Mobile broadband service can give high speed internet access to mobile broadband subscriber up to 2.7 Mbps and this speed can give more pleasure to do many things including access to unauthorized network on mobile broadband providers. To restrict accessing to the network element, mobile broadband providers apply some authorization policy to the mobile broadband subscribers. There are many policy can be applied either on end user, core network and border. To goal is how to protect the network from unauthorized users and give precisely network access to mobile broadband customers.
Authorization policy on mobile broadband service could be applied at several network elements below.
1. Mobile phone or modem (end user of mobile broadband service)
To limit the authorization access, mobile broadband subscriber will use certainty account while trying to access the service. The account is username and password that will be sent through mobile phone or modem. Usually mobile broadband provider will assign different account to access particular service. Authorization will be rejected if mobile broadband subscriber sends invalid parameters above. Authorization on the end user could be assigned on the AAA server
2. Router network
Authorization access of mobile broadband subscribers on the router network could be applied by assigning Access List (ACL). Which network address will be permitted to be accessed by mobile broadband subscribers is defined in this Access List (ACL). Authorization policy on the router is layer 3 application. It means, address of the destinations which will be granted or blocked are defined here
3. Public Data Serving Node (PDSN) or Gateway GPRS Support Node (GGSN)
Authorization access of mobile broadband subscribers on the PDSN or GGSN is just like on the router network. Which network will be granted or blocked are defined here. It depends on the PDSN or GGSN manufactures, some of them can be configured similar with the router and some of them are more complicated
4. Firewall
Authorization on the firewall means the destination address in the outside (internet) which authorized to be accessed by mobile broadband subscribers. The parameters that to be configured to allowing or blocking mobile broadband subscriber could be IP address, port and application type