Glossary term · Core Network

N3IWF

Non-3GPP access InterWorking Function

Core Network →

N3IWF is a core network function that enables secure integration of non-3GPP access networks into the 5G Core by acting as a gateway that terminates IPsec tunnels and relays traffic.

Introduced
Rel-15
Specifications
16 specs
Category
Core Network
Introduced
Rel-15
Specifications
16 specs
N3IWF Description Purpose Related Classification Detected Changes Specifications

Description

The Non-3GPP InterWorking Function (N3IWF) is a critical network function within the 5G Core (5GC) architecture, specifically defined to integrate untrusted non-3GPP access networks. Untrusted non-3GPP access refers primarily to access technologies not specified by 3GPP, such as Wi-Fi, which are considered untrusted from a 5G Core security perspective. The N3IWF serves as the secure point of entry for User Equipment (UE) connecting via such access, establishing itself as a termination point within the operator's trusted domain.

Architecturally, the N3IWF interfaces with the UE over the NWu reference point, which utilizes IKEv2 and IPsec protocols to establish secure tunnels. This ensures confidentiality and integrity for user plane traffic and signaling between the UE and the 5GC. On the network side, the N3IWF connects to other 5GC Network Functions via standard interfaces: it connects to the Access and Mobility Management Function (AMF) over the N2 interface for control plane signaling (e.g., registration, authentication) and to the User Plane Function (UPF) over the N3 interface for user data transfer. This allows the UE to be treated as if it were connected via 3GPP radio access, enabling consistent service continuity and policy enforcement.

The N3IWF's operation involves several key procedures. During initial attachment, the UE discovers an N3IWF and performs IKEv2 authentication and IPsec Security Association (SA) establishment, often leveraging 5G authentication credentials (e.g., from a USIM). The N3IWF then relays the UE's NAS messages (encapsulated within the IPsec tunnel) to the AMF over N2. For user plane, the N3IWF decapsulates incoming IPsec packets from the UE and forwards the inner IP packets to the UPF over a GTP-U tunnel on N3, and vice versa. It also plays a role in supporting mobility events, such as handovers between 3GPP and non-3GPP access.

Key components within the N3IWF's logical design include the termination points for IKEv2 and IPsec, the relay function for N1/N2 NAS signaling, and the GTP-U endpoint for the N3 interface. Its role is fundamental in realizing the 5G vision of access-agnostic service delivery, allowing operators to leverage existing Wi-Fi infrastructure to offload traffic, enhance coverage, and provide a seamless user experience without compromising 5G security and service standards.

Purpose & Motivation

The N3IWF was introduced in 3GPP Release 15 as part of the new 5G System (5GS) architecture to solve the critical problem of integrating non-3GPP access networks into the 5G core in a secure and standardized manner. Prior to 5G, integration of Wi-Fi with cellular networks was handled through separate, often proprietary gateways (like ePDG in EPS for untrusted Wi-Fi) that were not fully aligned with the cloud-native, service-based principles of 5GC. The motivation was to create a unified core that could deliver consistent services, security, and policies regardless of the underlying access technology (3GPP or non-3GPP).

Historically, non-3GPP access (especially untrusted Wi-Fi) presented security risks and management complexities. The N3IWF addresses these by providing a standardized, secure interworking function that applies the same robust 5G authentication and security mechanisms (like 5G-AKA or EAP-AKA') to non-3GPP connections. It solves the problem of access fragmentation, enabling seamless session continuity and service-based architecture exposure for devices connecting via Wi-Fi. This was driven by the industry need to leverage dense Wi-Fi deployments for capacity augmentation, indoor coverage, and fixed wireless access scenarios within the 5G service framework.

Furthermore, the creation of the N3IWF was motivated by the limitation of previous interworking solutions which were often bolt-ons to the core network. In 5G, the N3IWF is a first-class citizen within the SBA, interacting with the AMF and UPF via service-based interfaces. This allows for more flexible deployment, better scalability, and integrated policy control, fulfilling the 5G requirement for convergence of fixed and mobile networks.

Classification

Part ofAMF
Related approachesUPFATSSSIPSec

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (50 CRs across 6 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 4 changes
  • Corrections to Combined N3IWF/ePDG Selection TS 23.501CR0057
  • UE unable to use N3IWF identifier configuration in stand-alone N3IWF selection TS 23.501CR0630
  • Using TCP for reliable NAS transport between UE and N3IWF TS 23.501CR0692
  • Correction of N3IWF key TS 29.413CR0004
Rel-16 9 changes
  • FQDN format of N3IWF in a standalone non-public network TS 23.501CR0841
  • N3IWF FQDN configured in a UE to support access to PLMN/SNPN services via SNPN/PLMN TS 24.502CR0079
  • Clarifying N3IWF access to SNPN TS 23.501CR1751
  • N3IWF selection procedure when accessing SNPN via PLMN TS 23.501CR2521
  • FQDN for N3IWF selection to access PLMN services via an SNPN TS 24.502CR0102
  • Extending congestion notification to capture N3IWF or TNGF overload TS 24.502CR0130

+ 3 more changes

Rel-17 8 changes
  • Informative guideline on supporting session/service continuity between SNPN and PLMN when using N3IWF TS 23.501CR2563
  • Update to N3IWF selection for N3SLICE TS 23.501CR2662
  • N3IWF selection for emergency services TS 24.502CR0194
  • FQDNs for N3IWF selection for emergency services TS 23.501CR2848
  • Correction to the N3IWF selection procedure TS 23.501CR2723
  • Layer below IPsec to enable NAT traversal for TNGF/N3IWF access TS 23.501CR3442

+ 2 more changes

Rel-18 27 changes
  • N3IWF selection enhancement for support of S-NSSAI needed by UE TS 23.501CR3707
  • Resolving the EN related to N3IWF selection based on N3IWF identifier information in the REGISTRATION REJECT message TS 24.502CR0230
  • Prefixed OI/TAI Identifier FQDN for N3IWF selection TS 24.502CR0223
  • Update of SNPN N3IWF selection TS 24.502CR0221
  • N3IWF selection enhancement for support of S-NSSAI needed by UE TS 24.502CR0210
  • N3IWF selection for non-IMS services supporting extended home N3IWF identifier configuration and slice-specific N3IWF prefix configuration TS 24.502CR0248

+ 21 more changes

Rel-19 1 change
  • Correction on N3IWF selection TS 23.501CR5536
Rel-20 1 change
  • N3IWF/TNGF reselection considering energy related information. TS 23.501CR6493

Explore further

Broader topics and technologies where N3IWF plays a role.

Defining Specifications

3GPP specifications that define or reference N3IWF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk20 5G System Architecture Stage 2 Rel-20
TS 24.501 vk00 5G System (5GS) Non-Access Stratum (NAS) Protocol Rel-20
TS 24.502 vk00 Non-3GPP Access Network Discovery and Selection Rel-20
TS 24.526 vj40 UE Policies for 5G System (5GS) Rel-19
TS 24.890 vg00 5G NAS Protocol for 5GS Stage 3 Rel-16
TR 28.828 vi00 Charging Aspects for Non-Public Networks Rel-18
TS 29.214 vj30 Rx Reference Point Stage 3 Specification Rel-19
TS 29.413 vj00 NGAP for Non-3GPP Access Rel-19
TS 29.518 vk00 3GPP TS 29518 vk00: Namf Service Based Interface Rel-20
TS 29.525 vk00 UE Policy Control Service Stage 3 Rel-20
TS 29.561 vk00 5G Network Interworking Procedures Rel-20
TS 32.255 vk20 5G Data Connectivity Charging Rel-20
TS 32.256 vk00 5G Connection and Mobility Charging Rel-20
TS 33.127 vj70 Lawful Interception Architecture and Functions Rel-19
TS 33.501 vk20 5G Security Architecture and Procedures Rel-20
TS 38.413 vj30 NG Application Protocol (NGAP) for 5G NG Interface Rel-19