GTP Log Fields
Format: FUTURE_USE, Receive Time, Serial Number, FUTURE_USE, FUTURE_USE, FUTURE_USE, Generated Time, Source Address, Destination Address, FUTURE_USE, FUTURE_USE, Rule Name, FUTURE_USE, FUTURE_USE, Application, Virtual System, Source Zone, Destination Zone, Inbound Interface, Outbound Interface, Log Action, FUTURE_USE, Session ID, FUTURE_USE, Source Port, Destination Port, FUTURE_USE, FUTURE_USE, FUTURE_USE, Protocol, Action, GTP Event Type, MSISDN, Access Point Name, Radio Access Technology, GTP Message Type, End User IP Address, Tunnel Endpoint Identifier1, Tunnel Endpoint Identifier2, GTP Interface, GTP Cause, Severity, Serving Country MCC, Serving Network MNC, Area Code, Cell ID, GTP Event Code, FUTURE_USE, FUTURE_USE, Source Location, Destination Location, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, Tunnel ID/IMSI, Monitor Tag/IMEI, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE, FUTURE_USE
Receive Time (receive_time or cef-formatted-receive_time)
Month, Day and time the log was received at the management plane.
Serial Number (serial)
Serial number of the firewall that generated the log.
Generated Time (time_generated or cef-formatted-time_generated)
Time the log was generated on the dataplane.
Source Address (src)
Source IP address of packets in the session.
Destination Address (dst)
Destination IP address of packets in the session.
Rule Name (rule)
Name of the Security policy rule in effect on the session.
Tunneling protocol used in the session.
Virtual System (vsys)
Virtual System associated with the session.
Source Zone (from)
Source zone of packets in the session.
Destination Zone (to)
Destination zone of packets in the session.
Inbound Interface (inbound_if)
Interface that the session was sourced from.
Outbound Interface (outbound_if)
Interface that the session was destined to.
Log Action (logset)
Log Forwarding Profile that was applied to the session.
Session ID (sessionid)
Session ID of the session being logged.
Source Port (sport)
Source port utilized by the session.
Destination Port (dport)
Destination port utilized by the session.
IP Protocol (proto)
IP protocol associated with the session.
Action taken for the session; possible values are:
GTP Event Type (event_type)
Defines event triggered by a GTP message when checks in GTP protection profile are applied to the GTP traffic. Also triggered by the start or end of a GTP session.
Service identity associated with the mobile subscriber composed of a Country Code, National Destination Code and a Subscriber. Consists of decimal digits (0-9) only with a maximum of 15 digits.
Access Point Name (apn)
Reference to a Packet Data Network Data Gateway (PGW)/ Gateway GPRS Support Node in a mobile network. Composed of a mandatory APN Network Identifier and an optional APN Operator Identifier.
Radio Access Technology (rat)
Type of technology used for radio access. For example, EUTRAN, WLAN, Virtual, HSPA Evolution, GAN and GERAN.
GTP Message Type (msg_type)
Indicates the GTP message type.
End IP Address (end_ip_adr)
IP address of a mobile subscriber allocated by a PGW/GGSN.
Tunnel Endpoint Identifier1 (teid1)
Identifies the GTP tunnel in the network node. TEID1 is the first TEID in the GTP message.
|Tunnel Endpoint Identifier2 (teid2)|
Identifies the GTP tunnel in the network node. TEID2 is the second TEID in the GTP message.
GTP Interface (gtp_interface)
3GPP interface from which a GTP message is received.
GTP Cause (cause_code)
GTP cause value in logs responses which contain an Information Element that provides information about acceptance or rejection of GTP requests by a network node.
Severity associated with the event; values are informational, low, medium, high, critical.
Serving Network MCC (mcc)
Mobile country code of serving core network operator.
Serving Network MNC (mnc)
Mobile network code of serving core network operator.
Area Code (area_code)
Area within a Public Land Mobile Network (PLMN).
Cell ID (cell_id)
Base station within an area code.
GTP Event Code (event_code)
Event code describing the GTP event.
Source Location (srcloc)
|Source country or Internal region for private addresses; maximum length is 32 bytes.|
Destination Location (dstloc)
Destination country or Internal region for private addresses; maximum length is 32 bytes.
Tunnel ID/IMSI (imsi)
International Mobile Subscriber Identity (IMSI) is a unique number allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI shall consist of decimal digits (0 through 9) only and maximum number of digits allowed are 15.
Monitor Tag/IMEI (imei)
International Mobile Equipment Identity (IMEI) is a unique 15 or 16 digit number allocated to each mobile station equipment.
Objects > Security Profiles > GTP Protection
Objects > Security Profiles > GTP Protection The GTP Protection profile enables the firewall to inspect GTP traffic. To view this profile, you must enable ...
GTP Protection Profile
GTP Protection Profile The GTP Protection profile ( Objects Security Profiles GTP Protection ) enables the firewall to inspect GTP traffic. The options in the ...
Traffic Log Fields
Traffic Log Fields Format: FUTURE_USE, Receive Time, Serial Number, Type, Threat/Content Type, FUTURE_USE, Generated Time, Source IP, Destination IP, NAT Source IP, NAT Destination IP, ...
View GTP Logs
View GTP Logs GTP logs are event-based logs that include information on the a wide range of GTP attributes including GTP event type, GTP message ...
Generate Mobile Network Reports
Generate Mobile Network Reports You can view daily reports or configure and schedule custom reports on mobile network activity. The predefined Mobile Network Reports allow ...
Threat Log Fields
Threat Log Fields Format : FUTURE_USE, Receive Time, Serial Number, Type, Threat/Content Type, FUTURE_USE, Generated Time, Source IP, Destination IP, NAT Source IP, NAT Destination ...
Tunnel Inspection Log Fields
Tunnel Inspection Log Fields Format : FUTURE_USE, Receive Time, Serial Number, Type, Subtype, FUTURE_USE, Generated Time, Source IP, Destination IP, NAT Source IP, NAT Destination ...
Configure GTP Stateful Inspection
Configure GTP Stateful Inspection Mobile Network Operators use the GPRS Tunneling Protocol (GTP) on various interfaces in Roaming, Radio Access Network, and within the packet ...
Monitor GTP Traffic
Monitor GTP Traffic When you enable logging in a security policy rule, the firewall generates a traffic log for when traffic matches the criteria defined ...