Applying IPS signatures to IP packets within GTP-U tunnels
GTP-U (GTP user data tunnelling) tunnels carry user data packets, signaling messages and error information. GTP-U uses UDP port 2152. Carrier-enabled FortiGate units can apply IPS intrusion protection and detection to GTP-U user data sessions.
To apply IPS to GTP-U user data sessions, add an IPS Sensor to a profile and add the profile to a security policy that accepts GTP-U tunnels. The security policy Service field must be set to GTP or ANY to accept GTP-U packets.
The Carrier-enabled FortiGate unit intercepts packets with destination port 2152, removes the GTP header and handles the packets as regular IP packets. Applying an IPS sensor to the IP packets, the Carrier-enabled FortiGate unit can log attacks and pass or drop packets depending on the configuration of the sensor.
If the packet is GTP-in-GTP, or a nested tunnel, the packets are passed or blocked without being inspected.
To apply an IPS sensor to GTP-U tunnels
- Go to Security Profiles > Intrusion Prevention and select Create New (+) to add an IPS Sensor.
- Configure the IPS Sensor to detect attacks and log, drop, or pass attack packets.
- Go to Policy & Objects > IPv4 Policy and apply the IPS sensor to the security policy.
- Go to Policy & Objects > IPv4 Policy and select Create New to add a security policy or select a security policy.
- Configure the security policy to accept GTP traffic.
- Select the GTP profile within the security policy.
- Configure any other required security policy settings.
- Select OK to save the security policy.
For more information, see Intrusion prevention.
In the security policy configure the source and destination settings to match the GTP traffic. Service to GTP or ANY so that the security policy accepts GTP traffic.