PGW (Packet Data Network Gateway)

The Packet Data Network Gateway is the 4G EPC element that connects subscriber data sessions to external networks (internet, IMS, enterprise APNs). It allocates IP addresses, enforces per-bearer QoS, applies charging via the OCS/PCRF, and performs lawful interception. The PGW is the user-plane border between the trusted mobile core and external networks, and its 5G equivalent is the UPF; both require careful filtering and DDoS protection because they are reachable from untrusted networks.

Categories: Core NetworkIdentity and SubscriberThreats and Attacks

PGW in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

To place PGW in the wider telecom-security picture, review UDR, AMPS, Artificial Traffic Inflation, Backhaul, BTS and Cell Phone (Mobile Phone) — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.