Description | This article describes the solution for the error 'deny_cause="msg-filter' msgtypename="g-pdu' when GTP-U traffic is not working. |
Scope | FortiGate. |
Solution |
This error appears while troubleshooting GTPU-U traffic is not passing the firewall:
To examine the logs, ensure that both GTP-U and GTP-C logs are enabled in the GTP_Test_Profile. This will help identify if any packets are being dropped. The logs will show the 'deny_cause="msg-filter"', but the primary indicator is msgtypename="g-pdu", which signifies that the GTP-U traffic is being denied.
GTP Profile:
The GTP-U traffic is denied in message-filter-v0v1. Note that GTP-U messages always conform to GTP version 1
message-filter-v0v1:
config gtp message-filter-v0v
To resolve the issue, the set gtp-pdu enable option must be enabled in message-filter-v0v1. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.