Configure Multiple APN and DNN Sessions
Focus
Focus
Next-Generation Firewall

Configure Multiple APN and DNN Sessions

Table of Contents

Configure Multiple APN and DNN Sessions

Configure APN and DNN cellular subinterfaces on a 5G-integrated firewall to run independent data sessions on separate security zones and routing domains.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
The Multiple APN/DNN feature enables the establishment and maintenance of parallel, concurrent sessions across 4G LTE and 5G cellular networks, allowing for granular traffic segmentation, custom QoS definitions, and differentiated security policies. Beginning with PAN-OS® 12.2.2, you can run up to eight concurrent access point name (APN) sessions on 4G LTE networks or up to eight concurrent data network name (DNN) sessions on 5G standalone (SA) networks, or a combination of APN and DNN up to eight. Each session maps to a dedicated cellular subinterface with its own IP address, default gateway, routing domain, and security zone, letting you isolate workloads, apply distinct security policies per traffic type, and route different applications to different carrier connections—all on a single firewall.
Each additional APN or DNN session is provisioned as a cellular subinterface. The unit number assigned to a subinterface determines which SIM slot carries the session: units 1 through 7 use SIM slot 1, and units 8 through 14 use SIM slot 2. For example, on a single-modem firewall, Cellular1/1.1 through Cellular1/1.7 carry SIM 1 sessions and Cellular1/1.8 through Cellular1/1.14 carry SIM 2 sessions. On dual-modem platforms, each modem has its own parent cellular interface and follows the same unit-numbering scheme. The parent cellular interface (without a unit suffix) continues to carry the primary APN session and behaves the same way it did in earlier releases, so single-APN deployments require no changes. DNN sessions are handled in the same way as APN sessions, along with the network slicing.
APN and DNN both define how the firewall establishes a carrier data session, but they apply to different network generations. An APN identifies the packet data network that the firewall connects to through an Evolved Packet Core (EPC) in 4G LTE deployments. A DNN serves the same purpose in 5G SA networks, where the firewall establishes protocol data unit (PDU) sessions through a 5G Core (5GC). DNN profiles additionally support S-NSSAI (Single Network Slice Selection Assistance Information): you specify a Slice/Service Type (SST) value in the range 0–255 and an optional 24-bit Slice Differentiator (SD) to map the DNN session to a specific 5G network slice. The subinterface paradigm is the same for both APN and DNN configurations.
APN and DNN profiles are centrally managed under NetworkNetwork ProfilesCellularAPN/DNN Profile. You create a profile there and then assign it to the parent cellular interface or to individual subinterfaces. Subinterfaces inherit advanced cellular settings from the parent interface (exceptions are radio band preferences, GPS, DHCP relay, and SIM configuration). You configure each subinterface's security zone, virtual or logical router, and other configuration parameters independently. For example, you can use policy-based forwarding (PBF) to steer traffic to the appropriate subinterface based on source address, destination address, port, or application. In Panorama, APN/DNN profiles are available under TemplatesNetworkNetwork ProfilesCellularAPN/DNN Profile and push to managed firewalls through the standard template mechanism. Committing a multiple APN or DNN configuration does not require a firewall reboot.

Configure Multiple APNs

Create APN profiles and assign them to cellular subinterfaces to run multiple 4G LTE data sessions simultaneously on the same firewall. Each subinterface carries a separate APN connection with independent IP addressing and routing.
  1. Create one or more APN profiles.
    1. Select NetworkNetwork ProfilesCellularAPN/DNN Profile and click Add.
    2. For Type, choose APN.
    3. Enter a Profile Name and the APN Name as provided by your carrier.
    4. (Optional) Select a PDP Type and configure Authentication Type with credentials if your carrier requires authentication.
    5. Click OK and repeat for each additional APN.
  2. Select NetworkInterfacesCellular and select the cellular interface you want to configure.
  3. On the parent interface, assign the primary APN profile to the appropriate SIM slot and click OK.
  4. Add cellular subinterfaces for each additional APN session.
    1. On the Subinterfaces tab, click Add.
    2. Enter a unit number: 1–7 for SIM slot 1 sessions, or 8–14 for SIM slot 2 sessions.
    3. Choose the SIM Slot that corresponds to the unit number range.
    4. For APN/DNN Profile, choose the APN profile to assign to this subinterface.
    5. Click OK and repeat for each additional subinterface.
  5. For each subinterface, configure the Security Zone and Virtual Router settings on the IPv4 tab.
  6. Configure policy-based forwarding (PBF) rules to steer traffic to the appropriate APN subinterface based on source address, destination address, port, or application.
  7. Commit.
    A reboot is not required after committing APN subinterface configurations.

Configure Multiple DNNs

Create DNN profiles and assign them to cellular subinterfaces to run multiple 5G SA data sessions simultaneously. For network slicing deployments, configure S-NSSAI values on each DNN profile to map sessions to specific 5G network slices before assigning the profiles to subinterfaces.
  1. Create one or more DNN profiles.
    1. Select NetworkNetwork ProfilesCellularAPN/DNN Profile and click Add.
    2. For Type, choose DNN.
    3. Enter a Profile Name and the DNN Name as provided by your carrier.
    4. (Optional) Select a PDP Type and configure Authentication Type with credentials if your carrier requires authentication.
    5. (Optional) For network slicing, enter the Slice/Service Type (SST) value in the range 0–255, and enter the Slice Differentiator (SD) if your carrier requires it.
    6. Click OK and repeat for each additional DNN.
  2. Select NetworkInterfacesCellular and select the cellular interface you want to configure.
  3. On the parent interface, assign the primary DNN profile to the appropriate SIM slot and click OK.
  4. Add cellular subinterfaces for each additional DNN session.
    1. On the Subinterfaces tab, click Add.
    2. Enter a unit number: 1–7 for SIM slot 1 sessions, or 8–14 for SIM slot 2 sessions.
    3. Choose the SIM Slot that corresponds to the unit number range.
    4. For APN/DNN Profile, choose the DNN profile to assign to this subinterface.
    5. Click OK and repeat for each additional subinterface.
  5. For each subinterface, configure the Security Zone and Virtual Router settings on the IPv4 tab.
  6. Configure policy-based forwarding (PBF) rules to steer traffic to the appropriate DNN subinterface.
  7. Commit.
    A reboot is not required after committing DNN subinterface configurations.
  8. Verify the DNN sessions are active.
    show cellular dnn
    show cellular session detail