3GPP 23.501 v20.2.0 — the document's own text
6.2.9 N3IWF
Taught in 4. What each network function does (The 5G system architecture, in depth), 2. Who does what in the core (The 5G system architecture, overview).
The functionality of N3IWF in the case of untrusted non-3GPP access includes the following:
- Support of IPsec tunnel establishment with the UE: The N3IWF terminates the IKEv2/IPsec protocols with the UE over NWu and relays over N2 the information needed to authenticate the UE and authorize its access to the 5G Core Network.
- Termination of N2 and N3 interfaces to 5G Core Network for control - plane and user-plane respectively.
- Relaying uplink and downlink control-plane NAS (N1) signalling between the UE and AMF.
- Handling of N2 signalling from SMF (relayed by AMF) related to PDU Sessions and QoS.
- Establishment of IPsec Security Association (IPsec SA) to support PDU Session traffic.
- Relaying uplink and downlink user-plane packets between the UE and UPF. This involves:
- De-capsulation/ encapsulation of packets for IPSec and N3 tunnelling.
- Enforcing QoS corresponding to N3 packet marking (e.g. DSCP), taking into account QoS requirements associated to such marking received over N2. QoS includes 5QI, the Priority Level (if explicitly signalled) and optionally, the ARP priority level.
NOTE: Based on operator policy and/or regional/national regulations, the N3IWF can apply a different DSCP value to the outer ESP tunnel packet than the DSCP value of the inner IP packet.
- Packet marking, e.g. setting the DSCP value based on the Establishment cause on N2 and based on 5QI, the Priority Level (if explicitly signalled) and optionally, the ARP priority level on N3.
- Local mobility anchor within untrusted non-3GPP access networks using MOBIKE per IETF RFC 4555 [57].
- Supporting AMF selection.
- Support of ECN marking for L4S: The SMF, if applicable, provides ECN marking request per QoS flow level to the N3IWF as part of PDU session management procedures.
- When ECN marking for L4S at N3IWF is enabled for downlink or uplink, the N3IWF should set the Congestion Experienced (CE) codepoint in downlink or uplink as per the recommendations in IETF RFC 9330 [159], IETF RFC 9331 [160], IETF RFC 9332 [161], IETF RFC 6040 [198] and IETF RFC 9599 [199].
- Optionally, supporting PDU Set based Handling as defined in clause 5.37.5.