GTP Firewall
A GTP firewall is the perimeter control that inspects GPRS Tunneling Protocol traffic crossing the roaming border. It applies policy to both planes: GTP-C (the control plane that sets up, modifies and tears down sessions and bearers on S8, S5 and 5G N9) and GTP-U (the user plane that carries subscriber payload inside GTP tunnels). On a 4G EPC it sits between the partner SGSN/S-GW and the home P-GW; on a 5G core with roaming over N9 it sits between visited and home UPFs. In both cases the GRX/IPX interconnect is treated as untrusted.
The reference policy is GSMA FS.20. Control-plane screening covers the legitimate command set (Create-Session-Request, Modify-Bearer-Request, Delete-Session-Request and their responses), the Information Elements each command is allowed to carry, and the consistency of subscriber identifiers (IMSI/SUPI), APN, RAT type and Visited-PLMN with the session being negotiated. User-plane screening enforces TEID validity, anti-spoofing against the agreed tunnel endpoints, payload-protocol whitelisting, and rate limits that contain volumetric abuse without dropping legitimate traffic.
The attacks a correctly deployed GTP firewall is expected to contain include GTP tunnel hijack (forged Create-Session-Request from a network where the subscriber is not present), overbilling (forcing the home network to bill traffic on a torn-down session), IMSI disclosure through error-message leakage, and denial-of-service against the P-GW or UPF through malformed GTP-C or floods of TEID-mismatched GTP-U. Like the SS7 firewall and the Diameter firewall, it produces the per-session audit trail required for incident response and regulator reporting. The unified framing is in the Signaling Firewall guide; firewall rule sets are validated under attacker traffic in a telecom penetration test.
Frequently asked questions about gtp firewall
What does GSMA FS.20 require for GTP firewalling?
GSMA FS.20 defines category-based screening for GTP-C and GTP-U at GRX/IPX borders, structured similarly to FS.11 (SS7) and FS.19 (Diameter). It covers cross-plane filtering (GTP-U packets must not carry control-plane commands), source-address validation against IR.21-declared prefixes, TEID sanity checks, IMSI/APN allowlisting for known roaming partners, and rate limits to blunt DoS. The document is periodically revised; the current baseline is a mandatory reference for operators offering LTE roaming.
What is GTP tunnel hijacking?
GTP tunnel hijacking occurs when an attacker manipulates GTP-C signaling to take over an existing data session or create unauthorized tunnels. This can redirect subscriber traffic through attacker-controlled infrastructure, enabling data interception, session manipulation, or denial of service. GTP firewalls and strict tunnel endpoint verification are the primary defenses.
Related glossary terms
- FS.20 GPRS/GTP Security
- GTP Security GPRS Tunneling Protocol Security
- GGSN Gateway GPRS Support Node
- GTP GPRS Tunneling Protocol
- GTP Firewall
- Inter-PLMN Security
- SGSN Serving GPRS Support Node
- TEID Tunnel Endpoint Identifier
- User Plane Security
- GTP-C Spoofing
Related comparisons
More on Gtp Firewall
Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.