Discover Mobile Device Attributes
Focus
Focus
IoT Security

Discover Mobile Device Attributes

Table of Contents

Discover Mobile Device Attributes

IoT Security discovers the attributes of mobile devices in G3, G4, and G5 cellular networks.
Where Can I Use This?What Do I Need?
  • IoT Security (Managed by IoT Security)
  • IoT Security subscription for an advanced IoT Security product (Enterprise Plus, Industrial OT, or Medical)
IoT Security can learn mobile (cellular) device attributes, add the devices to its inventory, and track them by the IMEI numbers. You can then see various mobile device attributes for them on the AssetsDevices and Device Details pages. You can also use the mobile device attributes when creating custom alerts. However, because they are classified as Traditional IT, IoT Security doesn’t make policy rule recommendations or send firewalls IP address-to-device mappings for mobile devices.

Set up PAN-OS to Send IoT Security Mobile Device Attributes

This assumes that IoT Security is already onboarded on your firewall, it has the required licenses and certificates, and logging is enabled.
  1. Enable GTP Security on the firewall.
    1. Log in to PAN-OS, select DeviceSetupManagement, and then click Edit (the gear icon) for General Settings.
    2. Select GTP Security and then click OK.
    3. Commit your changes and then select DeviceOperationsReboot Device.
  2. Create a Log Forwarding profile that includes GTP logging.
    1. Log back in and select ObjectsLog ForwardingAdd.
    2. Enter a name for the log forwarding profile like Mobile Device Logging, select Enable enhanced application logging to Strata Logging Service, and then click OK.
  3. Create a Mobile Network Protection profile for the types of mobile devices on the network.
    The following are the recommended settings that enable the correlation of user IDs and equipment IDs to user equipment IP addresses (UEIP) for different mobile devices. For details about each setting, see the Mobile Network Protection Profile help in PAN-OS.
      Expand all
      Collapse all
    • 5G mobile devices with RADIUS
    • 5G mobile devices with Packet Forwarding Control Protocol (PFCP)
    • 3G and 4G mobile devices with GTP-C
  4. Create Security policy rules to log mobile device traffic and forward the logs to the logging service.
    Create Security policy rules to log mobile device traffic and forward logs to the logging service for IoT Security to analyze. The rules you create depend on the generation of mobile devices on the network and whether the network uses RADIUS or PFCP.
      Expand all
      Collapse all
    • 5G mobile devices with RADIUS
    • 5G mobile devices with PFCP
    • 3G and 4G mobile devices with GTP-C
  5. Commit the configuration

View Mobile Device Attributes in IoT Security

After the firewall begins logging mobile device traffic, it forwards the traffic metadata in GTP logs to the logging service, which in turn streams it to IoT Security. To check the status of the GTP logs, log in to the IoT Security portal and select AdministrationFirewalls. There you can see if IoT Security is receiving GTP logs, the time of the latest log, and how many GTP log events and bytes it’s received.
To see mobile device attributes in the device inventory on the Devices page, select AssetsDevices. Because the Mobile Device columns are hidden by default, click the icon with three vertical bars to open the column selection panel, and select all the columns you want to see. All the columns displaying mobile device attributes are available in the Mobile section:
  • Mobile Equipment Identity – The 15-to-17-digit code assigned to every mobile device to uniquely identify it International Mobile Equipment Identity (IMEI)
  • Mobile Subscriber Identity – A unique identifier issued on a Subscriber Identity Module (SIM) card. In 2G, 3G, and 4G networks, this identifier is referred to as International Mobile Subscriber Identity (IMSI). In 5G networks, it is called Subscription Permanent Identifier (SUPI).
  • Mobile Subscriber ISDN – The Integrated Services Digital Network number is a mapping of a cellular telephone number to a mobile subscriber
  • Mobile APN (Access Point Name) – Term used to identify the external Packet Data Network (PDN) to which mobile devices connect through the 2G, 3G, or 4G cellular network. In a 5G network, it refers to the Data Network Name (DNN).
  • Radio Access Technology – The underlying connection method mobile devices use for wireless radio communications; for example, Bluetooth, Wi-Fi, UMTS, LTE, or 5G NR
  • Mobile Base Station Code – The identification number that uniquely identify a cellular base station
  • Mobile Area Code – The area code of the user’s location
  • Mobile Network Code (MNC) – A two-digit (European standard) or three-digit (North American standard) number identifying the Public Land Mobile Network (PLMN) of the mobile subscriber
  • Mobile Country Code (MCC) – A three-digit number identifying the country of the mobile subscriber
  • Mobile TAC (Type Allocation Code) – An eight-digit number that identifies the manufacturer of a mobile device
  • Network Slice – The logically discrete section of network operating over a common infrastructure
  • Mobile Device – The end user device operating on a wireless network
In addition to showing columns with these attributes in the inventory table, you can also use them in filters and queries at the top of the Devices page. They are displayed on the Device Details page of mobile devices and are available for use when creating custom alert rules.