My phone has 26 different cellular interfaces.

I have 26 different cellular interfaces. I suspected network manipulation for sometime or in this case malicious network configuration. Is there any situation where anything that appears below would be normal?



Current Network:

Entry;Info;IP

Type;VPN (utun6);

IP Address;172.23.109.110;172.23.109.110

Gateway;;

Netmask;255.255.255.255;255.255.255.255

IPv6 Address;fd75:911e:eb9f::6d6e;fd75:911e:eb9f::6d6e

IPv6 Gateway;;

IPv6 Netmask;ffff:ffff:ffff::;ffff:ffff:ffff::

DNS Server 1;172.23.109.2;172.23.109.2

IPv6 DNS Server 1;fddd:9c8a:f886::6d03;fddd:9c8a:f886::6d03

Public IP Address;Unknown;Unknown

WiFi:

Entry;Info

Connected to WiFi;NO

Cell:

Entry;Info;IP

Connected to Cell;YES;

IP Address;10.126.57.23;10.126.57.23

Gateway;10.126.57.23;10.126.57.23

Netmask;255.255.255.255;255.255.255.255

IPv6 Address;2600:381:eb1e:2e53:a1b9:db5c:d196:45d6;2600:381:eb1e:2e53:a1b9:db5c:d196:45d6

IPv6 Gateway;fe80:4::b06e:743d:eae2:f4fc;fe80:4::b06e:743d:eae2:f4fc

IPv6 Netmask;ffff:ffff:ffff::;ffff:ffff:ffff::

Interface;pdp_ip0;

Carrier Name;--;

CCarrier Country code;65535;

Country code;--;

Mobile network;65535;

Allows VOIP;YES;

Access technology;CTRadioAccessTechnologyNRNSA;

LAN:

Entry;Info

Connected to LAN;NO

VPN:

Entry;Info;IP

Connected to VPN;YES;

IP Address;172.23.109.110;172.23.109.110

Gateway;;

Netmask;255.255.255.255;255.255.255.255

IPv6 Address;fd75:911e:eb9f::6d6e;fd75:911e:eb9f::6d6e

IPv6 Gateway;;

IPv6 Netmask;ffff:ffff:ffff::;ffff:ffff:ffff::

Interface;utun6;utun6

Interfaces:

Entry;Info

awdl0 (Apple Wireless Direct Link);fe80::c492:4bff:feaa:5227

ipsec0 (IPSec Tunnel);fe80::38fd:f519:314e:3151

ipsec1 (IPSec Tunnel);fe80::38fd:f519:314e:3151

ipsec3 [1] (IPSec Tunnel);fe80::38fd:f519:314e:3151

ipsec3 [2] (IPSec Tunnel);2600:381:eb7f:c2c7:db:230b:f12c:2181

ipsec4 [1] (IPSec Tunnel);fe80::38fd:f519:314e:3151

ipsec4 [2] (IPSec Tunnel);2600:381:eb7f:c2c7:db:230b:f12c:2181

llw0 ;fe80::c492:4bff:feaa:5227

lo0 [1] (Loopback);127.0.0.1

lo0 [2] (Loopback);::1

lo0 [3] (Loopback);fe80::1

pdp_ip0 [1] (Cellular);10.126.57.23

pdp_ip0 [2] (Cellular);fe80::1023:c36b:2209:933

pdp_ip0 [3] (Cellular);2600:381:eb1e:2e53:8f4:6cc4:1442:e14f

pdp_ip0 [4] (Cellular);2600:381:eb1e:2e53:a1b9:db5c:d196:45d6

pdp_ip1 [1] (Cellular);fe80::1473:655e:8b86:da2b

pdp_ip1 [2] (Cellular);2600:381:eb7f:c2c7:db:230b:f12c:2181

pdp_ip1 [3] (Cellular);2600:381:eb7f:c2c7:889:5623:adc9:c3e2

utun0 (Virtual Tunnel);fe80::3f1c:5748:192d:d91d

utun1 (Virtual Tunnel);fe80::28d4:5e5d:5671:dd82

utun2 (Virtual Tunnel);fe80::7dd9:ef17:29de:c536

utun3 (Virtual Tunnel);fe80::ce81:b1c:bd2c:69e

utun6 [1] (Virtual Tunnel);fe80::38fd:f519:314e:3151

utun6 [2] (Virtual Tunnel);172.23.109.110

utun6 [3] (Virtual Tunnel);fd75:911e:eb9f::6d6e

Proxy information:

Entry;Info

__SCOPED__;Dict(1)


iPhone 15, iOS 18

Posted on Aug 29, 2025 5:36 PM

Reply

Similar questions

2 replies

Aug 30, 2025 7:47 AM in response to DNLMars

What sort of network manipulation or malicious network configuration are you encountering here?


There are twenty-six internet protocol network-related devices shown.


In addition to the usual and mundane IP devices expected such as loopbacks, I see some seven cellular-related devices with IPv4 and mostly IPv6, and a mix of ordinary and tunnel- and IPsec-related devices.


The public IPv6 addresses are associated with AT&T, with various private and link local IPv4 and IPv6 addresses among.


Nothing particularly suspicious.


Out of curiosity, is this output from some log or telemetry data, or from a tool using CNCopyCurrentNetworkInfo or such?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

My phone has 26 different cellular interfaces.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.