, I'm just going to nuke, reinstall the BE firmware and reconfigure later today...