Chapter 4 FortiOS Carrier : Configuring GTP on FortiOS Carrier : Configuring Encapsulated Filtering in FortiOS Carrier
  
Configuring Encapsulated Filtering in FortiOS Carrier
Encapsulated traffic on the GPRS network can come in a number of forms as it includes traffic that is “wrapped up” in another protocol. This detail is important for firewalls because it requires “unwrapping” to properly scan the data inside. If encapsulated packets are treated as regular packets, that inside layer will never be scanned and may allow malicious data into your network.
On Carrier-enabled FortiGate units, GTP related encapsulated filtering falls under encapsulated IP traffic filtering, and encapsulated non-IP end user address filtering.