Heksagon Helps Ucell Block 90% of Gray A2P Traffic Across 184 Live Test Attempts
- Client: Ucell
- Sector: Mobile Network Operator (10.9+ million subscribers)
- Region: Central Asia (Uzbekistan)
- Challenge: Gray A2P termination, flash call, and spam call traffic arriving as local P2P
- Solution: Heksagon Voice Firewall with Flash Call Prevention, verified through active test calling
- Scope: Live inbound international voice traffic on the production network, national traffic excluded
- Result: 90% average block rate across 184 controlled test attempts, 166 blocked by firewall rules
Published:
The Challenge
The economics of gray A2P termination are simple. The traffic that would normally monetize through A2P interconnect arrangements arrives looking like ordinary subscriber traffic and gets billed that way. An application sends a one-time password or an authentication call to a subscriber. Instead of terminating through a wholesale A2P agreement, the traffic is routed over IP to a SIMBOX or GSM gateway sitting inside the country, which terminates it from a local SIM. The operator's MSC records it as ordinary P2P traffic. The A2P rate is never applied, and the loss does not appear anywhere in standard reporting.
Ucell, one of Uzbekistan's largest mobile operators with more than 10.9 million subscribers, was seeing this across several classes of traffic at once. Some senders delivered authentication codes as flash calls, where the last digits of the calling number carry the code, and the call is dropped before answer. Others generated Wangiri-style call attempts from international ranges. Both patterns look similar at the signaling level, and both bypass the revenue path that A2P messaging would have followed.
Verification was the harder problem. Aggregators rotate their numbering ranges, so a rule set that blocked every test attempt in April could quietly stop matching in May, once a sender moved to a range no filter covered yet. Block counts alone would not have shown that.
The Solution: Three Layers of Rules
Ucell and Heksagon built the defense as three rule layers inside the Heksagon Voice Firewall, each aimed at a different stage of the bypass, but all writing to the same real-time enforcement path.
- Layer one blocks invalid and unassigned international numbering. The firewall operates on a block-by-default policy for inbound international calls, admitting only calling numbers that fall inside allocated ITU E.164 ranges. Numbering that was never commercially allocated to any operator is rejected outright. This removes fabricated calling line identity before any behavioral analysis is needed.
- Layer two blocks flash calls based on calling history. The firewall separates calling numbers that have an established relationship with the network from those that do not, and treats the latter as untrusted. Numbers that go on to behave like ordinary international callers are whitelisted. Repeat attempts that follow immediately after a block are caught by the same layer. National traffic is excluded.
- Layer three applies flash call monitoring and action per direction. Calls are observed and classified against analytical profiles built on traffic pattern and duration characteristics per prefix. Prefixes that show a high concentration of very short calls are blacklisted automatically. Calls that run long enough to indicate genuine conversation are read as legitimate and whitelisted for a defined period, which keeps the block rate high without penalizing real callers.
Alongside the three layers, a dedicated Spam Call Rule runs on the same enforcement path, targeting call attempts from international ranges that match known spam-calling patterns rather than genuine subscriber communication. It accounts for 11% of all blocks in the test period.
What Heksagon Does in the Architecture
For clients like Ucell, Heksagon’s Voice Firewall is the enforcement point. Every inbound international call gets evaluated against the active rule set in real time and either passed, rejected, or rerouted, with no operator action per call. Analytical profiles run underneath, so classification improves as more traffic is observed.
The part that made the Ucell deployment measurable is rule-level attribution. Each call detail record carries the name of the rule that activated and the action it took. When Ucell requests an authentication code from a real application on a test SIM and the code does not arrive by SMS, the team can open the CDR log and see which rule caught the call, or see that nothing did.
Ucell chose Heksagon because they needed active validation of rule effectiveness rather than passive reporting alone. A platform that reports blocked volumes in aggregate would have shown the same 90% without saying which rule produced it, or when one stopped matching.
The firewall's reporting and monitoring views show blocks per rule per date and per hour. A rule that stops blocking traffic shows up within the same day rather than at the end of a reporting cycle, which is the difference between a gap of hours and a month of quiet leakage.
The Results
Ucell ran 21 controlled testing sessions between April and May 2026, requesting authentication codes from live consumer applications on test SIMs and checking the firewall logs for each attempt.
- 184 test attempts, 166 blocked by rule, for a 90% average block rate across the full period
- 18 attempts passed, 9.8% of the total, most traced to a specific numbering range or pattern and closed with a new or widened filter
- 94% to 100% block rate in the first four sessions after the rules went live, and 82% to 100% through the following three weeks as more sender services were added to the test set
- A sharp two-session drop in early May, followed by recovery to a 67% to 100% range for the rest of the period
- Blocks came from across the rule set rather than one layer: calling history 49%, direction specific flash call rules 19%, and the Spam Call Rule 11%
The most instructive session of the period was the one that failed. Across 5 and 6 May the block rate fell to between zero and 11%, and eight of the 18 unblocked attempts recorded across the entire period came from 6 May alone. The monitoring view showed which rules had stopped blocking, and the cause was a sender moving to a numbering range that no active rule covered. Filters for the new ranges were activated, and the 7 May session came back at 87%. Of the remaining misses, seven were individual calling numbers from adjacent ranges that each needed a new or widened filter, and three are still being classified.
Facing the Same Challenge? What This Means for You
The bypass mechanics are the same on any network: IP routing into a local SIM gateway, termination as P2P, no A2P rate collected. Only the mix of senders changes, which is why the rule logic that reached 90% on the Ucell network transfers to other operators even though the numbers will not. The second transferable finding is that 90% is a maintained figure rather than a fixed one. Aggregators move numbering ranges, and the gap between a range switch and a filter update is the revenue exposure. Ucell closed that gap inside a single testing session because Heksagon made blocking data visible per rule and per hour.
For MNOs seeing the same pattern, the practical step is to stop inferring performance from block counts and start generating test traffic against live sender services, then read the outcome rule by rule. Heksagon Voice Firewall provides the enforcement layer and spam-pattern detection, with Flash Call Prevention covering flash calls. To see what this could look like against your own traffic profile, contact us.