▾ PushSettings {} 2
· Topic = "com.hk.entitlements"
· MultiSIMTopic = "com.cellcom.multisimapns"
· OverrideOperatorName = "Cellcom"
▾ MMS {} 12
MMSC URL, WAP proxy, size limits and junk-report routing. · MaxMessageSize = 1048576
· GroupModeAllowUserOverride = true
· CanUseTransactionIdWithContentLocation = true
· UAProf = "http://iphonemms.apple.com/iphone/uaprof-2MB.rdf"
· MMSC = "http://mms.cellcom.com/cellcom/mms.php"
· AllowFetchFromMultipleMMSCs = false
· GroupModeEnabled = false
· AllowReturnReports = true
· CarrierRequiredPhoneNumberHeaderName = "X-MDN"
· UserCanReinitiateActivation = false
· VisualVoicemailServiceName = "IMAP"
▾ CarrierEntitlements {} 8
Server that gates carrier features (Wi-Fi Calling, tethering, Watch plans). SupportedEntitlements is a bitmask of which entitlement classes are queried. · SupportedEntitlements = 80 bits 4, 6 · 0x50
Bitmask of entitlement classes the device may request from the entitlement server. Individual bit meanings are not published. ▾ Authentication {} 2
· Username = "0$IMSI@nai.epc.mnc$MNC.mcc$MCC.3gppnetwork.org"
· ProvisioningRecheckPeriod = 6
· SupportedEntitlementsStandaloneMode = 209
· ServerAddress = "https://deg.ims.cellcom.com/ium-OEMInterface/servlet/IUMServlet"
· UserAgent = "Entitlement/$version ($device) iOS/$iOSVersion"
▾ DisallowedDialingPrefixes [] 1
Dial strings the handset refuses to send. · SupportsSupplementaryServicesOverIMS = true
· SupportsUserBusyCauseCode = true
▾ SMSSettings {} 4
· SupportsTextToEmergency = true
· TransportFallback = true
· SupportSimToolkitIMSRegNotifications = true
▾ Services [] 4
USSD/short-code shortcuts surfaced in the carrier menu in Settings. ▾ [0] {} 2
· ServiceName = "Directory Assistance"
▾ [1] {} 2
· ServiceName = "Check Bill Balance"
▾ [2] {} 2
· ServiceName = "Pay My Bill"
▾ [3] {} 2
· ServiceName = "View My Minutes"
· DefaultWhenImsSwitchOff = 1
· PreferPrimaryDNS = true
▾ SupportedSIMs [] 1
MCC+MNC values (optionally with _GID1-/_GID2-/_ID- qualifiers) this bundle claims. The handset picks a bundle by matching the SIM against this list. ▾ MaxBluetoothModemConnections [] 1
· VVMIgnoresIntlDataRoaming = true
▾ com.apple.voicemail.imap {} 11
· MaxGreetingDuration = 120
· GreetingNotification = true
· AuthenticationScheme = "DIGEST-MD5"
· BypassSMSCAvailabilityCheck = true
· ClientManagesTrash = true
▾ AllowedIMAPServers {} 1
· ShowLTEWarningUnsupportedCarrier = false
· ExitEmergencyModeWhenPlacingFirstRegularCall = true
· SuspendFastDormancyAllowed = true
· PhoneNumberRegistrationGatewayAddress = "9876"
Short code the handset SMSes to register its number with Apple services (iMessage/FaceTime). · IPCUApnTypemask = 19 bits 0, 1, 4 · 0x13
· SMSSizeInBytesSentAsMMSInstead = 973
· HomeBundleIdentifier = "com.apple.UnitedStates"
The country bundle this carrier bundle expects to sit on top of. · DeliveryReceiptsDefault = false
▾ IMSConfig {} 8
IMS (VoLTE / Wi-Fi Calling) stack configuration: SIP signalling, media/SRTP, registration and headers. ▾ Signaling {} 38
· UseEphemeralSipSourcePortForTcp = true
· RingbackTimerSeconds = 60
· SessionExpiresSeconds = 300
· AllowPhoneContextInEmergencyUri = false
· RingingTimerSeconds = 55
· UserAgentHeaderValue = "APPLE---${DEVICE}---${OS_VERSION}"
▸ OutgoingCallPrefix {} 2
· RetryAfterStatusCodes = "480,486,500,503,600"
· AccessBarringType = "Both"
▸ AdditionalFeatureTags {} 1
· EmergencyRegistrationTimeoutSeconds = 2
· LocationForShortCodeCalls = "BOTH"
· AllowLimitedAccessModeRegistration = true
▸ IncomingCallEndReasons {} 5
· PdpBackOffTimerforRA = 900000
· CSFBOnAccessBarred = true
· EmergencyCallBackModeExpirationSeconds = 300
· ReportSipErrorsDuringReRegistration = true
· AlwaysSetPhoneContext = true
· InviteErrorResponsesToTriggerCSFB = "503"
· AllowSimultaneousCallsWhileUnregistered = false
· TriggerCSFBOnWaitForRingingTimeout = false
· AllowRemoteHoldForUnconfirmedCalls = true
· RegistrationPolicy = "VZW"
· RegisterSmsWhenAccessBarringZero = true
· UseDialogEventPackage = true
· ReRegistrationHysteresisTimerMilliseconds = 60000
· RestartRingbackTimerOn180 = true
· EmergencyImpuRank = "MDN@domain"
· CallSetupPingTimerMilliseconds = 2000
· MinSessionExpiresSeconds = 300
▾ LocalShortCodeNumbers [] 7
▾ ConferenceCalling {} 1
· conferenceServer = "sip:confserver@ims.cellcom.com"
▾ SMS {} 1
· enableInNonVoLTEMode = true
▾ Media {} 12
· RTCPIntervalSeconds = 5
· InactivityTimerRTPSeconds = 20
· EnableBandwidthSpecifiers = true
· SRTPEndToAccessEdgeProtection = true
· InactivityTimerRTCPSeconds = 20
· UseRestrictiveDirectionWhenCreatingAnswer = false
▾ SIM {} 3
· CarrierDomain = "ims.cellcom.com"
· impiFormat = "imsi@carrierDomain"
▾ XCAP {} 12
· NafHost = "xcap.ims.cellcom.com"
· imsFeatureDependency = true
· ContentType = "application/xcap-el+xml"
· DisableOnNetworkError = false
· ForbiddenHttpErrorCodes = "400,403,500"
· imsRegistrationDependency = true
· SupportsCFErasure = true
· BsfHost = "bsf.ims.cellcom.com"
▾ Voice {} 6
· DisableVolteSwitchOnIncompatibleState = true
· EnableVolteByDefault = true
· BlockSilentRedialOverCS = true
· TestEmergencyPSAPSupported = true
· ShowCallForwardingSwitch = false
· CarrierName = "Cellcom"
Operator name shown in the status bar and in Settings. ▾ AttachAPN {} 1
The APN attached at LTE/NR registration, before any user-selected APN. · DeliveryReceiptsAllowUserOverride = false
· DisallowCarrierMenuAtHome = true
· ShowCallWaitingSwitch = false
· StaticNATType = 448 bits 6, 7, 8 · 0x1c0
· RemoteDiagnosticsWWANAllowed = true
▾ MTU [] 1
Per-technology MTU override, keyed by a technology bitmask. ▾ [0] {} 2
· technology-mask = 12 bits 2, 3 · 0xc
▾ Location {} 2
Location policy during emergency calls, including AML. ▾ EmergencyLocation {} 3
▸ AugmentedEmergencyAction {} 1
· AllowOTDOADuringEmergencyMode = true
· SupportsImsCapability = true
▾ QualityOfServiceAudio {} 2
· PhoneNumberIsVoiceMailNumber = true
▾ SupportedPLMNs [] 1
Networks treated as the home network for this bundle. · Enable4GByDefault = true
· ShowVoiceRoamingSwitch = true
▾ CellBroadcast {} 7
Public-warning (cell broadcast) configuration. Only country bundles carry the full schema; carrier bundles carry at most throttling knobs. ▾ AlertConfigurations {} 2
Named sound + vibration pairs referenced by the message-ID mappings. ▸ Configuration_WHAM {} 2
▾ GeofencingConfiguration {} 1
Device-side geofencing (WEA 3.0 style): the handset re-checks the alert area before displaying. · SwitchGroupTitle = "Government Alerts"
Section header used for these alerts in Settings > Notifications. ▾ MessageIDParameters3GPP [] 9
Maps 3GPP cell-broadcast message identifier ranges (TS 23.041) onto named alert types. An identifier that is not mapped is ignored by the handset. ▾ PrimaryBroadcastLanguages [] 1
Languages the handset prefers when a broadcast is sent in several. ▾ AlertTypes {} 6
Per-alert-type presentation. UserConfigurable:false means there is no off switch in Settings. ▾ MessageValidityPeriod {} 1
How long a received broadcast stays valid, in minutes. ▾ apns [] 2
Access Point Names. Each entry carries a type-mask (which services may use it) and a tech-type-mask (which radio technologies). ▾ [0] {} 2
· technology-mask = 1 bits 0 · 0x1
▾ [1] {} 2
· technology-mask = 8 bits 3 · 0x8
▾ RemoteCardProvisioningSettings {} 1
eSIM download settings: SM-DP+ hostnames, ICCID prefixes that match this carrier, and whether an Apple ID check is required. · ServerURL = "https://cco.prod.ondemandconnectivity.com"
· PrimaryDeviceGetsProvisioningInformation = false
· RequiresServiceProvisioning = true
· ShowCallerIDSwitch = false
· TestEmergencyNumber = "922"
Number used to test the emergency path without reaching a PSAP.