ePDG

July 24, 2026
ePDG (Evolved Packet Data Gateway) is a network gateway in the 4G/LTE mobile network architecture. It provides secure connectivity for subscribers to the operator's core network through untrusted (non-3GPP) access networks, such as public Wi-Fi.
The main purpose of ePDG is to protect user traffic and provide access to operator services outside the cellular network.

ePDG operation diagram

Figure 1 — VoWiFi connection architecture via ePDG

The role of ePDG in VoWiFi

ePDG is widely used to enable VoWiFi (Voice over Wi-Fi) — a technology that allows calls and SMS to be sent over Wi-Fi while maintaining a connection to the mobile operator’s network.

This is especially important in places with weak mobile signal: inside buildings, in basements, shopping centers, and offices. In such cases, a smartphone can automatically switch to Wi-Fi and continue using the operator’s voice services.

The connection process looks like this:

  • The device connects to an available Wi-Fi network.
  • It establishes a secure tunnel to the ePDG.
  • It authenticates on the operator’s network.
  • Voice and user traffic is transmitted through the EPC core, just as it would be over an LTE connection.

As a result, the subscriber gets access to the operator’s services regardless of whether the cellular network or Wi-Fi is being used.

For more on building operator networks and mobile infrastructure solutions — see the VAS Experts ePDG page.

How does ePDG differ from a regular Wi-Fi connection?

Regular Wi-Fi provides internet access only. ePDG adds protection, subscriber authentication, and integration with the mobile operator’s infrastructure.

Regular Wi-Fi ePDG
Internet access only Secure access to the operator’s core network
Protection depends on Wi-Fi network settings A secure IPsec tunnel is used
No integration with the mobile network VoWiFi, IMS, and mobile services are supported
Traffic goes directly over the internet Traffic passes through a secure tunnel to the operator

For users, the difference shows up in the ability to make calls or receive SMS even without an LTE signal, as long as Wi-Fi access is available — for example, at the office or on a home network.

Protocols, architecture, and security

ePDG uses proven protocols for secure traffic exchange — IPsec for tunneling and IKEv2 for key negotiation.

Subscriber authentication is performed using EAP-AKA or EAP-AKA’. This ensures SIM-based identification, just as in the mobile network. Traffic between the device and the ePDG is fully encrypted, protecting data even when using public Wi-Fi.

This approach ensures:

  • data protection when using public Wi-Fi networks;
  • subscriber authentication;
  • confidentiality of voice and user traffic;
  • secure access to operator services regardless of the connection point.

ePDG scales horizontally and supports millions of simultaneous connections. The gateway is most often integrated with the EPC core, the IMS subsystem, and roaming nodes, with policy management implemented through PCRF (Policy and Charging Rules Function).

Where ePDG is used

ePDG is used in mobile operator networks for several purposes:

  • providing VoWiFi services;
  • secure transmission of mobile traffic over Wi-Fi;
  • extending network coverage inside buildings;
  • reducing load on the LTE radio network;
  • supporting roaming through trusted and untrusted access networks.

Modern ePDG solutions scale horizontally, support millions of simultaneous connections, and integrate with IMS and EPC platforms as well as network policy management systems.

Technical FAQ

What is ePDG in simple terms?

ePDG is a secure gateway between a subscriber’s device connected via Wi-Fi and the operator’s mobile network. It allows voice services and mobile internet to be used securely over any Wi-Fi network.

What is ePDG for?

The main purpose of ePDG is to provide secure access to operator services through untrusted access networks, primarily Wi-Fi. Without it, VoWiFi cannot be properly implemented in LTE architecture.

What protocols does ePDG use?

IPsec and IKEv2 are used to secure the connection. Subscriber authentication is typically performed using the EAP-AKA or EAP-AKA’ methods, which rely on SIM card data.

How does ePDG differ from PGW?

PGW (Packet Data Network Gateway) connects the mobile network core to external IP networks and the internet. ePDG provides secure subscriber access to that core via Wi-Fi and other non-3GPP networks. In other words, PGW handles the outbound connection to data networks, while ePDG handles secure inbound access to the operator’s network via alternative access.