3GPP 23.501 v20.2.0 — the document's own text
5.8.6 Node Level rule for abnormal traffic handling
Taught in 13. Where the packets actually go (The 5G system architecture, in depth), 5. The connection, and what is promised on it (The 5G system architecture, overview).
To mitigate abnormal user plane traffic, the UPF can be configured by SMF with Node Level rule(s) which indicate node level handling actions for different types of abnormal traffic. The format of the Node Level rule is as follows:
Table 5.8.6-1: Node Level rule configured on UPF by SMF
| Attribute | Description |
|---|---|
| Node Level rule ID | Unique identifier to identify this rule. |
| Traffic Filters (NOTE 1) | This IE can contain multiple Packet Filter Sets or Application IDs. This IE can also be empty when SMF provides the Node Level rule to allow the IE to be populated based on Packet Filter Sets or Application IDs received in the Analytics output and in this case, each Packet Filter Set is associated with a timer that is set as described in clause 5.54. |
| Type of Abnormal traffic (NOTE 1) | (Conditional), Contains one of the types of abnormal traffic as described in clause 6.24.3 of TS 23.288 [86]. |
| Mitigation Action | Identifies the mitigation action (as described below) to apply to the packet corresponding to the Traffic Filters. |
| NOTE 1: See detailed description on the usage of these attributes in clause 5.54. |
Possible mitigation actions are:
- Drop: Block traffic matching Application ID/IP Packet Filter Set.
- Throttle: Apply bandwidth limitation (e.g. to a pre-configured value in Mbps) to the traffic matching Application ID/IP Packet Filter Set.
- Inhibit Downlink Data Reporting (DLDR): When UE is in IDLE mode and receives (DL) traffic matching Application ID/IP Packet Filter Set, UPF does not trigger N4 DLDR notification towards SMF, thus avoiding waking up UE unnecessarily (due to abnormal traffic).