Bridging the Skies: How Signaling Unlocks the Satellite-to-Mobile Revolution Read newspost
5G Traffic Growth Accelerates as India Closes the Gap with 4G Read newspost
6G Core Debate Raises Familiar Questions About Standards and Evolution Read newspost

5G Firewall (5GFW)

Protect your 5G network with the BroadForward 5G Firewall, the FS.36 compliant defense shield for all 5G signaling across the interconnect boundary between mobile operators. It secures the 5G roaming and inter PLMN/IPX domain – the trust zone where 5G cores exchange SBA (HTTP/2) signaling, and protects 5G networks against possible attacks, unauthorized senders, fraud, cross operator signaling threats and much more.

Deployment options:

  • Bare metal Bare metal
  • Virtual machine Virtual machine
  • Container Container
  • Cloud Cloud

Features:

  • GUI based firewall rules enablement and configuration
  • Follows GSMA FS.36 recommendations
  • Transparent mode for non-blocking trail of firewall rules
  • UE-tracking for cat.3 location/velocity time-distance plausibility determination
  • Can be combined with SEPP service
  • Topology Hiding with dynamic obfuscation

The BroadForward 5G Firewall in your Network

The BroadForward 5G Firewall (5GFW) is the network’s active defense and enforcement layer for all HTTP/2 SBI signaling inside a 5G Standalone core. It establishes a unified security perimeter that continuously inspects, filters, and governs service‑based traffic across intra‑PLMN, roaming, and IPX borders, protecting 5G networks from malicious requests, spoofing, location‑tracking exploits, roaming abuse, denial of service (DoS), and unauthorized data extraction.

The 5GFW is part of BroadForward’s signaling security portfolio, recognized across the industry with its GSMA GLOMO‑nominated firewall engine and Champion status in Kaleido Intelligence’s Roaming Vendor Hub 2025–2026 (ranking among the top 16 vendors out of 80). It enables operators to gain full visibility and control over 5G security, ensuring that every inbound and outbound message adheres to strict trust, policy, and threat‑mitigation rules.

Years of BFX USC in production
0
Operators running BFX USC
0 +
GSMA GLOMO winner
0 x

Trusted by

liberty-global
2DEGREES
AIRALO
ALIANZA
ARELION
ATOS
BICS
CELLUSYS
CGI
CIRRUS
CLARO
COMFONE
DIGICEL
DOCOMO
EMIRCOM
ENGHOUSE
ETISALAT
IBASIS
ICONECTIV TNS
LEBARA
M1
MOBIFONE
MODULO
MTN BYOBAB
NGVOICE
NOMIOS
NSSOL
NTT
ODINE
ORANGE
POLKOMTEL
PROXIMUS
SAMSUNG
TATA
TELENET
TELKOMSEL
TELMEX
TERRESTAR
TURK TELEKOM INTL
UNITEL
VODAFONE

Multi-tenancy

Safeguard Your 5G Architecture: Industry-Recognized Security Defense

Every BroadForward product runs on the BFX USC - one engine, one operational model. Adding and working with new 2G–5G signaling functions is straightforward because all BroadForward products use the same GUI, provisioning model, workflows, and operational environment - one interface for all signaling.

Features a 100% graphical interface (CLI is also supported) for building custom security policies, inspection rules, and anomaly detection workflows, empowering security teams to adapt to emerging threats instantly without waiting for vendor code updates.

Built on BroadForward’s GSMA GLOMO nominated firewall engine and backed by the BroadForward’s Champion status in Kaleido Intelligence’s Roaming Vendor Hub - acknowledging BroadForward’s leadership in signaling security.

BroadForward 5GFW

Trusted by professionals

See why leading professionals choose BroadForward.

We’re proud to have been leveraging the BroadForward platform for quite a while. The solution has played an important role in enabling connectivity with operators and providers preparing for the 5G SA era. Its flexibility, reliability, and future-ready architecture make it a standout platform in the industry.

This not only saves money, but critically speeds time to market

An elegant and innovative solution to a legacy problem of critical voice networks — fulfils an immediate market need

One of the few independent signaling experts successful in winning business from operators looking for a multi-technology signaling platform

BroadForward’s solutions have already strengthened our signaling capabilities, driving greater operational efficiency

We’re proud to have been leveraging the BroadForward platform for quite a while. The solution has played an important role in enabling connectivity with operators and providers preparing for the 5G SA era. Its flexibility, reliability, and future-ready architecture make it a standout platform in the industry.

This not only saves money, but critically speeds time to market

An elegant and innovative solution to a legacy problem of critical voice networks — fulfils an immediate market need

One of the few independent signaling experts successful in winning business from operators looking for a multi-technology signaling platform

BroadForward’s solutions have already strengthened our signaling capabilities, driving greater operational efficiency

Specifications

Everything you need to evaluate, in one place

Supported Standards & Core Features

  • GSMA 5G Security Guidelines (FS.36) Fully compliant with GSMA guidelines for 5G Service-Based Architecture security, screening for Category 1, 2, and 3 cross-border and cross-protocol vulnerabilities.
  • HTTP/2 & JSON Deep Packet Inspection (DPI) Performs Layer 4 through Layer 7 stateful inspection of HTTP/2 headers, RESTful URI paths and JSON body payloads in real time.
  • GSMA Award-Nominated Firewall Technology Nominated by the GSMA for the prestigious Global Mobile (GLOMO) Awards, recognizing BroadForward's proven leadership and innovation in signaling security.
  • Script-Free GUI Security Rules Engine Provides a 100% graphical environment to build, test, and activate custom security rules, payload filters, and threat mitigations without writing code or paying vendor CR fees.
  • Native Multi-Layer Protocol Inspection Inspects and correlates traffic directly at the protocol translation boundary, preventing cross-PLMN security exploits from becoming real threats.
  • Efficient & Cloud‑Agnostic Architecture Designed for low-latency, cloud-native deployment on Kubernetes-based or Red Hat OpenShift container environments, virtual machines, or bare-metal edge nodes.

Extended Features

  • Velocity Tracking & Time-Distance Plausibility Detects implausible subscriber location jumps across international borders to stop SIM swap fraud, service/billing abuse and mobile identity theft.
  • Transparent Mode Support New security rules can be introduced in transparent mode, where they are evaluated and logged but do not block traffic until fully validated.
  • Converged Multi-Gen Security Engine BroadForward products run on a common signaling engine, BFX USC. One engine, one operational model - Adding and working with new 2G–5G signaling functions is straightforward because all BroadForward products use the same GUI, provisioning model, workflows, and operational environment - one interface for all signaling. Each function deploys independently on bare metal, virtual machines, or containers.
  • Topology Hiding & Anonymization Strips internal network routing details, FQDNs, callback-URIs, notification-URIs and private IP addresses from outbound HTTP/2 traffic.
  • OAuth2 & Transport Layer Security Validation Enforces strict TLS 1.3/1.2 handshake verification, token validation, and OAuth2 access control to prevent rogue NFs and identity spoofing.
  • Rate Limiting Selective Ingress Throttling Provides dynamic traffic throttling, request validation, and burst suppression to protect critical 5G core databases (UDM, UDR, NRF) from signaling overloads.

Get more product information

Request the latest data sheet for the BroadForward 5G Firewall and share it with your security team for a complete technical overview.

  • Full technical specifications and security feature list
  • Deployment topology and multi-generation firewall integration overview
A person in a suit smiles while holding a BroadForward GLOMO award.

FAQ

We are happy to help you with any questions.

Deployment

Freedom of Environment: Deploying Where it Makes Sense

With the BFX Unified Signaling Core (USC) at its foundation, operators are not tied to a specific hardware vendor, appliance cycle, or hyperscaler. The BroadForward 5G Firewall can be deployed or migrated across virtual machines, containers, or bare metal, using the same configuration, without re engineering. Because the BroadForward 5G Firewall separates the underlying execution platform from its threat inspection rules, state tables, and security profiles, moving environments requires no re-engineering. All firewall inspection logic, GSMA security rules, topology-hiding profiles, and cross-protocol-layer correlation logic built in the GUI can be exported as clean, platform-independent configuration files.

Bare metal

Maximum performance on existing server hardware. No hypervisor overhead.
Bare metal

Virtual machine

Deploy on your current hypervisor. Full HA and geo-redundancy supported.
Virtual machine

Container

Kubernetes-orchestrated. Automated lifecycle management. Scales horizontally.
Container

Cloud

Public, private, or hybrid. Scales without re-architecture as your network grows.
Cloud
Search

Change language