N6 Reference Point

Also known as: N6 Reference Point

N6 is the 3GPP 5G reference point between the UPF and a data network (typically the internet, an IMS network or an enterprise DN), defined in TS 23.501. It is the egress user-plane border where NAT, firewalling, DPI, charging enforcement and lawful intercept mediation typically sit, and where operator responsibility for subscriber traffic ends.

Categories: Core NetworkSecurity ControlsThreats and Attacks

N6 in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place N6 in the wider telecom-security picture, review SCP Abuse, N4, N8, Egress, HTTP and Mediation Device (Lawful Interception): each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • 5G Security 5G SBA, SEPP, SUCI, 5G-AKA, N32 and service-based interface security.
  • SS7 Firewall GSMA FS.11 category 1/2/3 SS7 message screening at the STP edge.
  • Diameter Firewall GSMA FS.19 screening at the Diameter Edge Agent on S6a/S9/S13.
  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.