The proxy that sits between every GTP conversation in your network.
GTP Proxy is a high-performance proxy positioned in the GTP signalling and data path between network nodes. It inspects, routes, filters, and secures GTP-C and GTP-U traffic — giving you one consistent control point across your mobile core, interconnect, and roaming edges.
Four jobs. One consistent GTP control point.
Inspect
Deep visibility into GTP-C signalling and GTP-U bearer traffic as it transits the proxy, down to individual Information Elements — not just headers.
Route
Steer GTP traffic based on the value of any Information Element — RAT-Type, Serving Network, ULI, APN, IMSI range — not just source/destination.
Filter
Enforce message- and IE-level policy: allow, block, or rewrite traffic that doesn't meet your operational rules.
Secure
Protect the signalling and data path at the GTP layer — a defensible perimeter for interconnect and roaming traffic.
Positioned exactly where GTP traffic needs a decision made.
GTP Proxy is deployed inline between GTP-enabled nodes — for example between an SGSN/MME/AMF and a GGSN/PGW/UPF, or at the interconnect boundary with a roaming partner. Because it understands GTP-C and GTP-U natively — down to individual header flags, optional Information Elements, and vendor Private Extensions — it can make routing, filtering, and security decisions at the message and IE level, not just at the IP layer.
That native understanding extends across access types, not just S5/S8: GTP Proxy sits on the S2b path from the ePDG just as naturally, so a subscriber's IMS/VoLTE session can hand over onto VoWiFi without the PGW-facing side ever seeing an inconsistent view of the session.
It's the "secure/automate" layer of the platform: the thing actually carrying and controlling GTP traffic, managed day-to-day through Grace, its built-in operations console, and continuously verified by Blaze.
Route on any GTP element — not just IP.
Because GTP Proxy parses every message natively, routing decisions can key off any Information Element it sees — radio access type, serving network, ULI, APN, IMSI range, QoS/ARP — alone or combined. That's a level of steering granularity a plain IP router or load balancer never sees.
# GTP Proxy routing rule — illustrative syntax
route_rule "NB-IoT roamers via Australia":
match CreateSessionRequest:
RAT-Type == NB-IoT
Serving-Network.MCC == 505 # Australia
APN matches "iot.*"
then:
route-to: iot-core-pool
apply-qos: iot-low-power-profile
charging-profile: iot-roaming-wholesale
An NB-IoT device roaming onto an Australian partner network carries a distinct RAT-Type and Serving Network Information Element the moment it attaches. GTP Proxy sees that combination on the Create Session Request itself and steers the session to a dedicated IoT core path — with IoT-appropriate QoS and a wholesale roaming charging profile — automatically, without the partner changing anything on their side.
The same pattern applies to any element: route premium-QoS subscribers to a faster path, isolate a problematic APN, or send a specific IMSI range to a lab environment for troubleshooting — see more element-based routing patterns. Or steer each MVNO's traffic on a shared sponsor APN — IMS, used for VoLTE, is the most common one — to that MVNO's own GGSN/PGW by IMSI/MNC, without ever splitting the APN.
Grace: everything it takes to operate GTP Proxy, without operating blind.
Grace is the management and monitoring console built into GTP Proxy — configuration, observability, policy control, and day-2 lifecycle in one operational surface built for network engineers and NOC/SRE teams. It's not a separate product to buy or deploy; it's how you run the Proxy you already have.
Configuration
Manage GTP Proxy routing, filtering, and security policy from one interface — version-controlled and auditable.
Live monitoring
Real-time visibility into GTP-C/GTP-U throughput, session state, error rates, and node health.
Policy management
Define, stage, and roll out GTP-level policy changes safely, with clear before/after visibility.
Day-2 lifecycle
Upgrades, scaling, and incident response for GTP Proxy — the operational surface a NOC actually lives in.
Built for the people who run the network
Designed around NOC and SRE workflows: dashboards, alerts, and controls that answer "what is happening right now" without needing to read raw GTP traces.
Change with confidence
Stage policy and configuration changes, preview their effect, and roll them out — or back — without guesswork.
One pane for one Proxy fleet
Manage a single GTP Proxy or a distributed fleet across sites and interconnects from a consistent operational view.
Where operators put GTP Proxy to work.
Interconnect & roaming protection
Sit at the edge of your mobile core and screen inbound GTP traffic from roaming and interconnect partners before it reaches core nodes.
Topology hiding
Present a single, stable GTP endpoint to external partners while your internal core network evolves behind it.
Policy enforcement at the signalling layer
Apply consistent GTP-level rules across every node in the core, enforced centrally instead of per-vendor.
MVNO gateway steering on shared APNs
Route each MVNO's traffic on a shared sponsor APN to that MVNO's own GGSN/PGW by IMSI/MNC, without splitting the APN or the sponsor's core.