Skip to content

RAN Signaling

The telecom sensor monitors NGAP, F1AP, E1AP, XnAP, S1AP, E2AP, NRPPa, NAS 5G, NAS EPS, and SCTP signaling at the process level. The Console presents decoded procedure evidence, outcomes, coverage state, and related runtime identity for each observed interface.

Requires: Telecom sensor flavor.


NGAP (NG Application Protocol)

Standard: 3GPP TS 38.413
Interface: N2 between gNB and AMF
Transport: SCTP port 38412, PPID 60

NGAP is the primary control-plane protocol between the radio access network and the 5G Core. The sensor monitors NGAP at both the gNB and AMF, decoding APER PDU headers and extracting IEs for procedures relevant to security and operations.

Procedures monitored

ProcedureCodeWhat the sensor captures
InitialUEMessage15UE context, NAS PDU, RAN-UE NGAP ID
DownlinkNASTransport11NAS PDU delivery to UE
UplinkNASTransport46NAS PDU from UE to AMF
InitialContextSetup14Bearer setup success and failure
UEContextRelease41Context teardown event and latency
HandoverPreparation12Inter-AMF handover initiation and failure
NGSetup21N2 interface setup and failure

NGAP KPIs

KPITargetAlert
InitialContextSetupFailure rate per gNB< 0.1%Exceeded
UEContextRelease teardown latencyTrackedSpike
Handover success rate per AMFTrackedDrop below baseline
NGSetup failure count per gNB0Any failure

Open Telco > Network > RAN for Registration and Session Lifecycle and historical NGAP charts. Review NG Setup, Initial UE, Context Setup, and PDU Session evidence for the selected period.

Initial UE counts observed messages, not accepted registrations. Compare procedure attempts, successful outcomes, failures, and duration only where the corresponding evidence was captured. A missing outcome does not establish success or failure.

The AI assistant can also summarize the available historical NGAP evidence.

NGAP evidence

For nodes with an observed NGAP interface, Telovix reports decoded procedure activity and aggregated KPI values for the selected time range.

NGAP anomaly interpretation

High InitialContextSetupFailure rates from a specific gNB may indicate bearer setup failure, UE authentication issues, or a signaling flood. NGSetup failures indicate the gNB cannot register with the AMF; this may reflect network policy changes, IP routing changes, or active security filtering. Unexpected UEContextRelease without a preceding UEContextReleaseRequest from the network side indicates premature teardown.


F1AP (F1 Application Protocol)

Standard: 3GPP TS 38.473
Interface: F1 between gNB-CU-CP and gNB-DU
Transport: SCTP port 38472, PPID 62

F1AP is used in disaggregated gNB deployments where the CU-CP and DU run as separate components.

Procedures monitored

ProcedureWhat the sensor captures
F1SetupRequest / F1SetupResponseDU registration with CU-CP; setup success and failure count
InitialULRRCMessageTransferUE RRC context establishment from DU
DLRRCMessageTransferCU-CP to DU RRC message containing NAS or mobility information

F1AP anomalies

AnomalyMeaning
Repeated F1SetupFailureDU cannot register with CU-CP; radio coverage loss or configuration mismatch
RRC context lost unexpectedlyBearer failure or DU process crash during active UE session

E1AP (E1 Application Protocol)

Standard: 3GPP TS 38.463
Interface: E1 between gNB-CU-CP and gNB-CU-UP
Transport: SCTP port 38462, PPID 64

E1AP manages bearer contexts between the control-plane and user-plane CU components.

Procedures monitored

ProcedureWhat the sensor captures
E1SetupRequest / E1SetupResponseCU-UP registration with CU-CP
BearerContextSetupRequest / ResponseData bearer creation; outcome and latency
BearerContextModificationQoS or routing change on an existing bearer

E1AP metrics

  • Bearer setup latency per CU-UP
  • Bearer setup failure count
  • Bearer modification rate

XnAP (Xn Application Protocol)

Standard: 3GPP TS 38.423
Interface: Xn between neighboring gNBs
Transport: SCTP port 38422, PPID 61

XnAP coordinates inter-gNB handovers and neighbor registration.

Procedures monitored

ProcedureWhat the sensor captures
XnSetupRequest / XnSetupResponseNeighbor gNB registration
HandoverRequest / HandoverResponseInter-gNB handover; success and failure
UEContextReleaseTunnel cutover after handover completion

XnAP anomalies

AnomalyMeaning
Handover success rate dropDegraded radio conditions or inter-gNB signaling fault
Unexpected UEContextRelease from peer gNBPremature teardown; possible protocol violation or peer crash

E2AP (E2 Application Protocol)

Standard: O-RAN Alliance WG3
Interface: E2 between E2 agent (gNB) and Near-RT RIC
Transport: SCTP port 36421 with PPIDs 70, 71, and 72. Port 37464 is also recognized for alternate deployments.

E2AP carries RAN telemetry and control between E2 agents and the Near-RT RIC. xApps connect to the Near-RT RIC via SCTP port 36422 (E42 interface).

Procedures monitored

ProcedureWhat the sensor captures
E2 SetupE2 agent registration with RIC; RANfunctions advertised (CellID, UEID, PRB)
RIC SubscriptionRIC subscription request; subscription ID, action type (report, insert, policy)
RIC IndicationE2 node metric sample sent to RIC triggered by subscription
RIC ControlRIC control action sent to E2 node (e.g., handover trigger)

E2AP metrics

MetricSLA
Cell-level PRB utilizationTracked
Beam state and interferenceTracked
UE-level SINR and CQITracked
RIC response time< 100ms

Review E2AP activity in Telco > Network > O-RAN. The view combines protocol observations with the aggregated O-RAN topology.

E2AP evidence in the O-RAN view showing E2 agent and Near-RT RIC activity.
E2AP evidence in the O-RAN view showing E2 agent and Near-RT RIC activity. Click to enlarge

NAS 5G (Non-Access Stratum)

Standard: 3GPP TS 24.501
Transport: Encapsulated inside RRC, delivered to gNB, relayed to AMF via NGAP

NAS messages carry UE registration, authentication, and session management between the UE and the AMF. The sensor decodes NAS content where it is visible in NGAP payloads.

Message types observed

Message typeContext
RegistrationUE registers with network (Home or Roaming)
Service RequestExisting UE requesting a new service
Authentication ChallengeAMF challenge to UE
PDU Session EstablishmentUE requests a data session

NAS anomalies

AnomalyMeaning
Registration rejection with CAUSE_IMEI_NOT_ACCEPTEDDevice hit a blacklist; may indicate stolen device or policy enforcement
Repeated authentication failuresCredential attack or authentication sync failure
Session setup failuresPolicy or QoS misconfiguration downstream

NRPPa positioning signaling

NRPPa is carried within NGAP between the NG-RAN and location services. When visible, Telovix reports the message class, procedure, transaction identifier, criticality, related NGAP UE identifiers, and decode status. Positioning payload content is not retained.


SCTP (Stream Control Transmission Protocol)

Standard: RFC 9260
Role: Transport layer for NGAP, F1AP, E1AP, XnAP, E2AP, Diameter, and M3UA

All RAN control-plane protocols run over SCTP. The sensor monitors SCTP associations independently of the upper-layer protocol, providing transport-level visibility that complements protocol-level decoding.

What the sensor decodes

  • SCTP common header: source and destination port, verification tag, checksum
  • Chunk types: DATA (0x00), I-DATA (0x40 for interleaved), INIT, INIT-ACK, SACK, ABORT, SHUTDOWN
  • Fragment reassembly using stream ID, sequence number (SSN or MID), and B/E flags

Association tracking

Each SCTP association is tracked as a 4-tuple (src_ip:port to dst_ip:port) with state (ESTABLISHED, SHUTDOWN, CLOSED) and per-stream counters:

  • Message count per stream
  • Loss count per stream
  • RTT samples per association

SCTP metrics

MetricAnomaly trigger
Association churn rateRapid INIT/SHUTDOWN cycling
Chunk loss rateSACK gaps indicating packet loss
RTT samplesLatency increase or spike
Abort reason codesNon-zero count

SCTP anomalies

AnomalyMeaning
Spurious INIT during active sessionAssociation restart; indicates attack or crash loop
Multiple ABORT chunksProtocol violations; may indicate signaling attack
Unexpected stream resetBearer failure or peer-initiated teardown

Review current associations and health evidence in Telco > Network > RAN.


4G S1AP (S1 Application Protocol)

Standard: 3GPP TS 36.413
Interface: S1 between eNB and MME
Transport: SCTP port 36412

S1AP is the 4G equivalent of NGAP. The sensor identifies the eNB/MME interface and decodes the S1AP message class, procedure, criticality, stream, and selected session-relevant information elements. When NAS EPS is carried in a supported S1AP procedure, its message type and security-related metadata are shown as nested evidence.


Console views for RAN signaling

RAN view

In the Console, go to Telco > Network > RAN. The page shows RAN node inventory with detected interfaces, current KPI status, SLO state, and anomaly risk level per node.

Protocol analytics

In the Console, go to Telco > Network > RAN for SCTP association health and NGAP, F1AP, E1AP, XnAP, S1AP, NRPPa, and NAS evidence. Use Telco > Network > O-RAN for E2AP and E2 service-model activity.

NGAP KPIs via AI assistant

Ask the AI assistant: "Show NGAP KPIs for the last 24 hours."

The assistant returns observed procedure success rates, failure counts, and duration distributions for the requested time range.

Filtering runtime events by signaling role

In the Console, go to Monitor > Investigate and select a protocol under Telecom Searches. Choose NGAP, F1AP, E1AP, XnAP, S1AP, NRPPa, NAS/NGAP, NAS EPS, E2AP, or an E2 service model to run a structured historical search. Use Telco > Network or Telco > Sessions for the latest interface or session reports, then narrow by sensor or network function role.


Port reference

All RAN and adjacent signaling ports detected by the telecom sensor:

PortProtocolStandardRole indicated
38412 SCTPNGAP3GPP TS 38.413AMF (listener) or gNB (connector)
38472 SCTPF1AP3GPP TS 38.473gNB-CU-CP or gNB-DU
38462 SCTPE1AP3GPP TS 38.463gNB-CU-CP or gNB-CU-UP
38422 SCTPXnAP3GPP TS 38.423gNB (Xn interface)
36421 SCTP (37464 alternate)E2APO-RAN WG3Near-RT RIC (listener) or E2 Node
36422 SCTPE42O-RAN WG3xApp (connector to Near-RT RIC)
36412 SCTPS1AP3GPP TS 36.413eNB or MME (4G)
3868 / 5658 TCP/SCTPDiameterRFC 6733Diameter Node, CHF, HSS, PCRF
2905 SCTPM3UARFC 4666SIGTRAN Gateway
5060 / 5061 TCP/UDPSIPRFC 3261IMS Node
1812 / 1813 UDPRADIUSRFC 2865/2866RADIUS Server, AUSF, UDM

Operational guidance

SCTP multi-homing: SCTP supports multi-homed associations where a single association spans multiple IP addresses. The sensor tracks the primary address tuple. If a failover occurs to a secondary address, the sensor will observe a new 4-tuple and may treat it as a new association. This is expected behavior and does not indicate an anomaly.

NGAP KPI baseline: InitialContextSetupFailure rates vary by deployment. The 0.1% SLA target is a starting point. On dense urban deployments with high UE density, this rate may legitimately be higher. Review the baseline before enabling alert thresholds.

E2AP timing sensitivity: E2AP carries real-time RAN control actions. The RIC response time SLA is < 100ms. Any enforcement action on a Near-RT RIC process that introduces latency above this threshold could affect scheduling decisions. Use audit mode on Near-RT RIC nodes before enabling enforcement.

SCTP abort monitoring: SCTP ABORT chunks carry reason codes that can distinguish protocol violations from operational shutdowns. Review abort reasons in Telco > Network > RAN. A spike in ABORT chunks with non-standard reason codes on NGAP associations warrants immediate investigation.


Further reading

Released under the Telovix Commercial License.