This page will explain the general procedure for IP allocation during the initial attach (1st PDN setup). IP allocation can be allocated anytime after the initial attach and the additional IP setting after the initial attach and IPv6 allocation will be described in separate page.
IP Allocation for UE
The address a UE ends up using is not chosen by the UE. It asks for a kind of address, and the network picks the value. The two messages in the table below are where that happens, and everything else in the attach is carrying them.
|
Direction |
Message |
Comment |
|
UE -> NW |
RRC : RRC Connection Setup Complete + NAS : Attach Request |
UE Request a PDN with specific IP type |
|
UE <- NW |
RRC : RRC Connection Reconfiguration + NAS : Attach Accept |
Network Allocate a sepcific IP to UE |
PDN Connectivity Request
This is the uplink half, carried inside the Attach Request. The field to watch is the PDN type, because it is the only thing the UE gets to say about its address at this point.

The message type is D0 : the decoder prints it under the PDN connectivity request message identity.The protocol discriminator is 2 : this is an ESM message, travelling inside a NAS one.No EPS bearer identity is assigned yet : the bearer this request will create does not exist while the request is in flight.The PDN type value is IPv4 : that is the whole of what the UE asks for, and it names a kind rather than a value.The request type is initial request : this is the first PDN, which is what puts the exchange inside attach.
Activate Default EPS Bearer Context Req
The answer comes back in the downlink half, and it carries the value the UE will use. The PDN address element below is the one to read, and its length octet is worth checking against its contents.

The bearer now has an identity : EPS bearer identity value 5, where the request had none.The message type is C1 : D0 and C1 are the request and the activation that answers it.The PDN address contents are five octets : one octet of PDN type and four of address.The address reads C0A80101 : which is 192.168.1.1 in the hexadecimal the decoder prints.
24.301 clause 9.9.4.9 explains that arithmetic. The PDN address is a type 4 element of 7 to 15 octets. It opens with an identifier and a length, and its contents begin with the PDN type value. One octet of type plus four of IPv4 address is the five the decoder reports.
The 15 octet maximum is the other end of the same sum. It is the IPv4v6 case, with an eight octet interface identifier sitting between the type and the IPv4 address. The same clause says what the network has to send. It includes an IPv4 address when it sets the PDN type to IPv4 or IPv4v6, and an interface identifier when it sets IPv6 or IPv4v6.
The UE asks for a kind and the network sends a value : PDN type going up, PDN address coming down.D0 and C1 are the two message types : the connectivity request, and the activation that answers it.The length octet is checkable against the contents : five octets is one of type and four of address.This capture was given 192.168.1.1 : C0A80101, read straight off the decode.
IP Allocation for DNS
A DNS address is not part of the bearer, so it cannot travel in the PDN address element. It goes in the Protocol Configuration Options instead. That element is where anything without a field of its own travels.
|
Direction |
Message |
Comment |
|
UE -> NW |
RRC : RRC Connection Setup Complete + NAS : Attach Request |
UE Request a DNS via PCO |
|
UE <- NW |
RRC : RRC Connection Reconfiguration + NAS : Attach Accept |
Network Allocate DNS IP via PCO |
PDN Connectivity Request
The same uplink message appears again, with the highlight moved to the options element. One thing to notice first: the PDN type here reads IPv4v6 rather than IPv4, so this is a different attach from the one in the section above.


The request sits in the Additional parameters list : inside the Protocol configuration options, after the protocol list.Container 000D carries the DNS request : 24.008 calls it DNS Server IPv4 Address Request in this direction.Its length is zero : the specification requires the contents field of that container to be empty.Three more containers go up with it : 0003 for the IPv6 DNS server, 0010 for the IPv4 link MTU, and one more that 24.008 does not list.
Activate Default EPS Bearer Context Req
The answer uses the same element and the same container identifier as the request. What changes is the length, and that change is the whole mechanism. Everything else in the options is the PPP negotiation the element wraps.


The element carries its own identifier and length : IEI 27, and 27 octets of contents after it.The configuration protocol is PPP : 24.008 codes those three bits as PPP for use with IP PDP type or IP PDN type.Container 000D comes back with length 4 : and its contents read C0A80102, which is 192.168.1.2.The same address appears twice in the PPP payload : two options of six octets inside protocol 8021, both carrying C0A80102.
One identifier does two jobs here, and the direction decides which. 24.008 lists 000D in both of its container tables. From the MS to the network it is DNS Server IPv4 Address Request, and the clause requires its contents field to be empty. From the network to the MS it is DNS Server IPv4 Address, and the contents carry one IPv4 address.
That is why the two pictures differ only in a length. Nothing inside the container says request or answer, and nothing needs to. A container going up can only be a request, and one coming down can only be an answer.
The protocol list beside it is a second route to the same value. 24.008 leaves the contents of each protocol unit to the RFC that owns the protocol identifier, so what sits under 8021 is an IPCP exchange rather than anything 3GPP defines. This network answered on both routes with the same address.
The DNS address rides in the options element : it has no field of its own in the bearer setup.One identifier, two meanings : 000D is a request going up and an address coming down.Length zero is the request : 24.008 requires an empty contents field for that form.This capture was answered with 192.168.1.2 : four octets, C0A80102.The PPP path carries it as well : the same value appears inside protocol 8021 in the same element.
Reference
[1] 24.301 : 3GPP - Non-Access-Stratum protocol for EPS; Stage 3, v20.0.0. Clause 9.9.4.9 gives the PDN address element, its 7 to 15 octet range, and what the network must include for each PDN type.
[2] 24.008 : 3GPP - Mobile radio interface Layer 3 specification; Core network protocols; Stage 3, v20.0.0. Clause 10.5.6.3 gives the Protocol configuration options, the configuration protocol coding, and a container identifier list for each direction.