GTP Firewall

A GTP firewall is the perimeter control that inspects GPRS Tunneling Protocol traffic crossing the roaming border. It applies policy to both planes: GTP-C (the control plane that sets up, modifies and tears down sessions and bearers on S8, S5 and 5G N9) and GTP-U (the user plane that carries subscriber payload inside GTP tunnels). On a 4G EPC it sits between the partner SGSN/S-GW and the home P-GW; on a 5G core with roaming over N9 it sits between visited and home UPFs. In both cases the GRX/IPX interconnect is treated as untrusted.

The reference policy is GSMA FS.20. Control-plane screening covers the legitimate command set (Create-Session-Request, Modify-Bearer-Request, Delete-Session-Request and their responses), the Information Elements each command is allowed to carry, and the consistency of subscriber identifiers (IMSI/SUPI), APN, RAT type and Visited-PLMN with the session being negotiated. User-plane screening enforces TEID validity, anti-spoofing against the agreed tunnel endpoints, payload-protocol whitelisting, and rate limits that contain volumetric abuse without dropping legitimate traffic.

The attacks a correctly deployed GTP firewall is expected to contain include GTP tunnel hijack (forged Create-Session-Request from a network where the subscriber is not present), overbilling (forcing the home network to bill traffic on a torn-down session), IMSI disclosure through error-message leakage, and denial-of-service against the P-GW or UPF through malformed GTP-C or floods of TEID-mismatched GTP-U. Like the SS7 firewall and the Diameter firewall, it produces the per-session audit trail required for incident response and regulator reporting. The unified framing is in the Signaling Firewall guide; firewall rule sets are validated under attacker traffic in a telecom penetration test.

Frequently asked questions about gtp firewall

What does GSMA FS.20 require for GTP firewalling?

GSMA FS.20 defines category-based screening for GTP-C and GTP-U at GRX/IPX borders, structured similarly to FS.11 (SS7) and FS.19 (Diameter). It covers cross-plane filtering (GTP-U packets must not carry control-plane commands), source-address validation against IR.21-declared prefixes, TEID sanity checks, IMSI/APN allowlisting for known roaming partners, and rate limits to blunt DoS. The document is periodically revised; the current baseline is a mandatory reference for operators offering LTE roaming.

What is GTP tunnel hijacking?

GTP tunnel hijacking occurs when an attacker manipulates GTP-C signaling to take over an existing data session or create unauthorized tunnels. This can redirect subscriber traffic through attacker-controlled infrastructure, enabling data interception, session manipulation, or denial of service. GTP firewalls and strict tunnel endpoint verification are the primary defenses.

See all telecom security FAQs

Related glossary terms

Browse the full telecom security glossary

Related comparisons

More on Gtp Firewall

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.