Fortinet white logo
Fortinet white logo

New Features

Selective GTP FGSP sync: only S10 tunnels

Selective GTP FGSP sync: only S10 tunnels

You can use the following option to configure a FortiOS Carrier FGSP cluster to synchronize only S10 GTP tunnels:

config system settings

set gtp-fgsp-s10-only {disable | enable}

end

By default gtp-fgsp-s10-only is disabled and FortiOS Carrier FGSP synchronizes all GTP tunnels. You can enable gtp-fgsp-s10-only to synchronize only G10 tunnels.

If you are using FortiOS Carrier FGSP to synchronize GTP tunnels among multiple locations, and if you only need to synchronize S10 GTP tunnels among those locations, you can enable gtp-fgsp-s10-only. Enabling this option supports the GTP tunnel synchronization you need and potentially reduces the amount of bandwidth required for FGSP session synchronization.

Enabling gtp-fgsp-s10-only is compatible with disabling session-sync to stop synchronizing IP sessions, see Selective GTP FGSP sync: only synchronize GTP tunnels. If you disable session-sync and enable gtp-fgsp-s10-only, FortiOS Carrier FGSP only synchronizes S10 GTP tunnels and also does not synchronize IP sessions.

When gtp-fgsp-s10-only is enabled, FGSP support for GTP asymmetric routing is no longer supported and the gtp-asym-fgsp system settings CLI option becomes hidden.

Example topology

Default configuration: gtp-fgsp-s10-only disabled

CLI configuration:

config system settings

set gtp-fgsp-s10-only disable

end

All GTP tunnels are received by FortiGate 1 (FGSP primary). S10 and S8 GTP tunnels are synchronized to FortiGate 2 (FGSP peer).

The output of the diagnose firewall gtp tunnel list command for each FortiGate shows S10 and S8 tunnels:

FortiGate 1 (FGSP primary)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=6 imsi=987654112233445 msisdn=896745214365 mei=43658709.212030.1 ms_addr=80.80.80.1 s11_s4 0----------- (S8 Tunnel)
-----------index=00000013 life=23(sec) idle=22(sec) vd=0  ver=2-----------
c_pkt=2 c_bytes=540 u_pkt=0 u_bytes=0
rat type: utran
downlink cfteid:
    addr=10.10.10.10 teid=0x1ce7eab0 role=control vd=0 intf_type=s5/s8 sgw gtp-c
uplink cfteid:                                                                                                                         
    addr=20.20.20.10 teid=0x1ce7eab2 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=6 linked_id=6 type=regular dead=0 apn=internet2 selection=ms-or-net-provided-apn apn_restriction=public-2 user_addr=80.80.80.1 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.10.10.10 teid=0x1ce7eab1 role=data vd=0 intf_type=s5/s8 sgw gtp-u
        addr=20.20.20.10 teid=0x1ce7eab3 role=data vd=0 intf_type=s5/s8 pgw gtp-u

-----------prof=gtpp ref=5 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0----------- (S10 Tunnel) 
-----------index=00000014 life=5(sec) idle=5(sec) vd=0  ver=2-----------
c_pkt=1 c_bytes=52 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:                                                                                                                
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u
FortiGate 2 (FGSP peer)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=5 imsi=987654112233445 msisdn=896745214365 mei=43658709.212030.1 ms_addr=80.80.80.1 s11_s4 0----------- (S8 Tunnel)
-----------index=00000013 life=30(sec) idle=30(sec) vd=0  ver=2-----------
c_pkt=0 c_bytes=0 u_pkt=0 u_bytes=0
rat type: utran
downlink cfteid:
    addr=10.10.10.10 teid=0x1ce7eab0 role=control vd=0 intf_type=s5/s8 sgw gtp-c
uplink cfteid:                                                                                                                       
    addr=20.20.20.10 teid=0x1ce7eab2 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=6 linked_id=6 type=regular dead=0 apn=internet2 selection=ms-or-net-provided-apn apn_restriction=public-2 user_addr=80.80.80.1 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.10.10.10 teid=0x1ce7eab1 role=data vd=0 intf_type=s5/s8 sgw gtp-u
        addr=20.20.20.10 teid=0x1ce7eab3 role=data vd=0 intf_type=s5/s8 pgw gtp-u

-----------prof=gtpp ref=4 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0----------- (S10 Tunnel)
-----------index=00000014 life=11(sec) idle=11(sec) vd=0  ver=2-----------
c_pkt=0 c_bytes=0 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:                                                                                                                           
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u
Sync S10 GTP tunnels only: gtp-fgsp-s10-only enabled

CLI configuration:

config system settings

set gtp-fgsp-s10-only enabled

end

All GTP tunnels are received by FortiGate 1 (FGSP primary). Only S10 GTP tunnels are synchronized to FortiGate 2 (FGSP peer).

The output of the diagnose firewall gtp tunnel list command for each FortiGate shows FortiGate 1 (FGSP primary) has S10 and S8 tunnels and FortiGate 2 (FGSP peer) has only S8 tunnels:

FortiGate 1 (FGSP primary)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=6 imsi=987654112233445 msisdn=896745214365 mei=43658709.212030.1 ms_addr=80.80.80.1 s11_s4 0----------- (S8 Tunnel) 
-----------index=00000017 life=30(sec) idle=29(sec) vd=0  ver=2-----------
c_pkt=2 c_bytes=540 u_pkt=0 u_bytes=0
rat type: utran
downlink cfteid:
    addr=10.10.10.10 teid=0x1ce7eab0 role=control vd=0 intf_type=s5/s8 sgw gtp-c
uplink cfteid:                                                                                                                   
    addr=20.20.20.10 teid=0x1ce7eab2 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=6 linked_id=6 type=regular dead=0 apn=internet2 selection=ms-or-net-provided-apn apn_restriction=public-2 user_addr=80.80.80.1 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.10.10.10 teid=0x1ce7eab1 role=data vd=0 intf_type=s5/s8 sgw gtp-u
        addr=20.20.20.10 teid=0x1ce7eab3 role=data vd=0 intf_type=s5/s8 pgw gtp-u

-----------prof=gtpp ref=5 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0----------- (S10 Tunnel) 
-----------index=00000018 life=19(sec) idle=19(sec) vd=0  ver=2-----------
c_pkt=1 c_bytes=52 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u
FortiGate 2 (FGSP peer)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=4 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0-----------  (S10 Tunnel)
-----------index=00000018 life=25(sec) idle=25(sec) vd=0  ver=2-----------
c_pkt=0 c_bytes=0 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u

Selective GTP FGSP sync: only S10 tunnels

Selective GTP FGSP sync: only S10 tunnels

You can use the following option to configure a FortiOS Carrier FGSP cluster to synchronize only S10 GTP tunnels:

config system settings

set gtp-fgsp-s10-only {disable | enable}

end

By default gtp-fgsp-s10-only is disabled and FortiOS Carrier FGSP synchronizes all GTP tunnels. You can enable gtp-fgsp-s10-only to synchronize only G10 tunnels.

If you are using FortiOS Carrier FGSP to synchronize GTP tunnels among multiple locations, and if you only need to synchronize S10 GTP tunnels among those locations, you can enable gtp-fgsp-s10-only. Enabling this option supports the GTP tunnel synchronization you need and potentially reduces the amount of bandwidth required for FGSP session synchronization.

Enabling gtp-fgsp-s10-only is compatible with disabling session-sync to stop synchronizing IP sessions, see Selective GTP FGSP sync: only synchronize GTP tunnels. If you disable session-sync and enable gtp-fgsp-s10-only, FortiOS Carrier FGSP only synchronizes S10 GTP tunnels and also does not synchronize IP sessions.

When gtp-fgsp-s10-only is enabled, FGSP support for GTP asymmetric routing is no longer supported and the gtp-asym-fgsp system settings CLI option becomes hidden.

Example topology

Default configuration: gtp-fgsp-s10-only disabled

CLI configuration:

config system settings

set gtp-fgsp-s10-only disable

end

All GTP tunnels are received by FortiGate 1 (FGSP primary). S10 and S8 GTP tunnels are synchronized to FortiGate 2 (FGSP peer).

The output of the diagnose firewall gtp tunnel list command for each FortiGate shows S10 and S8 tunnels:

FortiGate 1 (FGSP primary)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=6 imsi=987654112233445 msisdn=896745214365 mei=43658709.212030.1 ms_addr=80.80.80.1 s11_s4 0----------- (S8 Tunnel)
-----------index=00000013 life=23(sec) idle=22(sec) vd=0  ver=2-----------
c_pkt=2 c_bytes=540 u_pkt=0 u_bytes=0
rat type: utran
downlink cfteid:
    addr=10.10.10.10 teid=0x1ce7eab0 role=control vd=0 intf_type=s5/s8 sgw gtp-c
uplink cfteid:                                                                                                                         
    addr=20.20.20.10 teid=0x1ce7eab2 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=6 linked_id=6 type=regular dead=0 apn=internet2 selection=ms-or-net-provided-apn apn_restriction=public-2 user_addr=80.80.80.1 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.10.10.10 teid=0x1ce7eab1 role=data vd=0 intf_type=s5/s8 sgw gtp-u
        addr=20.20.20.10 teid=0x1ce7eab3 role=data vd=0 intf_type=s5/s8 pgw gtp-u

-----------prof=gtpp ref=5 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0----------- (S10 Tunnel) 
-----------index=00000014 life=5(sec) idle=5(sec) vd=0  ver=2-----------
c_pkt=1 c_bytes=52 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:                                                                                                                
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u
FortiGate 2 (FGSP peer)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=5 imsi=987654112233445 msisdn=896745214365 mei=43658709.212030.1 ms_addr=80.80.80.1 s11_s4 0----------- (S8 Tunnel)
-----------index=00000013 life=30(sec) idle=30(sec) vd=0  ver=2-----------
c_pkt=0 c_bytes=0 u_pkt=0 u_bytes=0
rat type: utran
downlink cfteid:
    addr=10.10.10.10 teid=0x1ce7eab0 role=control vd=0 intf_type=s5/s8 sgw gtp-c
uplink cfteid:                                                                                                                       
    addr=20.20.20.10 teid=0x1ce7eab2 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=6 linked_id=6 type=regular dead=0 apn=internet2 selection=ms-or-net-provided-apn apn_restriction=public-2 user_addr=80.80.80.1 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.10.10.10 teid=0x1ce7eab1 role=data vd=0 intf_type=s5/s8 sgw gtp-u
        addr=20.20.20.10 teid=0x1ce7eab3 role=data vd=0 intf_type=s5/s8 pgw gtp-u

-----------prof=gtpp ref=4 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0----------- (S10 Tunnel)
-----------index=00000014 life=11(sec) idle=11(sec) vd=0  ver=2-----------
c_pkt=0 c_bytes=0 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:                                                                                                                           
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u
Sync S10 GTP tunnels only: gtp-fgsp-s10-only enabled

CLI configuration:

config system settings

set gtp-fgsp-s10-only enabled

end

All GTP tunnels are received by FortiGate 1 (FGSP primary). Only S10 GTP tunnels are synchronized to FortiGate 2 (FGSP peer).

The output of the diagnose firewall gtp tunnel list command for each FortiGate shows FortiGate 1 (FGSP primary) has S10 and S8 tunnels and FortiGate 2 (FGSP peer) has only S8 tunnels:

FortiGate 1 (FGSP primary)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=6 imsi=987654112233445 msisdn=896745214365 mei=43658709.212030.1 ms_addr=80.80.80.1 s11_s4 0----------- (S8 Tunnel) 
-----------index=00000017 life=30(sec) idle=29(sec) vd=0  ver=2-----------
c_pkt=2 c_bytes=540 u_pkt=0 u_bytes=0
rat type: utran
downlink cfteid:
    addr=10.10.10.10 teid=0x1ce7eab0 role=control vd=0 intf_type=s5/s8 sgw gtp-c
uplink cfteid:                                                                                                                   
    addr=20.20.20.10 teid=0x1ce7eab2 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=6 linked_id=6 type=regular dead=0 apn=internet2 selection=ms-or-net-provided-apn apn_restriction=public-2 user_addr=80.80.80.1 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.10.10.10 teid=0x1ce7eab1 role=data vd=0 intf_type=s5/s8 sgw gtp-u
        addr=20.20.20.10 teid=0x1ce7eab3 role=data vd=0 intf_type=s5/s8 pgw gtp-u

-----------prof=gtpp ref=5 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0----------- (S10 Tunnel) 
-----------index=00000018 life=19(sec) idle=19(sec) vd=0  ver=2-----------
c_pkt=1 c_bytes=52 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u
FortiGate 2 (FGSP peer)
diagnose firewall gtp tunnel list
list gtp tunnels

-----------prof=gtpp ref=4 imsi=280202019012163 msisdn=unknown mei=unknown ms_addr=Unknown s11_s4 0-----------  (S10 Tunnel)
-----------index=00000018 life=25(sec) idle=25(sec) vd=0  ver=2-----------
c_pkt=0 c_bytes=0 u_pkt=0 u_bytes=0
rat type: eutran
downlink cfteid:
    addr=Unknown teid=0x00000000 role=control vd=0 intf_type=s1-u enodeb gtp-u
uplink cfteid:
    addr=194.154.140.241 teid=0x024e88f4 role=control vd=0 intf_type=s5/s8 pgw gtp-c
1/1 bearers:
    id=5 linked_id=5 type=regular dead=0 apn=ip.primetel.MNC020.MCC280.GPRS selection=ms-or-net-provided-apn user_addr=10.131.138.209 u_pkt=0 u_bytes=0
    2 fteids:
        addr=10.144.1.164 teid=0x024c88f4 role=data vd=0 intf_type=s1-u sgw gtp-u
        addr=194.154.140.241 teid=0x024c88f4 role=data vd=0 intf_type=s5/s8 pgw gtp-u