Carrier web-based manager settings

Advanced filtering options

The FortiOS Carrier firewall supports advanced filtering against the attributes RAT, RAI, ULI, APN restriction, and

IMEI-SV in GTP to block specific harmful GPRS traffic and GPRS roaming traffic. The following table shows some of the GTP context requests and responses that the firewall supports.

 

Attributes supported by FortiCarrier firewalls

GTP Create PDP Context Request

GTP Create PDP Con- text Response

GTP Update PDP Con- text Request

GTP Update PDP Context Response

APN                           yes                                yes                                      –

 

APN Restriction

yes                                  –                                         –                                  yes

 

IMEISV                     yes                                  –                                         –                                     –

IMSI                           yes                                  –                                      yes                                  –

GTP Create PDP Context Request

GTP Create PDP Con- text Response

 

RAI

 

yes

 

–                                      yes

 

RAT

 

yes

 

–                                      yes

 

ULI

 

yes

 

–                                      yes

 

GTP Update PDP Con- text Request

GTP Update PDP Context Response

When editing a GTP profile, select Advanced Filtering > Add to create and add a rule. When the rule matches traffic it will either allow or deny that traffic as selected in the rule.

This entry was posted in FortiOS 5.4 Handbook on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.