Cellusys GTP Signalling Firewall v1.5
Cellusys GTP Signalling Firewall v1.5
Overview
The unified Cellusys Signalling Firewall(1) system protects a mobile operator's network by
sitting on its external links to other networks and filtering messages from reaching the
network, ensuring threats from individual messages, flooding or other issues are prevented
from reaching the network and causing issues. The unified firewall supports all relevant
signalling protocols: SS7/SIGTRAN, Diameter, SMPP, GTP.
Features
GTP Firewall provides full control over the signalling stack from IP to GTP. Base for the GTP
integration into the Cellusys Signalling Firewall is the GSMA FS.20 standard – with focus on
roaming traffic. The Signalling Firewall will apply pre-defined (GSMA FS.20) and user-defined
policies to this GTP-C traffic. As for all rules, they can be customized by the user using the
same rule definitions known from SS7, Diameter etc. Every GTP-C parameter is exposed and
available for query and policy enforcement. Due to internal correlation, each rule has access
to relevant fields of the GTP-C messages even if the field is not present in the original
message (such as IMSI in PDP-Context-Delete Messages).
(1) https://www.cellusys.com/security-solutions/signalling-firewall/
www.cellusys.com
GTP Signalling Firewall
Network integration
Integration of GTP is done inline: physical links carrying roaming GTP traffic will be
connected to the GTP firewall switch. Using BISDN-OS(2) as platform this switch extracts
relevant GTP-C messages bidirectional and forwards them to the firewall message
processor, while all other traffic is transparently bypassed. The integration supports all
current physical interfaces using SFPs (100MBps – 100Gbps). Up to 8 links can be connected
using one GTP firewall switch. Also mirror ports are available to connect other Cellusys
products such as Mobile Broadband Monitoring. Permanent port monitoring of the GTP
firewall switch supports switching to other firewall instances or completely bypass all traffic
(transparent mode).
Specifically, due to the inline mode, no network configuration on PS nodes is required. This
simplifies the integration dramatically.
www.cellusys.com
Roaming | Security | Analytics
www.cellusys.com