GTPv2 Tunnel Cleanup and Traffic Logs
Learn how to configure, verify, monitor GTPv2 tunnel behavior, including enabling traffic logging to track forwarded, dropped, or rate-limited packets for effective troubleshooting and visibility.
GTPv2 Tunnel Cleanup
A GPRS tunneling protocol version 2 (GTPv2) tunnel enables transmission of GTPv2 traffic between GPRS support nodes (GSNs).
While transmitting traffic, GTPv2 tunnels might hang for a number of reasons. For example, delete-pdp-request messages might get lost in the network, or a GSN might not shut down properly. In such a case, you can remove hanging GTPv2 tunnels either automatically or manually.
To remove a hanging GTPv2 tunnel automatically, you need to set a GTPv2 tunnel timeout value on the device. The device automatically identifies and removes a tunnel that is idle for the period specified by the timeout value. The default GTPv2 tunnel timeout value is 36 hours.
You can use the set security gtp profile name timeout command to configure this value on the device. The timeout range is 1 through 1000 hours.
To remove a hanging GTPv2 tunnel manually, you need to use the clear security gtp tunnel command.
Example: Set the Timeout Value for GTPv2 Tunnels
This example shows how to set the timeout value for GTPv2 tunnels.
Requirements
No special configuration beyond device initialization is required before configuring this feature.
Overview
In this example, you set the tunnel timeout value to 40 hours for the GTPv2 inspection object named gtp2.
Configuration
Step-by-Step Procedure
To configure the GTPv2 tunnel timeout value:
Specify the GTPv2 profile.
[edit] user@host# set security gtp profile gtp2
Specify the timeout value.
[edit] user@host# set security gtp profile gtp2 timeout 40
If you are done configuring the device, commit the configuration.
[edit] user@host# commit
GTPv2 Traffic Logs
You can use the console or syslog to view GTPv2 traffic logs. You can configure the device to log GTPv2 packets based on their status. GTPv2 packet status can be any of the following:
Forwarded—GTPv2 packet was forwarded because it was valid.
State-invalid—GTPv2 packet was dropped because it failed stateful inspection or a sanity check. In case of a sanity check failure, the packet is marked as sanity.
Prohibited—GTPv2 packet was dropped because it failed message length, message type, or International Mobile Subscriber Identity (IMSI) prefix checks.
Rate-limited—GTPv2 packet was dropped because it exceeded the maximum rate limit of the destination GSN.
By default, GTPv2 logging is disabled on the device. You can use the set security gtp profile name log command to enable GTPv2 logging on the device.
Example: Enable GTPv2 Traffic Logs
This example shows how to enable GTPv2 traffic logging on a device.
Requirements
No special configuration beyond device initialization is required before configuring this feature.
Overview
In this example, you enable GTPv2 traffic logging for forwarded GTPv2 packets.
Configuration
Step-by-Step Procedure
To enable GTPv2 traffic logging for forwarded GTPv2 packets:
Specify the GTPv2 profile.
[edit] user@host# set security gtp profile gtp2
Enable logging for GTPv2 forwarded packets.
[edit] user@host# set security gtp profile gtp2 log forwarded basic
If you are done configuring the device, commit the configuration.
[edit] user@host# commit