Product family 3 of 6 · SMS Firewall / SS7 SMS firewall / SMPP ESME firewall
Guardivia SMS Signaling and ESME Gateway Firewall
One carrier-grade platform for SS7/SIGTRAN SMS signaling inspection, SMPP/ESME gateway inspection, fraud prevention and A2P monetization.
Shared inspection path
Architecture viewInputs
SS7 / MAPSMPP / ESMEGuardivia processing
Outputs
AllowQuarantine / CDROn this pageOverview
Product overview
Guardivia SMS Signaling and ESME Gateway Firewall is a carrier-grade SMS security, traffic-control, fraud-prevention and A2P monetization platform. It inspects SS7/SIGTRAN SMS signaling (MO, MT and AT) and SMPP/ESME application traffic through one coordinated policy and inspection environment, correlating signaling metadata and message content before delivery. It is built for MNOs, MVNOs, MVNEs, interconnect and signaling hubs, SMS aggregators and private mobile networks.
How does an SMS Firewall identify grey routes?
Guardivia SMS Signaling and ESME Gateway Firewall identifies grey routes by correlating the message's route with its behaviour: commercial content or sender patterns arriving over P2P interconnects, abnormal Global Titles, MSISDN ranges submitting A2P-like volumes, mismatches between SRI-SM results and the delivery path, and velocity outside subscriber norms. Confirmed grey traffic is blocked, tagged or redirected to an authorised, billable route.
What are Hawk, Dolphin and Shark in the Guardivia SMS Firewall?
Hawk, Dolphin and Shark are the three functional engines of the Guardivia SMS Signaling and ESME Gateway Firewall. Hawk processes and screens SS7/SIGTRAN SMS signaling. Dolphin and Shark are redundant SMPP, ESME, content, spam, policy and AI-inspection engines. All SS7 MO, MT and AT SMS traffic, and all external and local SMPP ESME traffic, pass through the same inspection layer before delivery.
Last reviewed 2026-09-12 by the Guardivia QoS Engineering Team. Product facts on this page describe current capabilities; items marked “where supported”, “optional”, “integration” or “consultancy” are confirmed per deployment.
Target customers
- Mobile network operators protecting subscribers and A2P termination revenue
- MVNOs and MVNEs with their own SMSC or ESME gateway
- Interconnect and signaling hubs screening partner SMS traffic
- SMS aggregators enforcing policy on customer binds
- Private mobile networks with external messaging connectivity
Problems solved
- A2P traffic injected over P2P interconnects, SIM boxes and unauthorised Global Titles bypasses billing.
- Spam, smishing and sender-ID spoofing erode subscriber trust in SMS and trigger regulatory pressure.
- Signaling-side and application-side inspection are usually separate products with inconsistent policies.
- OTP flooding and repeated OTP abuse consume capacity and mask fraud.
- Operators lack evidence-grade reporting to enforce commercial agreements with aggregators.
Business outcomes
- One policy environment across SS7 signaling and SMPP/ESME traffic.
- Reduced spam, smishing and spoofing reaching subscribers.
- Grey-route and SIM-box traffic detected and redirected to authorised routes.
- A2P revenue protected through sender, aggregator and agreement registries with reconciliation reporting.
- AI-assisted classification with every enforcement decision confirmed by an authorised engineer.
Key capabilities
Hawk: SS7/SIGTRAN SMS signaling
Screens MO-ForwardSM, MT-ForwardSM, SRI-SM and related SMS operations, validates Global Titles and routing paths, and hands message content to the inspection layer.
Dolphin and Shark: inspection engines
Redundant SMPP, ESME, content, spam, policy and AI-inspection engines that process both internal SS7-derived traffic and external ESME binds.
Multi-dimensional inspection
Content, sender ID, addresses, prefix, country, operator, GT, routing path, account, velocity, DLRs, HLR/SRI-SM results, MNP data and AI risk score correlated per message.
Fraud and security controls
Spam, smishing, malicious URLs, sender-ID spoofing and variation, GT spoofing, grey routes, SIM boxes, direct injection, home-routing bypass, flooding and OTP abuse.
A2P monetization
A2P/P2P separation, sender-ID, aggregator and commercial-agreement registries, authorised-route enforcement, CDRs, revenue dashboards and reconciliation.
Governed AI
Learning mode, baselines, proposed rules and thresholds, an AI operational coworker with scheduled recommendations, and human confirmation before enforcement.
Detailed feature groups
Every supported capability is listed under its correct product. Nothing is omitted for brevity.
Inspection dimensions
Every message is evaluated across correlated dimensions:
- Message content and multilingual text patterns
- Sender ID, source address and destination address
- Prefix, country and operator
- Global Title and routing path
- Client account and ESME system ID
- Message category
- URL and domain
- Submission velocity and traffic volume
- Geographic pattern and historical behaviour
- Delivery receipts
- HLR and SRI-SM results and MNP information
- AI risk score and rule or profile matches
Traffic classification
- A2P, P2P, P2A and M2P
- OTP, transactional, service, promotional, advertising, political and personal
- Spam, smishing and fraudulent
- Legitimate, suspicious and prohibited
Security and fraud controls
- Spam detection; smishing and phishing detection; malicious URL scanning
- Sender-ID spoofing detection and sender-ID variation and manipulation detection
- GT spoofing and abnormal GT behaviour
- Grey-route detection; SIM-box and SIM-farm detection
- Unauthorised direct injection and SMS Home Routing bypass detection
- Routing manipulation detection
- Flooding protection; OTP flooding and repeated OTP detection
- MSISDN behavioural profiling and traffic velocity controls
- Country and operator policies; client-specific profiles; prefix filtering
- Content and regular-expression rules; multilingual content filtering
- Whitelists and blacklists; registered sender validation; aggregator validation
- Rate limiting
- Actions: quarantine, drop, allow, block, tag, redirect, reroute, force sender ID, policy-based delivery
A2P monetization and revenue assurance
- A2P and P2P separation and commercial sender detection
- Grey-route elimination and authorised-route enforcement
- Sender-ID registry, aggregator registry and commercial-agreement registry
- Approved volume and route controls
- Local versus international traffic separation
- CDR generation and BSS/billing integration
- Revenue dashboards, revenue-leakage estimation and recovered-revenue reporting
- Traffic and invoice reconciliation
- Reporting by sender, client, aggregator, route, country, operator and period
Management, monitoring and reporting
- Role-based web console
- Real-time TPS; submitted, processed, delivered, pending, failed and blocked traffic
- A2P and P2P split; firewall-block and AI-block analysis
- Threat categories, sender profiles, route profiles and threat-origin visualisation
- Revenue-assurance dashboard
- Node and service health; DLR performance; rule effectiveness
- Custom report builder; scheduled, executive, NOC technical, compliance and aggregator-performance reports
- CSV, Excel and PDF export where supported
- SNMP, webhooks and SIEM integration; email and SMS alerts
- Escalation and acknowledgement workflows
- Audit logs, configuration-change logs, CDR and forensic evidence
Supported protocols and interfaces
| Protocol / interface | Role | Status |
|---|---|---|
| SS7/MAP over SIGTRAN (SCTP, M3UA, SCCP, TCAP) | Hawk: MO, MT and AT SMS signaling inspection | Verified capability |
| SMPP v3.4 / v5.0 | Dolphin and Shark: ESME binds and internal inspection | Verified capability |
| SMPPS/TLS | Encrypted ESME binds, depending on operator requirements | Verified capability |
| HLR / SRI-SM and MNP | Subscriber and portability verification | Verified capability |
| VRRP | Service address availability across Dolphin and Shark | Verified capability |
| PCC-based session distribution | 50/50 distribution of new connections where applicable | Where supported |
| SNMP, syslog, webhooks, SIEM | Alarms and security-event export | Verified capability |
| REST | Rule management, provisioning and reporting | Verified capability |
Swipe horizontally to view all columns.
Architecture
The firewall preserves a three-engine functional architecture. Hawk terminates SS7/SIGTRAN toward the STP and performs SMS signaling processing and screening: GT validation, routing-path checks, SRI-SM correlation and MO/MT/AT operation handling. Hawk forwards message content over an internal SMPP path to the inspection layer.
Dolphin and Shark are redundant inspection engines. Both run the SMPP server, ESME account handling, content and spam analysis, policy engine and AI classification. External and local SMPP ESMEs bind directly to the same engines, so signaling-derived traffic and application traffic are governed by one set of policies. A VRRP-protected service address keeps binds available; where applicable, PCC-based distribution splits new sessions 50/50 across Dolphin and Shark, and health monitoring redirects new connections when an engine is unavailable.
Decisions (allow, block, tag, rate-limit, quarantine, redirect, reroute, force sender ID) are returned to Hawk or applied on the SMPP path before the message reaches the SMSC.
Text description of this diagram
SMS Firewall architecture. Left: partner MNOs and roaming SMS over SS7/MAP arrive via the operator STP into Hawk (SS7/SIGTRAN SMS signaling processing). Hawk passes MO, MT and AT SMS over internal SMPP to Dolphin and Shark, two redundant inspection engines sharing a VRRP service address with PCC-based session distribution. External ESMEs and local SMPP clients bind directly to Dolphin and Shark over SMPP or SMPPS/TLS. Inspection covers content, sender, route, velocity, HLR/MNP and AI scoring. Allowed traffic continues to the operator SMSC and subscribers; blocked traffic is quarantined or dropped; all decisions feed the console, CDRs and reporting.
Message inspection workflow
- 01
Ingress: an SMS arrives at Hawk over SS7/SIGTRAN (MO, MT or AT) or at Dolphin/Shark over an SMPP or SMPPS/TLS bind.
- 02
Signaling validation (Hawk): protocol sanity, Global Title and routing-path checks, SRI-SM and MNP correlation, home-routing bypass indicators.
- 03
Handover: Hawk forwards the message over the internal SMPP path to the active inspection engine; ESME traffic is already inside the engine.
- 04
Classification: content, sender, account, velocity and historical behaviour are evaluated against rules, profiles, registries and the AI risk model.
- 05
Policy decision: allow, tag, rate-limit, quarantine, block, drop, redirect, reroute or force sender ID, according to operator policy.
- 06
Enforcement and delivery: allowed traffic proceeds to the operator SMSC; redirected A2P proceeds over the authorised, billable route.
- 07
Evidence: decision, reason code, dimensions and CDR are written for the console, reports, SIEM and forensic review.
Integrations
Integration types are stated explicitly. Custom integrations are delivered by Guardivia’s in-house QoS Engineering Team, not by an external vendor. See the full integration catalogue.
| System | Detail | Type |
|---|---|---|
| STP and SS7 network | SIGTRAN associations for Hawk | Native integration |
| Operator SMSC | Guardivia Operator SMSC or third-party SMSC over SMPP or MAP | Native integration |
| External ESMEs and aggregators | SMPP v3.4/v5.0 and SMPPS/TLS binds | Native integration |
| HLR / HSS and MNP | SRI-SM correlation and portability data | Standards-based |
| BSS and billing | CDR export and commercial-agreement reconciliation | Standards-based |
| SIEM, NOC, SNMP, webhooks | Security events, alarms and acknowledgements | Standards-based |
| Sender-ID registries | National or operator registries where an API is documented | Custom (in-house engineering) |
| Guardivia Honeypot SMS Testing | Confirmed indicators imported as firewall intelligence after human review | Native integration |
Swipe horizontally to view all columns.
Security controls
- SMPPS/TLS binds and per-account source-IP restrictions
- Role-based console access with audit and configuration-change logs
- Quarantine storage with controlled analyst access
- Separation of monitoring mode and enforcement mode
- No lawful-interception functions; the platform is a security and policy engine
Management functions
- Role-based web console for policies, rules, registries and profiles
- REST API for rule management and provisioning
- Client, sender and aggregator profile administration
- Rule versioning with change history
- Escalation and acknowledgement workflows
Monitoring and reporting
- Real-time TPS and traffic-state dashboards
- Threat-category, sender and route profiles; threat-origin visualisation
- Revenue-assurance dashboard with leakage and recovery estimates
- Node, engine and DLR health
- Rule effectiveness and AI-block analysis
- Scheduled and custom reports with CSV, Excel and PDF export where supported
High availability
- Redundant Dolphin and Shark inspection engines
- VRRP for service-address availability
- PCC-based 50/50 session distribution where applicable
- Health monitoring with automatic redirection of new connections
- Redundant SIGTRAN associations on Hawk
Scalability
- Additional inspection engines behind the same service address
- Independent scaling of signaling processing and content inspection
- Sizing established during traffic baselining rather than published as generic figures
Deployment options
- Inline with the STP and SMSC, or in front of an ESME gateway
- Monitoring-only, hybrid or enforcement modes
- Linux on bare metal or virtual machines; on-premise, hosted or managed
- Standalone or integrated with the Guardivia Operator SMSC and Core Network Suite
Use cases
Grey-route elimination and A2P recovery
Commercial traffic hiding in P2P interconnects is classified, blocked or redirected, and aggregators are onboarded through the agreement registry.
Sender-ID protection for banks
Registered sender IDs are enforced; variations and spoofing attempts are blocked and evidenced for the bank and regulator.
Hub screening
A signaling hub applies partner-specific policies to SMS transiting its STP and reports per-partner outcomes.
ESME policy enforcement
An aggregator applies OTP-abuse, promotional and political-content controls per customer bind.
In-House Engineering Advantage
Owned end to end by the Guardivia QoS Engineering Team
Signaling inspection, SMPP processing, rule engines, traffic analytics, AI assistance and integrations are all internally developed by the QoS Engineering Team.
- New fraud patterns become detection logic through the same team that operates the platform in monitoring mode.
- Registry and BSS integrations follow the operator's formats rather than a vendor template.
- Rule-engine and classifier updates are released under Guardivia's own regression testing.
- Signaling edge cases from a specific STP or SMSC are fixed at source.
Scope and limitations
Stated plainly so that buyers, engineers and AI assistants describe this product accurately.
- SS7 firewall scope is SMS signaling. General SS7 protection (location tracking, non-SMS MAP categories) is outside this product unless separately agreed.
- The platform does not provide lawful interception.
- AI proposes classifications, rules and thresholds; an authorised engineer confirms enforcement. Uncontrolled autonomous blocking is not a feature.
- Blocking rates, latency, throughput and revenue figures are established per deployment and are not published as generic claims.
Frequently asked questions
Does the firewall cover both SS7 and SMPP traffic?
Yes. Hawk inspects SS7/SIGTRAN SMS signaling and passes content to the inspection layer; Dolphin and Shark inspect SMPP/ESME traffic directly. Both domains share one policy environment.
Can it work with our existing SMSC?
Yes. The firewall sits in front of any SMSC over MAP or SMPP. It is also pre-integrated with the Guardivia Operator SMSC.
How is AI governed?
The platform starts in monitoring and learning mode, builds baselines, then proposes classifications, rules and thresholds. An AI operational coworker issues daily recommendations early on, typically moving to weekly as traffic stabilises. An authorised engineer reviews and confirms every enforcement change.
What happens to blocked messages?
According to policy they are dropped or quarantined with full reason codes, dimensions and CDRs for analyst review, reporting and forensic evidence.
Does it protect against general SS7 attacks such as location tracking?
This product's SS7 scope is SMS signaling. Broader SS7 category screening is addressed through the Core Network Suite STP platform or a separately scoped engagement.
How does the firewall support A2P monetization?
It separates A2P from P2P, enforces sender-ID, aggregator and commercial-agreement registries, redirects unauthorised A2P to billable routes, generates CDRs and reconciles traffic against invoices.
Request a demo of Guardivia SMS Signaling and ESME Gateway Firewall
Demos are run by the engineers who develop the product, using your protocols and integration points.