IoT Guide

Industrial Fixed-IP 4G Router — Private APN, VPN, Inbound Remote Access | Eziwan

Industrial 4G router with a static IP address on a private APN. Inbound remote access via RDP, VNC, SSH, and SCADA. Built-in IPSec/OpenVPN. 4G failover.

Quick answer
A Industrial 4G router with a static IP address receives a static IP address— either public or private—on your carrier’s public access network (APN), enabling direct incoming connections (RDP, VNC, SSH, SCADA) from your infrastructure—without requiring a central server VPN. Ideal for theinbound remote access securely connected to controllers, HMIs, and isolated industrial equipment.

Static IP on a 4G Network: Why It’s Different from Consumer Services

With a consumer mobile plan or a standard M2M SIM card, the carrier assigns a dynamic IP address to each connection, which changes every time you reconnect. In addition, carriers use CGNAT (Carrier Grade NAT): your 4G router is located behind an IP address shared by hundreds of customers—making it impossible to establish incoming connections to it.

For industrial applications requiring incoming remote access (PLC control, SCADA connection, RDP monitoring), it is essential to have a static IP address that is always accessible.

There are two architectures that can be used to achieve this goal with an Eziwan industrial 4G router:

Architecture 1 — Private operator APN with a fixed public IP: Each M2M SIM in your fleet is assigned a unique fixed public IP. Traffic is routed through the operator’s MPLS VPN. Suitable for large fleets with existing IT infrastructure.

Architecture 2 — Permanent VPN to the Eziwan Cloud: The router automatically establishes an outbound VPN tunnel to the Eziwan platform, which assigns it a fixed tunnel IP address. Access from anywhere on the Eziwan network. Suitable for networks of all sizes; immediate deployment.

Private APN: Your Company’s Dedicated M2M Network

A private APN is an M2M data network exclusive to your company, configured by the carrier. Unlike a public Internet APN, it is not accessible from the Internet—only the SIM cards in your fleet can connect to it.

FeaturePublic APN (Internet)Private APN
Internet AccessYes (exposed)No (private)
IP AddressDynamic (CGNAT)Static (dedicated)
Traffic IsolationNoYes (dedicated MPLS)
Incoming connectionsNot possiblePossible (controlled)
Setup timeImmediate2–4 weeks
CostIncluded in planMonthly surcharge

A private APN is the recommended solution for large M2M fleets (>50 SIMs) operated by industrial companies that want a data network completely isolated from the public Internet.

Permanent VPN: A Static IP Address Without a Private APN

For companies that do not wish to subscribe to a private operator-provided VPN (due to delays, cost, or contractual complexity), Eziwan offers an alternative solution based on a permanent VPN:

The Eziwan 4G router automatically establishes an encrypted VPN tunnel (OpenVPN or WireGuard) to the Eziwan servers upon startup. This tunnel remains active at all times. Within the Eziwan infrastructure, each router has a unique fixed tunnel IP, accessible from the Eziwan portal or from your corporate network via a BGP/IPSec connection.

This architecture offers the same benefits as a public static IP address, with superior security guarantees:

  • No open inbound ports on the router (Zero Inbound)
  • Traffic is always encrypted with AES-256
  • Works with any SIM, even those with dynamic CGNAT IP addresses
  • Transparent dual-SIM failover: the tunnel IP remains the same

Remote Access Protocols via 4G Fixed IP

The Eziwan 4G router with a static IP address supports all industrial remote access protocols:

Remote access to PLCs:

  • Modbus TCP (port 502): direct access to Schneider, ABB, and Wago PLC registers
  • S7 Communication (port 102): connection from TIA Portal, Step 7, and WinCC to Siemens S7
  • OPC-UA (port 4840): standard IIoT protocol for interoperability
  • EtherNet/IP (port 44818): Rockwell/Allen-Bradley protocol

Remote access to HMIs and supervision PCs:

  • RDP (port 3389): remote Windows access
  • VNC (port 5900): access to Linux HMIs and Raspberry Pi devices
  • SSH (port 22): command-line access to industrial Linux devices

Securing Inbound Remote Access: Best Practices

Inbound remote access via a static IP address opens up new possibilities but also presents new risks. Eziwan’s best practices for securing industrial remote access:

  1. Always use the VPN: Never expose your PLCs directly to the Internet, even on a private network. The Eziwan VPN tunnel adds a layer of encryption and authentication.

  2. Source IP whitelist: Configure inbound firewall rules on the router to allow only IP addresses from your infrastructure (data center, corporate network).

  3. Two-factor authentication: Enable 2FA on the Eziwan portal for remote access user accounts.

  4. Time-Limited Sessions: Set inactivity timeouts for RDP/VNC access (automatic logout after 30 minutes of inactivity).

  5. Logging: Enable logging for all incoming connections to the Eziwan portal to detect intrusion attempts.

Use Case: Industrial Remote Access via Fixed 4G IP

Remote PLC Maintenance: Your technicians can remotely access your customers’ Siemens, Schneider, or Rockwell PLCs via TIA Portal or Unity Pro—just as if they were on the site’s local network. Reduce travel by 60 to 80%.

Multi-site SCADA Monitoring: Your Wonderware, Ignition, or WinCC server centralizes monitoring of 50 industrial sites, each equipped with an Eziwan 4G router with a static IP address. A single interface for all your sites.

Remote Maintenance of Sold Equipment: Machine manufacturers (OEMs) integrate an Eziwan 4G router into their equipment to remotely access machines installed at their customers’ sites. Proactive after-sales service based on real-time telemetry.

Frequently Asked Questions

You might also like