GTPv2 Tunnel Cleanup and Traffic Logs

Learn how to configure, verify, monitor GTPv2 tunnel behavior, including enabling traffic logging to track forwarded, dropped, or rate-limited packets for effective troubleshooting and visibility.

GTPv2 Tunnel Cleanup

A GPRS tunneling protocol version 2 (GTPv2) tunnel enables transmission of GTPv2 traffic between GPRS support nodes (GSNs).

While transmitting traffic, GTPv2 tunnels might hang for a number of reasons. For example, delete-pdp-request messages might get lost in the network, or a GSN might not shut down properly. In such a case, you can remove hanging GTPv2 tunnels either automatically or manually.

To remove a hanging GTPv2 tunnel automatically, you need to set a GTPv2 tunnel timeout value on the device. The device automatically identifies and removes a tunnel that is idle for the period specified by the timeout value. The default GTPv2 tunnel timeout value is 36 hours.

You can use the set security gtp profile name timeout command to configure this value on the device. The timeout range is 1 through 1000 hours.

To remove a hanging GTPv2 tunnel manually, you need to use the clear security gtp tunnel command.

Example: Set the Timeout Value for GTPv2 Tunnels

This example shows how to set the timeout value for GTPv2 tunnels.

Requirements

No special configuration beyond device initialization is required before configuring this feature.

Overview

In this example, you set the tunnel timeout value to 40 hours for the GTPv2 inspection object named gtp2.

Configuration

Step-by-Step Procedure

To configure the GTPv2 tunnel timeout value:

  1. Specify the GTPv2 profile.

  2. Specify the timeout value.

  3. If you are done configuring the device, commit the configuration.

Verification

Confirm that the configuration is working properly.

Verify GTPv2 Tunnel Timeout Value

Purpose

Verify that GTPv2 tunnel timeout value.

Action

From operational mode, enter the show security gtp command.

GTPv2 Traffic Logs

You can use the console or syslog to view GTPv2 traffic logs. You can configure the device to log GTPv2 packets based on their status. GTPv2 packet status can be any of the following:

  • Forwarded—GTPv2 packet was forwarded because it was valid.

  • State-invalid—GTPv2 packet was dropped because it failed stateful inspection or a sanity check. In case of a sanity check failure, the packet is marked as sanity.

  • Prohibited—GTPv2 packet was dropped because it failed message length, message type, or International Mobile Subscriber Identity (IMSI) prefix checks.

  • Rate-limited—GTPv2 packet was dropped because it exceeded the maximum rate limit of the destination GSN.

By default, GTPv2 logging is disabled on the device. You can use the set security gtp profile name log command to enable GTPv2 logging on the device.

Example: Enable GTPv2 Traffic Logs

This example shows how to enable GTPv2 traffic logging on a device.

Requirements

No special configuration beyond device initialization is required before configuring this feature.

Overview

In this example, you enable GTPv2 traffic logging for forwarded GTPv2 packets.

Configuration

Step-by-Step Procedure

To enable GTPv2 traffic logging for forwarded GTPv2 packets:

  1. Specify the GTPv2 profile.

  2. Enable logging for GTPv2 forwarded packets.

  3. If you are done configuring the device, commit the configuration.