BroadForward SEPP powers the world’s first live 5G standalone roaming connection
Achieving the highest GSMA recognition as the leading signaling experts
World-class signaling products: when progress matters to you
Providing network functions to the world’s leading MNOs, MVNOs, IoT, MNP and IPX providers

5G Firewall (5GFW)

The BroadForward 5G Firewall (5GFW) is a complete, software‑based signaling security solution that protects 5G Standalone networks against attacks, unauthorized senders, malformed messages and other signaling‑layer threats. The 5GFW supports the GSMA FS.36 guidelines for 5G Service‑Based Architecture (SBA) security and can be deployed alongside the BroadForward SEPP, Diameter Firewall (DFW) and SS7 Firewall (SS7FW).

Latest firewall requirements

Firewall technology has evolved from fixed, black‑box rule sets into flexible, multi‑access security solutions capable of adapting to new threats and new network technologies. Many existing security products, however, do not provide consistent protection across 2G, 3G, 4G and 5G, nor do they offer the flexibility required to comply with the latest industry recommendations.

With the rise of signaling‑layer attacks, governments and regulators worldwide are demanding more stringent security measures. Industry bodies such as the GSMA have published new guidelines, including FS.36, to address threats emerging during the transition to 5G Standalone.

The introduction of a 5G Service‑Based Architecture (SBA), built on HTTP/2 communication between network functions, brings scalability and flexibility but also exposes operators to a new class of signaling threats. As operators expand 5G SA deployments and prepare for 5G roaming, securing interconnect traffic and preventing protocol abuse becomes essential. New specifications are often open to interpretation, requiring solutions that allow operators to adapt security rules dynamically. The complexity of modern networks also increases the need for non‑intrusive, live testing of firewall rules to verify their effectiveness without impacting traffic.

BroadForward 5G Firewall – Advanced signaling security for 5G Standalone networks

The BroadForward 5GFW provides advanced protection for all interfaces referenced by FS36. It inspects and validates HTTP/2 signaling traffic, enforces security policies and prevents malicious or non‑compliant behavior across the 5G Core. The 5GFW includes a default set of firewall rules aligned with GSMA FS.36, and none of the rules are hard‑coded. Operators can fully adapt and extend them as needed.

The intuitive Graphical User Interface provides complete control over firewall rules and full visibility into signaling traffic. Operators can configure, adapt, enable or disable rules across all supported access technologies without scripting, coding or vendor involvement. Rule enforcement is reflected in Event Detail Records, supporting improvements in interconnect management and compliance with NG.113 (5G), IR.88 and IR.21.

The 5GFW can be deployed alongside BroadForward SEPP, SCP, BSF, DFW and SS7FW, providing a unified signaling security framework. Also see: BroadForward again recognized by Kaleido as Champion vendor for signaling security

Transparent Mode

Each mobile network has unique security requirements, and implementation teams must ensure firewall rules are both effective and safe. The BroadForward Firewall includes a unique transparent mode feature that allows operators to test and fine‑tune security rules on the live network without impacting traffic.

New rules can be introduced in transparent mode, where they are evaluated and logged but do not block traffic until fully validated. This enables safe, non‑intrusive verification of rule effectiveness before activation.

GSMA FS.36 Capabilities

The BroadForward 5GFW natively supports the GSMA FS.36 recommendations for 5G interconnect security, enabling operators to implement a consistent, standards‑based security framework for roaming traffic:

  • Category 1 – analysis of the URI & HTTP method to ensure protection of interfaces meant for internal use only (only roaming traffic is allowed to enter MNO network).
  • Category 2 – detailed screening of subscriber identifier information elements to ensure messages from international interconnect do not target internal subscribers.
  • Category 3 – 5G interconnect messages filtering based on subscriber location and time-based criteria to prevent anomalous or fraudulent signaling activity.
  • Message Validation – Deep inspection and parsing of HTTP/2 messages to ensure structural correctness and contextual compliance.
  • Origin Authentication – Verifies the identity of sending network functions to prevent unauthorized access and spoofing.
  • Routing Control – Policy‑based routing and filtering to ensure only legitimate traffic reaches critical network functions.

BroadForward 5GFW Features

The BroadForward 5GFW significantly enhances operator capabilities to detect and mitigate unexpected or fraudulent traffic, providing major advantages over traditional firewall products:

  • Unrivaled flexibility – Routing, screening and filtering on any required HTTP/2 message parameter. Full freedom to create and adapt rules without coding, scripting or vendor dependency.
  • Transparent mode support – Unique, live, non‑intrusive testing of security rules with Event Detail Record logging for offline evaluation.
  • Comprehensive SBA protection – Advanced protection across critical 5G Core interfaces interfaces used in roaming scenarios. including SEPP-SEPP (N32), AMF – UDM (N8), SMF – UDM (N10), AMF – AUSF (N12) and other service‑based functions.
  • GSMA FS.36 compliant – Built around industry‑standard 5G interconnect security parameters.
  • Unified security suite – 2G/3G/4G and 5G firewall support in a single software engine running on the GSMA award winning BroadForward BFX Unified Signaling Core (USC) platform.
  • Flexible deployment models – Standalone 5GFW or co‑hosted with BroadForward SEPP, using a common GUI and single capacity license.
  • Completely GUI‑based – All configuration, rule orchestration, monitoring and management via the graphical interface. NOTE: CLI, scripting or API modifications can be applied as well depending on customer needs and available integrations.
  • Optional co-hosting with SEPP function(s) – Providing additional interconnect security capabilities such as topology hiding, certificate validation and end to end protection across N32 interfaces.
  • Carrier‑grade – Highly scalable, high‑availability, geo‑redundant architecture.

Optional support for

Virtualized, cloud‑based and containerized deployment

The BroadForward 5GFW offers unmatched deployment flexibility, supporting bare metal, virtual machines, containers and cloud environments (Such as RHOS and Kubernetes based platforms). This 100% software‑based, cloud‑agnostic and hardware‑independent solution eliminates the need for specialized hardware or proprietary operating systems, enabling seamless scaling without vendor lock‑in.