Static IP on a 4G Network: Why It’s Different from Consumer Services
With a consumer mobile plan or a standard M2M SIM card, the carrier assigns a dynamic IP address to each connection, which changes every time you reconnect. In addition, carriers use CGNAT (Carrier Grade NAT): your 4G router is located behind an IP address shared by hundreds of customers—making it impossible to establish incoming connections to it.
For industrial applications requiring incoming remote access (PLC control, SCADA connection, RDP monitoring), it is essential to have a static IP address that is always accessible.
There are two architectures that can be used to achieve this goal with an Eziwan industrial 4G router:
Architecture 1 — Private operator APN with a fixed public IP: Each M2M SIM in your fleet is assigned a unique fixed public IP. Traffic is routed through the operator’s MPLS VPN. Suitable for large fleets with existing IT infrastructure.
Architecture 2 — Permanent VPN to the Eziwan Cloud: The router automatically establishes an outbound VPN tunnel to the Eziwan platform, which assigns it a fixed tunnel IP address. Access from anywhere on the Eziwan network. Suitable for networks of all sizes; immediate deployment.
Private APN: Your Company’s Dedicated M2M Network
A private APN is an M2M data network exclusive to your company, configured by the carrier. Unlike a public Internet APN, it is not accessible from the Internet—only the SIM cards in your fleet can connect to it.
| Feature | Public APN (Internet) | Private APN |
|---|---|---|
| Internet Access | Yes (exposed) | No (private) |
| IP Address | Dynamic (CGNAT) | Static (dedicated) |
| Traffic Isolation | No | Yes (dedicated MPLS) |
| Incoming connections | Not possible | Possible (controlled) |
| Setup time | Immediate | 2–4 weeks |
| Cost | Included in plan | Monthly surcharge |
A private APN is the recommended solution for large M2M fleets (>50 SIMs) operated by industrial companies that want a data network completely isolated from the public Internet.
Permanent VPN: A Static IP Address Without a Private APN
For companies that do not wish to subscribe to a private operator-provided VPN (due to delays, cost, or contractual complexity), Eziwan offers an alternative solution based on a permanent VPN:
The Eziwan 4G router automatically establishes an encrypted VPN tunnel (OpenVPN or WireGuard) to the Eziwan servers upon startup. This tunnel remains active at all times. Within the Eziwan infrastructure, each router has a unique fixed tunnel IP, accessible from the Eziwan portal or from your corporate network via a BGP/IPSec connection.
This architecture offers the same benefits as a public static IP address, with superior security guarantees:
- No open inbound ports on the router (Zero Inbound)
- Traffic is always encrypted with AES-256
- Works with any SIM, even those with dynamic CGNAT IP addresses
- Transparent dual-SIM failover: the tunnel IP remains the same
Remote Access Protocols via 4G Fixed IP
The Eziwan 4G router with a static IP address supports all industrial remote access protocols:
Remote access to PLCs:
- Modbus TCP (port 502): direct access to Schneider, ABB, and Wago PLC registers
- S7 Communication (port 102): connection from TIA Portal, Step 7, and WinCC to Siemens S7
- OPC-UA (port 4840): standard IIoT protocol for interoperability
- EtherNet/IP (port 44818): Rockwell/Allen-Bradley protocol
Remote access to HMIs and supervision PCs:
- RDP (port 3389): remote Windows access
- VNC (port 5900): access to Linux HMIs and Raspberry Pi devices
- SSH (port 22): command-line access to industrial Linux devices
Securing Inbound Remote Access: Best Practices
Inbound remote access via a static IP address opens up new possibilities but also presents new risks. Eziwan’s best practices for securing industrial remote access:
-
Always use the VPN: Never expose your PLCs directly to the Internet, even on a private network. The Eziwan VPN tunnel adds a layer of encryption and authentication.
-
Source IP whitelist: Configure inbound firewall rules on the router to allow only IP addresses from your infrastructure (data center, corporate network).
-
Two-factor authentication: Enable 2FA on the Eziwan portal for remote access user accounts.
-
Time-Limited Sessions: Set inactivity timeouts for RDP/VNC access (automatic logout after 30 minutes of inactivity).
-
Logging: Enable logging for all incoming connections to the Eziwan portal to detect intrusion attempts.
Use Case: Industrial Remote Access via Fixed 4G IP
Remote PLC Maintenance: Your technicians can remotely access your customers’ Siemens, Schneider, or Rockwell PLCs via TIA Portal or Unity Pro—just as if they were on the site’s local network. Reduce travel by 60 to 80%.
Multi-site SCADA Monitoring: Your Wonderware, Ignition, or WinCC server centralizes monitoring of 50 industrial sites, each equipped with an Eziwan 4G router with a static IP address. A single interface for all your sites.
Remote Maintenance of Sold Equipment: Machine manufacturers (OEMs) integrate an Eziwan 4G router into their equipment to remotely access machines installed at their customers’ sites. Proactive after-sales service based on real-time telemetry.