N3IWF (Non-3GPP Interworking Function)

In telecommunications, the N3IWF is the 5G Network Function that allows untrusted non-3GPP access (typically Wi-Fi) to connect to the 5G core. It terminates IPsec/IKEv2 tunnels from the UE and exposes the N2 and N3 reference points to AMF and UPF as if the access were 3GPP-native.

Categories: Core NetworkSecurity ControlsProtocols and Standards

N3IWF in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place N3IWF in the wider telecom-security picture, review AES, OpenSSL, TNGF, EAP-AKA′, SEAF and N12 — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.