What TWAG is and why it is needed
To offload the cellular network, operators increasingly use Wi-Fi. However, the ways subscribers connect via Wi-Fi differ depending on whether the network is considered trusted.
If the operator fully controls the Wi-Fi infrastructure (for example, a corporate network, operator access points, or home routers with support for operator functions), Trusted Wireless Access is used. In this case, TWAG becomes the entry point into the mobile core.
TWAG is especially in demand when implementing Wi-Fi Offload, when part of the mobile traffic is shifted from LTE or 5G to Wi-Fi without degrading quality of service.
How TWAG works
In the 3GPP TS 23.402 architecture, TWAG is located between the trusted Wi-Fi network and the mobile operator’s core.
When a user connects, several stages take place:
- the device connects to a trusted Wi-Fi access point;
- TWAG interacts with the AAA server and performs subscriber authentication;
- after successful verification, a connection to the packet core is established;
- the user gains access to mobile services while retaining familiar access and routing policies.
User traffic is transmitted using the GTP (GPRS Tunnelling Protocol) or PMIPv6 (Proxy Mobile IPv6) protocols, depending on the network architecture.
Thanks to this, the operator can maintain uniform QoS, billing, and subscriber management policies regardless of whether the user is connected via LTE, 5G, or a trusted Wi-Fi network.
TWAG vs. ePDG: what’s the difference
TWAG and ePDG (Evolved Packet Data Gateway) solve a similar task — connecting users via Wi-Fi to the mobile network — but are used in different scenarios.
| TWAG | ePDG |
| Used in trusted Wi-Fi networks | Used in untrusted Wi-Fi networks |
| Does not require IPsec tunnels | Uses IPsec/IKEv2 to protect traffic |
| Typically used within the operator’s network | Allows connection through any public Wi-Fi |
| Lower traffic processing overhead | Higher level of protection when working over open networks |
You can learn more about secure access architecture in the materials on ePDG.
Where TWAG is used
The Trusted Wireless Access Gateway is used in the infrastructure of mobile operators and large corporate networks.
Typical scenarios:
- offloading the mobile network via Wi-Fi Offload;
- supporting VoWiFi (Wi-Fi Calling) services;
- integrating corporate Wi-Fi networks with the mobile core;
- connecting MVNOs to trusted wireless networks;
- building converged fixed-mobile networks (FMC).
Using TWAG makes it possible to maintain uniform security policies, quality of service (QoS), and subscriber management regardless of the access technology.
To build Wi-Fi Calling services, integrate with the EPC core, and deploy access gateways, operators can use VAS Experts’ ePDG and mobile network solutions, which support modern subscriber connection scenarios and the development of VoWiFi services.
Technical FAQ
What is TWAG in simple terms?
TWAG is a gateway that connects users of a trusted Wi-Fi network to the operator’s mobile network. It handles traffic transfer between Wi-Fi and the network core without using IPsec tunnels.
How does TWAG differ from ePDG?
The main difference lies in the type of access network. TWAG only works with trusted Wi-Fi networks managed by the operator. ePDG is designed to connect through any untrusted Wi-Fi network and protects traffic using IPsec and IKEv2.
Where is Trusted Wireless Access Gateway used?
TWAG is used in LTE and 5G networks to organize Wi-Fi Offload, support VoWiFi, connect corporate wireless networks, and build converged mobile infrastructure.
Does TWAG use IPsec?
No. Unlike ePDG, TWAG does not require IPsec tunnels, since it only works with trusted networks whose security is already ensured by the operator