Trellix Intrusion Prevention System enables you to monitor traffic in a mobile network. IPS for mobile networks is supported for NS-series models.
Sensors deployed in mobile networks monitor subscriber traffic and RADIUS accounting traffic that goes out of GGSN to Internet gateway and RADIUS servers. Each mobile device in the network has an IP address. When IPS inspection is enabled using the set mnsconfig command, the Sensor parses RADIUS accounting exchanged between GGSN and the RADIUS server and forms an association of IP addresses and subscriber mobile identity details like phone number, IMSI number, and APN. The Sensor also associates the attacks that are detected on the internet traffic with the mobile subscriber identity data and includes them in alerts sent to the Manager.
Due to the use of fixed source and destination ports in all RADIUS packets that are exchanged over UDP by the GGSN/RADIUS server, there is a possibility that the Sensor could miss parsing RADIUS accounting traffic at high data rates. This situation can be avoided by using the set mnsconfig radiusLB CLI command.
When the mobile security feature is enabled, Sensors can detect application download on Android (.apk file) and work with Trellix GTI File Reputation to detect/block malware.
You can monitor subscriber and RADIUS accounting traffic using the following CLI commands:
set mnsconfig on/ off: Enables capturing and tagging of mobile subscriber data in the alerts sent to the Manager. This feature is disabled by default. Mobile entries are not persisted across a Sensor reboot.set mnsconfig radiusLB on/ off: Enables/ disables RADIUS traffic load balancingshow mnsconfig: Displays the status of mobile network security (enabled or disabled)
For more information on the CLI commands, see the CLI commands section.