General Packet Radio Service; 3Gpp R6 Information Elements Support Overview - Juniper NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 Manual

Configuring screenos devices guide
Hide thumbs Also See for NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01:
Table of Contents

Advertisement

CHAPTER 15

General Packet Radio Service

3GPP R6 Information Elements Support Overview

Copyright © 2010, Juniper Networks, Inc.
General Packet Radio Service (GPRS) networks connect to several external networks
including those of roaming partners, corporate customers, GPRS Roaming Exchange
(GRX) providers, and the public Internet. GPRS network operators face the challenge of
protecting their network while providing and controlling access to and from these external
networks. Juniper Networks provides solutions to many of the security problems plaguing
GPRS network operators.
In the GPRS architecture, the fundamental cause of security threats to an operator's
inherent lack of security in GPRS Tunneling Protocol (GTP). GTP is the protocol used
between GPRS support nodes (GSNs). Communication between different GPRS networks
is not secure because GTP does not provide any authentication, data integrity, or
confidentiality protection. Implementing Internet Protocol Security (IPsec) for connections
between roaming partners, setting traffic rate limits, and using stateful inspection can
eliminate a majority of the GTP's security risks. Juniper Networks security devices mitigate
a wide variety of attacks on the Gp, Gn, and Gi interfaces.
NOTE: Only ISG2000 devices support GTP functionality. For more information
on GPRS, see the Concepts and Examples ScreenOS Reference Guide.
This chapter contains the following topics:
3GPP R6 Information Elements Support Overview on page 407
Configuring Access Point Name Restriction (NSM Procedure) on page 409
Configuring IMSI Prefix Filter (NSM Procedure) on page 409
DHCP Relay Overview on page 410
Information elements (IEs) are included in all GTP control message packets. IEs provide
information about GTP tunnels, such as creation, modification, deletion, and status. NSM
supports IEs consistent with Third-Generation Partnership Project (3GPP) Release 6. If
you are running an earlier release, or have contractual agreements with operators running
earlier releases of 3GPP, you can reduce network overhead by restricting control messages
containing unsupported IEs.
407

Advertisement

Table of Contents
loading

Table of Contents