Bridging the Skies: How Signaling Unlocks the Satellite-to-Mobile Revolution Read newspost
5G Traffic Growth Accelerates as India Closes the Gap with 4G Read newspost
6G Core Debate Raises Familiar Questions About Standards and Evolution Read newspost

Security Edge Protection Proxy (SEPP)

Secure your 5G interconnects with the BroadForward SEPP. Serving as the security gateway for N32 HTTP/2 SBI traffic, it delivers TLS hop-by-hop protection for N32 traffic and optional end-to-end (PRINS) security with optional advanced topology hiding and 5G firewalling in accordance with GSMA FS.36 (5G Interconnect Security Guidelines) to safeguard inter-PLMN roaming, ensure 3GPP compliance, and scale global 5G SA interconnects.

Deployment options:

  • Bare metal Bare metal
  • Virtual machine Virtual machine
  • Container Container
  • Cloud Cloud

Features:

  • GUI based configuration management
  • TLS hop-by-hop protection
  • Dynamic peer discovery
  • Topology hiding
  • gRPC interface for traffic monitoring
  • 5G Firewall according to FS.36

Foundation

The BroadForward SEPP in your Network

The BroadForward Security Edge Protection Proxy (SEPP) provides the network with a strong and active security and policy enforcement layer at the inter‑PLMN boundary. When deployed, it centrally governs all HTTP/2 N32 SBI traffic exchange with roaming partners. The SEPP manages N32‑c security negotiations, performs N32‑f signing and encryption, enforces anti‑spoofing and trust policies, and orchestrates dynamic cross‑border routing – giving operators full visibility, protection, and control over how their 5G core interacts with external networks and IPX providers. The BroadForward SEPP is built for carrier grade performance, delivering stable low latency processing and high transaction throughput on modern multi core deployments, suitable for high end roaming environments and IPX interconnects.

Years of BFX USC in production
0
Operators running BFX USC
0 +
GSMA GLOMO winner
0 x

Trusted by

liberty-global
2DEGREES
AIRALO
ALIANZA
ARELION
ATOS
BICS
CELLUSYS
CGI
CIRRUS
CLARO
COMFONE
DIGICEL
DOCOMO
EMIRCOM
ENGHOUSE
ETISALAT
IBASIS
ICONECTIV TNS
LEBARA
M1
MOBIFONE
MODULO
MTN BYOBAB
NGVOICE
NOMIOS
NSSOL
NTT
ODINE
ORANGE
POLKOMTEL
PROXIMUS
SAMSUNG
TATA
TELENET
TELKOMSEL
TELMEX
TERRESTAR
TURK TELEKOM INTL
UNITEL
VODAFONE

Multi-tenancy

Securing 5G Roaming: Centralized Protection for Inter-PLMN Architectures

Every BroadForward product runs on the BFX USC - one engine, one operational model. Adding and working with new 2G–5G signaling functions is straightforward because all BroadForward products use the same GUI, provisioning model, workflows, and operational environment - one interface for all signaling.

Features a 100% graphical interface for configuring N32 security rules, message harmonization, and inter-PLMN routing policies, empowering operators to adapt to partner requirements instantly without custom coding or expensive vendor (change) requests.

Includes native 4G-to-5G interworking functions (IWF) to connect HTTP/2 service-based 5G core functions directly with legacy Diameter nodes (like 4G PCRF and EIR) for phased network function implementations and network migrations

BroadForward SEPP

Trusted by professionals

See why leading professionals choose BroadForward.

We’re proud to have been leveraging the BroadForward platform for quite a while. The solution has played an important role in enabling connectivity with operators and providers preparing for the 5G SA era. Its flexibility, reliability, and future-ready architecture make it a standout platform in the industry.

This not only saves money, but critically speeds time to market

An elegant and innovative solution to a legacy problem of critical voice networks — fulfils an immediate market need

One of the few independent signaling experts successful in winning business from operators looking for a multi-technology signaling platform

BroadForward’s solutions have already strengthened our signaling capabilities, driving greater operational efficiency

We’re proud to have been leveraging the BroadForward platform for quite a while. The solution has played an important role in enabling connectivity with operators and providers preparing for the 5G SA era. Its flexibility, reliability, and future-ready architecture make it a standout platform in the industry.

This not only saves money, but critically speeds time to market

An elegant and innovative solution to a legacy problem of critical voice networks — fulfils an immediate market need

One of the few independent signaling experts successful in winning business from operators looking for a multi-technology signaling platform

BroadForward’s solutions have already strengthened our signaling capabilities, driving greater operational efficiency

Specifications

Everything you need to evaluate, in one place

Supported Standards & Core Features

  • 3GPP N32 Interface Support Fully compliant with 3GPP TS 29.573 and TS 33.501, supporting N32-c control plane capability negotiation and N32-f secure payload transfer.
  • One Engine, Any Protocol All BroadForward products run on the BFX Unified Signaling Core (USC), providing one engine and one operational model for all 2G–5G signaling functions. The same GUI and workflows apply across all products, delivering a single interface for all signaling.
  • Script-Free GUI Signaling Orchestration Provides a 100% graphical environment to build custom inter-PLMN routing rules, N32 security policies, and mediation workflows without scripts, vendor CRs or custom software development.
  • Efficient & Cloud‑Agnostic Architecture Designed for low resource consumption and maximum deployment flexibility across bare metal, virtualized platforms, containers, or hybrid cloud environments.

Extended Features

  • IPX & Hosted SEPP Multi-Tenancy Supports multi-tenant operational models enabling IPX providers and MNO groups to host SEPP services for multiple (virtual) operators from a single software instance.
  • 3GPP Security & OAuth2 Inter-PLMN Protection Enforces TLS 1.3 encryption across inter-operator borders, validates TLS certificate authentication or optionally uses OAuth2 access tokens, and prevents cross-border identity spoofing and unauthorized SBI requests.
  • Topology Hiding & Privacy Protection Provides configurable rules for removing, rewriting, or masking topology‑related information in HTTP/2 SBI messages across the N32 interface, hiding internal network details such as FQDNs, IP addresses, and sensitive headers before traffic leaves the PLMN border.
  • gRPC Interface for Traffic Monitoring Provides a dedicated channel that forwards decrypted copies of SEPP signaling traffic to the operator's network monitoring and analysis systems.
  • 3GPP 4G–5G Roaming Interworking (IWF) Interworking capabilities connecting 5G N24-based roaming policy signaling (carried over N32) with legacy 4G Diameter infrastructure.
  • HTTP/2 JOSE Encryption & Signing (PRINS) Enforces Application-Layer Security using JSON Object Signing and Encryption (JOSE) for message integrity, confidentiality (PRINS) over N32-f.
  • Dynamic peer discovery for remote SEPP service Dynamic peer discovery via DNS SRV for remote SEPP for a required MCC/MNC plus well-known FQDN, avoiding the need to preconfigure all remote SEPP peers and transport details.
  • Extendable with Onboard 5G Firewall Extends SEPP with a FS.36 compliant defense shield for all 5G signaling across the interconnect boundary between mobile operators.

Get more product information

Request the latest data sheet for the BroadForward SEPP and share it with your team for a complete technical overview.

  • Full technical specifications and feature list
  • Inter-PLMN deployment architecture and IPX integration overview
A person in a suit smiles while holding a BroadForward GLOMO award.

FAQ

We are happy to help you with any questions.

Deployment

Freedom of Environment: Deploying Where it Makes Sense

With the BFX Unified Signaling Core (USC) at its foundation, operators are not tied to a specific hardware vendor, appliance cycle, or hyperscaler. The BroadForward SEPP can be deployed or migrated across virtual machines, containers, or bare metal, using the same configuration, without re engineering. Because BroadForward SEPP separates the underlying execution platform from its routing logic, N32 security configurations, and firewall profiles, moving environments requires no re-engineering. All border security rules, N32 control profiles, topology-hiding configuration, and connection configurations built in the GUI can be exported as clean, platform-independent configuration files.

Bare metal

Maximum performance on existing server hardware. No hypervisor overhead.
Bare metal

Virtual machine

Deploy on your current hypervisor. Full HA and geo-redundancy supported.
Virtual machine

Container

Kubernetes-orchestrated. Automated lifecycle management. Scales horizontally.
Container

Cloud

Public, private, or hybrid. Scales without re-architecture as your network grows.
Cloud
Search

Change language