[113263] in North American Network Operators' Group
Re: Do we still need Gi Firewall for 3G/UMTS/HSPA network ?
daemon@ATHENA.MIT.EDU (Alexander Harrowell)
Thu Apr 9 12:41:11 2009
From: Alexander Harrowell <a.harrowell@gmail.com>
To: nanog@nanog.org
Date: Thu, 9 Apr 2009 17:21:28 +0100
In-Reply-To: <084962C061414240A0CDB4BE328A9B2D119F91724A@GVW1100EXC.americas.hpqcorp.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
--nextPart10615352.vS7hP7Jsdp
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
On Thursday 09 April 2009 16:48:32 Lee, Steven (NSG Malaysia) wrote:
> Hi all, in most of the existing 2G/2.5G mobile PS-core (Packet Switch)
> networks have Gi segment (interface between GGSN & IP Router/firewall). D=
ue
> to the IP address constraint, operator usually do NAT on the Gi firewall =
to
> NAT the private IP to public IP in the past. Looking at the traffic patte=
rn
> and user access behaviour, does it make sense to have firewall between the
> GGSN & Public Internet if the public IP addresses are sufficient to cater
> for mobile subscribers? Especially with 3G/UMTS/HSPA or even LTE in the
> future.
>
> Please share your thought and thanks in advance :)
>
> Regards,
> Steven Lee
I would think that, however you are providing IP addresses, any ingress poi=
nt=20
to a GSM core network ought to be carefully policed on security grounds.=20
Especially if you have IMS or SIP-based services or intend to deploy them.
--nextPart10615352.vS7hP7Jsdp
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.4-svn0 (GNU/Linux)
iD8DBQBJ3iCT0c69vkueJcQRAjjpAKCefpKsICuP0/Wf3256TIoOrvj7AQCePSvD
dFDT6dhGF+jenD4dCXBMtyY=
=vf64
-----END PGP SIGNATURE-----
--nextPart10615352.vS7hP7Jsdp--