GTP events have categorized by their severity; the firewall
generates GTP logs when GTP events occur.
The firewall generates GTP logs when the following events
occur, and these events are displayed both in the logs and on the
GTP Events widget on the
ACC
Mobile Network Activity
. With
the exception of the GTP session start and GTP session end logs,
GTP logs are triggered by the GTP protection profile configuration.
The session start and session end logs are generated when you enable
logging in Security policy rules.
Severity
GTP Event Type Description
Critical
GTP-in-GTP
GTP-U tunnel alert limit
High
GTPv1 message failed stateful inspection
Abnormal GTPv1-C message with missing mandatory
IE
Abnormal GTPv1-C message with invalid IE
Abnormal GTPv1-C message with invalid header
Abnormal GTPv1-C message with out of order
IE
Abnormal GTPv1-C message with unsupported message
type
Other abnormal GTPv1-C message
GTPv2 message failed stateful inspection
Abnormal GTPv2-C message with invalid header
Abnormal GTPv2-C message with missing mandatory
IE
Abnormal GTPv2-C message with invalid IE
Abnormal GTPv2-C message with out of order
IE
Abnormal GTPv2-C message with unsupported message
type
Other abnormal GTPv2-C message
Abnormal GTP-U message with missing mandatory
IE
Abnormal GTP-U message with invalid IE
Abnormal GTP-U message with invalid header
Abnormal GTP-U message with out of order IE
Abnormal GTP-U message with unsupported message
type