Followings are about the expected UE response to the attach reject with a specified reject cause. I think just illustration is good enough and would not need any further explanation.
The rule behind each picture is in 24.301 clause 5.5.1.2.5, and it is quoted under every drawing below so the two can be checked against each other. A table of all seven causes comes first, because the differences between them are easier to see side by side than one at a time.
Followings are the topics :
- What each cause does to the UE
- Cause #3 'Illegal UE' - multiple PLMN
- Cause #6 'Illegal ME' - multiple PLMN
- Cause #7 'EPS Service not allowed' - single PLMN
- Cause #14 'EPS Service not allowed in this PLMN' - single PLMN
- Cause #14 'EPS Service not allowed in this PLMN' - multiple PLMN
- Cause #15 'No Suitable Cells in TA' - multiple PLMN
- Cause #25 'Not Authorized for this CSG' - multiple PLMN
- Reference
What each cause does to the UE
The drawings below show what a UE was observed to do. 24.301 clause 5.5.1.2.5 says what it is required to do, and the two agree. Reading the rule first makes each picture quicker to follow, because every one of them is the same three questions: what gets marked bad, how wide the mark reaches, and what clears it.
| #3 | Illegal UE | The USIM is invalid for EPS |
Switching off, removing the UICC, or timer T3245 expiring. |
| #6 | Illegal ME | The same treatment as #3. The specification groups #3, #6 and #8 in one paragraph and gives them one rule. | Switching off, removing the UICC, or timer T3245 expiring. |
| #7 | EPS services not allowed | The USIM is invalid for |
Switching off, removing the UICC, or timer T3245 expiring. |
| #14 | EPS services not allowed in this PLMN | The PLMN identity goes into the |
Switching off, removing the UICC, or timer T3245 expiring. |
| #15 | No Suitable Cells In tracking area | The current TAI goes into the |
Switching off, removing the UICC, or the periodic erase described below. |
| #25 | Not authorized for this CSG | The CSG ID and its PLMN are removed from the Allowed CSG list. The UE enters EMM-DEREGISTERED.LIMITED-SERVICE and looks for another suitable cell. | The CSG list being provisioned again. |
One column explains most of what the pictures show. The width of the mark decides how far the UE runs. A mark on the USIM follows the subscriber everywhere, so #3, #6 and #7 stop the UE dead on every PLMN in range. A mark on a PLMN or on a tracking area is narrower, so #14 and #15 send the UE looking for somewhere the mark does not apply.
The lists are not all cleared the same way either, and this is where a lab session can mislead you. 24.301 clause 5.3.2 says the two forbidden tracking area lists are erased when the UE is switched off, when the UICC is removed, and also
Timer T3245 is the other quiet exit. Clause 5.3.7a says that on expiry the UE erases the forbidden PLMN list and the
Every cause answers the same three questions : what is marked, how wide the mark is, and what clears it.A USIM mark travels with the subscriber : which is why #3, #6 and #7 bar every PLMN at once.A PLMN or TA mark is narrower : so the UE goes looking, which is what #14 and #15 show.Not every bar needs a power cycle : the forbidden TA lists also clear on a 12 to 24 hour period.
Cause #3 'Illegal UE' - multiple PLMN
Cause #3 says the subscriber is not a legitimate one. That is the widest refusal on this page, and the drawing is worth reading for what the UE does not do afterwards rather than for what it does.
Two networks are in range in the drawing below, PLMN 1 and PLMN 2, and the UE tries only the first.

Figure 1. The refusal follows the subscriber, not the network. Two PLMNs are in range and neither is tried again.
The attach carries three things : RRC Connection Setup Complete, an Attach Request and a PDN Connectivity Request, which is the ordinary initial attach.The reject arrives from PLMN 1 : carrying Cause #3, Illegal UE.Neither PLMN is retried : the note says the UE never retries camping on PLMN1 nor PLMN2, checked over 60 seconds.Manual selection does not rescue it : the second note records that manual network selection does not start camping either.A power cycle does : and the last arrow shows the attach going out again after it.
24.301 clause 5.5.1.2.5 explains every one of those observations in a single paragraph, and it covers causes #3, #6 and #8 together. The UE sets the EPS update status to EU3 ROAMING NOT ALLOWED and deletes any GUTI, last visited registered TAI, TAI list and eKSI. It then considers the USIM invalid for EPS services and non-EPS services, deletes the list of equivalent PLMNs, and enters EMM-DEREGISTERED.NO-IMSI.
The phrase that matters is
The specification also names the ways out, and the drawing shows one of the three. The USIM stays invalid until the UE is switched off, or the UICC is removed, or timer T3245 expires. A power cycle is the first of those.
The mark is on the USIM : not on the PLMN that sent the reject.EMM-DEREGISTERED.NO-IMSI is the state : which is why manual selection does nothing.Three exits exist : switch off, UICC removal, or T3245 expiry.Non-EPS service goes too : #3 invalidates the card for both, unlike #7 further down.
Cause #6 'Illegal ME' - multiple PLMN
Cause #6 blames the equipment rather than the subscriber, and the picture below is the same as the one above. That is not an oversight in the drawing, because the specification treats them alike.
The sequence below is identical to the one for cause #3 apart from the cause value in the reject.

Figure 2. Illegal ME produces the same behaviour as Illegal UE. Only the reason differs.
The cause value is the only difference : the reject reads Cause #6, Illegal ME.Both PLMNs are barred again : the same note about PLMN1 and PLMN2 over 60 seconds.Manual selection is still ineffective : for the same reason as in the drawing above.A power cycle still recovers it : and the attach goes out again to PLMN 1.
24.301 clause 5.5.1.2.5 puts #3, #6 and #8 in one paragraph and gives them one rule, which is why the two drawings match. The UE marks the USIM invalid for EPS and non-EPS services, deletes the equivalent PLMN list, and enters EMM-DEREGISTERED.NO-IMSI in all three cases.
What differs is the accusation, and it matters when you are deciding what to change. Illegal UE points at the subscription, so the SIM or the HSS record is where to look. Illegal ME points at the equipment, which in practice means the IMEI has been blacklisted or is not accepted. Swapping the SIM into another handset separates the two in one test: #3 follows the card and #6 stays with the phone.
The counters in the same paragraph reinforce that reading. When the reject was integrity checked, the UE sets its SIM or USIM considered invalid counters to their implementation maximum, so a handset that keeps its own retry budget has just spent all of it.
Same rule, different accusation : the specification groups #3, #6 and #8.#3 points at the subscription : and #6 points at the equipment.A SIM swap tells them apart : the mark either follows the card or stays with the phone.Retry counters are exhausted deliberately : when the message was integrity checked.
Cause #7 'EPS Service not allowed' - single PLMN
Cause #7 is narrower than the two above, and the drawing shows only one network because one is enough. The difference from #3 is not visible in the picture at all, which is why the rule is worth reading beside it.
A single network is drawn below, and the sequence stops as soon as the reject arrives.

Figure 3. EPS service is refused for this subscriber. The card is still good for everything that is not EPS.
One PLMN, one exchange : the attach goes up and the reject comes back with Cause #7.The UE does not retry : the note reads that it never retries camping on the PLMN.Nothing follows in the drawing : there is no power cycle arrow here, and the author's note above supplies it: a power cycle lets the UE camp again.
24.301 clause 5.5.1.2.5 gives #7 almost the same treatment as #3, with one word removed. The UE sets EU3 ROAMING NOT ALLOWED, deletes GUTI, last visited registered TAI, TAI list and eKSI, and considers the USIM invalid
Compare that with the paragraph for #3, which invalidates the card for EPS services and non-EPS services. Cause #7 leaves the non-EPS side alone, so a UE that can fall back to GERAN or UTRAN still has service there. On an LTE only device the two look identical from the outside, and on a device with a 2G or 3G radio they do not.
The state is EMM-DEREGISTERED rather than the NO-IMSI variant that #3 uses, which is consistent with a card that is still valid for something. The exits are the same three: switching off, removing the UICC, or T3245 expiring.
EPS only : the card keeps its non-EPS validity.The difference is invisible on an LTE only device : and obvious on one that can fall back.The state is EMM-DEREGISTERED : not the NO-IMSI form #3 uses.The same three exits apply : switch off, UICC removal, or T3245.
Note : If you power cycle the UE will retry camping on.
Cause #14 'EPS Service not allowed in this PLMN' - single PLMN
Cause #14 names the PLMN in its own text, so the bar it writes is narrow. With only one network in range the UE has nowhere to take that knowledge, which is what makes this drawing and the next one a pair worth reading together.
One network is drawn below. The reject ends the sequence because there is nothing else to try.

Figure 4. The PLMN is barred and no other is in range, so the UE stops. The same cause with a second network looks completely different.
The reject names the PLMN : Cause #14, EPS Service not allowed in this PLMN.The UE does not retry that PLMN : which is the whole of the note in the drawing.The sequence simply ends : no power cycle and no second attempt are drawn, because there is nowhere for the UE to go.
24.301 clause 5.5.1.2.5 is specific about where the bar is written. The UE deletes GUTI, last visited registered TAI, TAI list and eKSI. It also deletes the list of equivalent PLMNs and resets the attach attempt counter. In S1 mode it then stores the PLMN identity in the
Nothing in that sentence touches the USIM. The card stays valid, and one PLMN identity is added to a list. The UE then enters EMM-DEREGISTERED.PLMN-SEARCH and runs the PLMN selection defined in 23.122. That step has no visible effect here, and a very visible one in Figure 5.
The clause adds one more line worth knowing in a lab. If the message was integrity checked and the UE keeps a PLMN-specific PS-attempt counter for that PLMN, it sets that counter to its maximum. So the UE is not merely declining to retry: it has recorded that retrying is pointless.
The bar is on the PLMN : written into a list, with the USIM untouched.PLMN selection runs regardless : it just has nothing to find here.The attach attempt counter is reset : this is not treated as a failure to retry.The per-PLMN attempt counter is maxed out : when the message was integrity checked.
Cause #14 'EPS Service not allowed in this PLMN' - multiple PLMN
This is the same cause as the drawing above with one thing changed: a second network is in range. The UE behaves identically and the outcome is the opposite, which is the clearest demonstration on this page of what a narrow bar buys.
Two networks are drawn below, and the second one accepts the attach the first refused.

Figure 5. A PLMN level bar leaves the subscriber connectable. The UE moves and registers.
The refusal is identical to the single PLMN case : the same cause and the same note about never retrying that PLMN.The UE then attaches to PLMN 2 : the Initiate Attach arrow goes to the second lifeline.The second network allows it : the note beside PLMN 2 records that the network allows the attach.Registration completes : the last arrow is the completion of registration, and the subscriber has service.
The rule behind this is the one quoted above, and no part of it is different. The UE stored PLMN 1 in the
Put the two drawings side by side and the lesson is about diagnosis rather than about the UE. One symptom points straight at #14: no service on one network and normal service on another. The fault is then in the subscription for that PLMN rather than in the handset or the card. The same fault with no second network in range looks exactly like a dead device.
The list is per PLMN and survives until the UE is switched off, the UICC is removed, or T3245 expires. So a UE that attached to PLMN 2 will still refuse PLMN 1 after a handover back into its coverage, and that is correct behaviour rather than a stuck state.
Same cause, same rule, opposite outcome : the only variable is what else is in range.Service on one network and not another points at #14 : and at the subscription for that PLMN.The bar survives the move : PLMN 1 stays forbidden while the UE is camped on PLMN 2.Only the three exits clear it : switch off, UICC removal, or T3245.
Cause #15 'No Suitable Cells in TA' - multiple PLMN
Cause #15 bars a tracking area rather than a network, and the drawing is built to make that visible. Read the two lifeline labels before anything else, because they are what the sequence turns on.
Two networks are drawn below and both are in the same tracking area, which the lifeline labels give as TA1.

Figure 6. The bar is on the tracking area, so a second PLMN in the same TA is no help at all.
Both lifelines carry TA1 : they read PLMN 1, TA1 and PLMN 2, TA1, and that is the point of the drawing.The reject is labelled by its real name : Cause #15, No Suitable Cells in TA.Neither PLMN is retried : not because both are barred, but because the one tracking area they share is.A power cycle recovers it : and the attach goes out again to PLMN 1.
24.301 clause 5.5.1.2.5 says the UE stores the current TAI in the list of
That explains why a second network does not help here while it rescued the UE under #14. PLMN 2 is perfectly allowed. Its cells are in TA1, TA1 is forbidden, and the UE has no suitable cell to select. Had the drawing given PLMN 2 a different tracking area, the sequence would have looked like the #14 multiple PLMN case instead.
The clearing rule is the one that differs from every other cause on this page. Clause 5.3.2 says the forbidden tracking area lists are erased when the UE is switched off, when the UICC is removed, and
The bar is on the tracking area : not on the PLMN and not on the card.Another PLMN only helps if it is another TA : which is exactly what this drawing denies it.The state is LIMITED-SERVICE : emergency calls remain possible.The list also clears on a timer : every 12 to 24 hours, with no user action at all.
Cause #25 'Not Authorized for this CSG' - multiple PLMN
Cause #25 is the narrowest refusal here. It bars one closed subscriber group rather than a network or an area, and the drawing spends its first two messages establishing which cell is which.
Two cells of the same PLMN are drawn below, and the SIB1 content at the top is what separates them.

Figure 7. The CSG is removed from the allowed list and the UE moves to an ordinary cell of the same network.
The first SIB1 declares a CSG cell : csg-indication is True and a 27 bit csg-identity is broadcast.The second SIB1 declares an ordinary cell : csg-indication is False and csg-identity is omitted.Both lifelines are the same PLMN : they read PLMN 1 twice, so this is a move between cells rather than between networks.The reject comes from the CSG cell : Cause #25, Not Authorized for this CSG.The UE edits its own allowed list : the note says it removes the current CSG from the allowed CSG list and searches for another cell in the same PLMN.It then attaches on the non-CSG cell : the last arrow goes to the second lifeline.
24.301 clause 5.5.1.2.5 matches the note in the drawing almost word for word. If the CSG ID and its associated PLMN identity are in the Allowed CSG list, the UE removes that entry. It sets EU3 ROAMING NOT ALLOWED, resets the attach attempt counter, enters EMM-DEREGISTERED.LIMITED-SERVICE, and searches for a suitable cell using the rules in 36.304.
This is the only cause on the page where the UE changes a list that a human provisioned. The allowed CSG list is configuration, and the network has just told the UE that one entry in it is wrong. Nothing will put that entry back except provisioning it again, which is why the clearing column for #25 in the table above does not mention a power cycle.
The note already on this page is exactly right, and the specification wording confirms it. EMM cause #25 is only applicable when received from a CSG cell. The same cause from a non-CSG cell is an abnormal case, and clause 5.5.1.2.6 says what the UE does with it. The two SIB1 messages at the top of the drawing are there so you can tell which kind of cell sent it.
One protection is worth adding to that note. The same clause says that an ATTACH REJECT with cause #25 received
The bar is on one CSG : the narrowest scope on this page.The UE deletes provisioned configuration : which is why only re-provisioning restores it.It only counts from a CSG cell : from anywhere else it is an abnormal case.Unprotected #25 must be discarded : the UE should not act on it at all.
Note : 24.301 5.5.1.2.5 states as follows.
EMM Cause #25 is only applicable when recieved from a CSG cell.
EMM Cause #25 recieved from a non-CSG cell is considered as an abnormal case.
Reference
One specification carries every rule quoted on this page, and the clause numbers are given beside each cause so the wording can be checked rather than taken on trust.
- 24.301 - Non-Access-Stratum (NAS) protocol for EPS; Stage 3, v20.0.0. Clause 5.5.1.2.5 is the per-cause UE behaviour. Clause 5.5.1.2.6 covers the abnormal case that a cause #25 from a non-CSG cell falls into. Clause 5.3.2 is the forbidden tracking area lists and how they are erased, and clause 5.3.7a is timer T3245. Table 9.9.3.9.1 lists the EMM cause values and their names.
- 23.122 - NAS functions related to Mobile Station in idle mode. This is the PLMN selection the UE runs after cause #14.
- 36.304 - User Equipment procedures in idle mode. This is the cell selection the UE runs after cause #25.