Chapter 4 FortiOS Carrier : Configuring GTP on FortiOS Carrier : Configuring Encapsulated Filtering in FortiOS Carrier : Configuring Encapsulated IP Traffic Filtering
  
Configuring Encapsulated IP Traffic Filtering
Generally there are a very limited number of IP addresses that are allowed to encapsulate GPRS traffic. For example GTP tunnels are a valid type of encapsulation when used properly. This is the GTP tunnel which uses the Gp or Gn interfaces between SGSNs and GGSNs. However, a GTP tunnel within a GTP tunnel is not accessible — FortiOS Carrier will either block or forward the traffic, but is not able to open it for inspection.
The ability to filter GTP sessions is based on information contained in the data stream and provides operators with a powerful mechanism to control data flows within their infrastructure. You can also configure IP filtering rules to filter encapsulated IP traffic from Mobile Stations.
To configure the Encapsulated IP Traffic Filtering, go to Security Profiles > Carrier > GTP Profile, and edit a GTP profile. Expand Encapsulated IP Traffic Filtering to configure settings. See “Encapsulated IP traffic filtering options”.