IoT MVNO Growth Accelerates as Intelligent Signaling Becomes Critical Read newspost
China Becomes the World’s Largest 5G Market Read newspost
MVNO Momentum Accelerates Worldwide Read newspost

Security Edge Protection Proxy (SEPP)

Secure your 5G interconnects with the BroadForward SEPP. Serving as the ultimate security gateway for N32 HTTP/2 SBI traffic, it delivers end-to-end N32-c/N32-f protection, PRONT security, and advanced topology hiding-to effortlessly safeguard inter-PLMN roaming, ensure 3GPP compliance, and scale global 5G SA interconnects.

Deployment options:

  • Bare metal Bare metal
  • Virtual machine Virtual machine
  • Container Container
  • Cloud Cloud

Features:

  • GUI config management
  • TLS-Hop-By-Hop
  • PRINS (roadmap)
  • Dynamic Peer Discovery
  • Topology Hiding
  • Firewall according to FS.36 (Optional)

Foundation

The BroadForward SEPP in your Network

The BroadForward Security Edge Protection Proxy (SEPP) provides the network with a strong and active security and policy enforcement layer at the inter‑PLMN boundary. Once deployed, it centrally governs all HTTP/2 SBI traffic exchanged with roaming partners, replacing fragmented bilateral integrations with a controlled, policy‑driven security perimeter. The SEPP manages N32‑c security negotiations, performs N32‑f JOSE signing and encryption, enforces anti‑spoofing and trust policies, and orchestrates dynamic cross‑border routing – giving operators full visibility, protection, and control over how their 5G core interacts with external networks.

Years of BFX in production
0 +
Operators running BFX globally
0
GSMA GLOMO winner
0 x

Trusted by

Multi-tenancy

Securing 5G Roaming: Centralized Protection for Inter-PLMN Architecture

Runs on BroadForward’s BFX Unified Signaling Core (USC) platform, allowing operators to co-host 5G SEPP alongside SCP, STP, DSC, and BSF-eliminating border silos, reducing integration points, and lowering total cost of ownership.

Features a 100% graphical interface for configuring N32 security rules, message harmonization, and inter-PLMN routing policies, empowering operators to adapt to partner requirements instantly without custom coding.

Includes native 2G/3G/4G-to-5G interworking functions (IWF) to connect HTTP/2 inter-PLMN 5G core functions directly with legacy roaming infrastructure (SS7/MAP and 4G Diameter S9/S6a) for seamless cross-border migration.

Trusted by professionals

See for yourself why professionals choose BroadForward.

We’re proud to have been leveraging the BroadForward platform for quite a while. The solution has played an important role in enabling connectivity with operators and providers preparing for the 5G SA era. Its flexibility, reliability, and future-ready architecture make it a standout platform in the industry.

An elegant and innovative solution to a legacy problem of critical voice networks — fulfils an immediate market need

This not only saves money, but critically speeds time to market

An elegant and innovative solution to a legacy problem of critical voice networks — fulfils an immediate market need

This not only saves money, but critically speeds time to market

One of the few independent signaling experts successful in winning business from operators looking for a multi-technology signaling platform

BroadForward’s solutions have already strengthened our signaling capabilities, driving greater operational efficiency

BroadForward’s solutions have already strengthened our signaling capabilities, driving greater operational efficiency

One of the few independent signaling experts successful in winning business from operators looking for a multi-technology signaling platform

Specifications

Everything you need to evaluate, in one place

Supported Standards & Features

  • 3GPP Rel-16/Rel-17 N32 Interface Support Fully compliant with 3GPP TS 29.573 and TS 33.501, supporting N32-c control plane capability negotiation and N32-f secure payload transfer.
  • HTTP/2 JOSE Encryption & Signing (PRONT) Enforces Application-Layer Security using JSON Object Signing and Encryption (JOSE) for message integrity, confidentiality, and PRONT (Protocol HTTP Header Hiding) over N32-f.
  • IPX & Hosted SEPP Multi-Tenancy Supports multi-tenant operational models enabling IPX providers and MNO groups to host SEPP services for multiple virtual operators from a single software instance.
  • 3GPP Security & OAuth2 Inter-PLMN Protection Enforces TLS 1.3 encryption across inter-operator borders, validates access tokens, and prevents cross-border identity spoofing and unauthorized SBI requests.
  • Topology Hiding & Privacy Protection Strips internal network topology details, FQDNs, IP addresses, and sensitive HTTP/2 SBI headers before traffic leaves the PLMN border.
  • 3GPP 4G–5G Roaming Interworking (IWF) Standardized interworking capabilities connecting 5G N32 roaming traffic directly to legacy 4G Diameter (DEA/S6a/S9) and SS7 IPX infrastructure.

SEPP Features

  • Converged Multi-Protocol Single Engine Built on the BFX platform, allowing operators to run SEPP alongside 5G SCP, BSF, DSC, and STP on a common engine, significantly lowering TCO.
  • Script-Free GUI Signaling Orchestration Provides a 100% graphical environment to build custom inter-PLMN routing rules, N32 security policies, and mediation workflows without writing code.
  • Native Multi-Generational Protocol Interworking Optional out-of-the-box translation between HTTP/2 (N32), Diameter (S6a/S9), and SS7 (MAP), allowing unified border control across 2G, 3G, 4G, and 5G roaming.
  • Single-Capacity Cross-Protocol Licensing Uses a unified capacity license where traffic volume can freely shift between border protocols (N32, Diameter, SS7) as international 5G SA roaming traffic grows.
  • Ultra-Lightweight & Cloud-Agnostic Footprint Extremely low resource consumption designed for flexible deployment across bare metal, virtualized platforms, Kubernetes containers, or hybrid cloud environments.

Get more product information

Request the latest data sheet for the BroadForward SEPP and share it with your team for a complete technical overview.

  • Full technical specifications and feature list
  • Inter-PLMN deployment architecture and IPX integration overview

FAQ

We are happy to help you with any questions.

Deployment

Freedom of Environment: Deploying Where it Makes Sense

You are never tied to a specific hardware vendor, appliance cycle, or hyperscaler. Wherever the BroadForward SEPP was deployed first, the software can be redeployed using the same configuration on VMs, Containers or bare metal. Because the BroadForward SEPP separates the underlying execution platform from its routing logic, N32 security configurations, and firewall profiles, moving environments requires no re-engineering. All border security rules, N32 control profiles, topology-hiding parameters, and 3GPP Rel-16/Rel-17 interworking configurations built in the GUI can be exported as clean, platform-independent configuration profiles or declarative Kubernetes Helm charts.

Bare metal

Maximum performance on existing server hardware. No hypervisor overhead.
Bare metal

Virtual machine

Deploy on your current hypervisor. Full HA and geo-redundancy supported.
Virtual machine

Container

Kubernetes-orchestrated. Automated lifecycle management. Scales horizontally.
Container

Cloud

Public, private, or hybrid. Scales without re-architecture as your network grows.
Cloud
Search

Change language