Connectivity AND Security: Why It’s a Mistake to Separate Them
A 4G router without a VPN exposes the OT network to serious risks. The temptation to “just open Modbus port 502” or “enable RDP port forwarding” to access an HMI is real—but it’s one of the most dangerous practices in connected OT.
Thousands of industrial devices are listed on Shodan (a search engine for services exposed on the Internet), with their Modbus registers directly accessible without authentication. In 2021, an attacker altered the chlorine levels at a water treatment plant in Florida via direct TeamViewer access.
The 4G router with built-in VPN solves this problem at its source: the VPN is enabled by default, the OT network is never exposed to the Internet, and remote access is secured through authentication and encryption.
How a 4G + VPN Router Works
Advantages of a Built-in VPN vs. an External VPN
| Criterion | VPN built into router | Separate external VPN |
|---|---|---|
| Number of devices | 1 | 2 (router + VPN device) |
| Configuration | Single (all-in-one) | Dual (router + VPN) |
| Cabinet space | Minimal | Double |
| Single point of failure | 1 | 2 |
| Active VPN guarantee | Yes (built-in firmware) | To be verified |
| Cost | Lower | Higher |
| Maintenance | Only one device to update | Two |
Zero-Touch Provisioning: Deployment Without a Network Technician
The main operational advantage of a 4G router with an integrated VPN is zero-touch provisioning: the router leaves the factory with its configuration preloaded (APN, VPN settings, certificates). On-site, the technician simply plugs in the power and connects the field equipment. Within 3 to 5 minutes, the router is connected, the VPN is established, and the site is visible in the cloud platform.
No need to connect to the network service, no manual IP address configuration, and no need to manage VPN certificates. That’s what makes it possible to deploy 50 sites in just a few days.
The Eziwan Approach
The Eziwan Gateway is a 4G router with built-in VPN (OpenVPN + IPSec), dual M2M SIM support, a native RS-485 port, and zero-touch provisioning. The VPN is enabled by default upon first startup, with certificates automatically generated and deployed from the Eziwan Cloud.
For more information: Secure Industrial VPN, Remote Access to Industrial PLCs, and Remote Access Without Port Forwarding.