Guest

Subscriber-Aware Firewall

Introduction

Protect Your Network’s Borders

Protect mobile data network borders by maintaining tight per-subscriber control over the traffic traversing firewalls. Subscriber-Aware Firewall is based on the RADIUS Accounting Inspection capabilities available on Cisco’s stateful firewall devices, including the Cisco PIX Firewall family, the Adaptive Security Appliance family, and the Cisco 7600 Firewall Service Module.

RADIUS Accounting Start and Stop messages originated by the Gateway GPRS Support Node link Mobile Subscriber IDs with each session opened by the firewall protecting the mobile data network border.

Unlike other firewalls, which only associate IP addresses with open sessions, the Subscriber-Aware Firewall ensures that open sessions are immediately closed when a mobile subscriber disconnects from the mobile data network.

Subscriber-Aware Firewall prevents persistent, malicious, or externally originated traffic from reaching subscribers who are assigned the same temporary IP address via Dynamic Host Resolution Protocol as a previous subscriber.

More Resources