sk106469 - Security Gateway drops GTP traffic with the log "Message includes unexpected information element type"
Security Gateway drops GTP traffic with the log "Message includes unexpected information element type"
Product: Carrier Security
Version: R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-02-01
Symptoms
- Security Gateway drops GTP traffic with this traffic log:
Message includes unexpected information element type XXX, failing parse. In case the IE should be accepted please add it to gtpv2_ignore_elements table in gtp.def
Example:
Message includes unexpected information element type 200, failing parse. In case the IE should be accepted please add it to gtpv2_ignore_elements table in gtp.def
Cause
The Security Gateway received an Information Element that is not expected with the particular message type (according to the 3GPP specification supported by the Security Gateway). This can often occur after equipment upgrade in the operator's or roaming partner's network.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 44
- Jumbo Hotfix Accumulator for R81.20 starting from Take 119
- Jumbo Hotfix Accumulator for R81.10 starting from Take 183
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Also, you can follow the available workaround procedure:
Background
GPRS Tunneling Protocol (GTP) is the communications protocol of mobile networks.
Important note:
After installing the relevant fix, the behavior of gtpv2_ignore_elements has changed. The system now supports two tables for ignoring Information Elements (IE):
- gtpv2_ignore_elements – recommended table, where IEs are matched more reliably, including those within group IEs.
- gtpv2_ignore_remaining_elements – a fallback table.
Action Plan
Review a full GTP packet capture and locate the Information Element (IE) that is being dropped.
In the packet capture, look for this section:
IE Type:
This is the Information Element (IE) that you will need to add to the relevant gtp.def file on the Security Management Server / Multi-Domain Security Management Server. Refer to sk107499 for the location of the relevant file.
Connect to the command line on the Security Management Server / Multi-Domain Security Management Server that manages the Security Gateway / Cluster.
Log in to the Expert mode.
Back up the relevant gtp.def file (in our example, we work with $FWDIR/lib/gtp.def):
cp -v $FWDIR/lib/gtp.def{,_BKP}
- Edit the file in plain-text editor:
vi $FWDIR/lib/gtp.def
- In the file, locate this line:
gtpv2_ignore_elements = {<MSG_ID1,IE_TYPE1>, <MSG_ID2,IE_TYPE2>};
Add the IE that you wish to ignore in one of the following format:
Recommended table to insert elements to be ignored:
gtpv2_ignore_elements = {<MSG_ID1,IE_TYPE1>, <MSG_ID2,IE_TYPE2>};Example for the message type 33 with IE 84 and type 32 with IE 121:
gtpv2_ignore_elements = {<33,84>, <32,121>};Fallback table:
gtpv2_ignore_remaining_elements = {IE_TYPE1>, <IE_TYPE2>};Example for the IE 84 and IE 121:
gtpv2_ignore_remaining_elements = {<84>, <121>};
Save the changes in the file and exit Vi editor.
In SmartConsole, install the Access Control policy on the Security Gateway / Cluster.
Test the GTP traffic.
Important Note
Some Information Elements (IEs) are mandatory according to the 3GPP specification. Therefore, adding them to the gtpv2_ignore_elements table will cause the parsing to fail due to their absence from the verification. For this reason, we recommend adding exceptions for IEs for each affected message type, as demonstrated in the example in point 2-f above.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.