* [Blog](https://www2.paloaltonetworks.com/blog) * [Network Security](https://www2.paloaltonetworks.com/blog/network-security/) * [5G Security](https://www2.paloaltonetworks.com/blog/network-security/category/5g-security/) * Turning Cellular into Sec... # Turning Cellular into Secure Transport for Critical Infrastructure [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fnetwork-security%2Fturning-cellular-into-secure-transport-for-critical-infrastructure%2F) [](https://twitter.com/share?text=Turning+Cellular+into+Secure+Transport+for+Critical+Infrastructure&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fnetwork-security%2Fturning-cellular-into-secure-transport-for-critical-infrastructure%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww2.paloaltonetworks.com%2Fblog%2Fnetwork-security%2Fturning-cellular-into-secure-transport-for-critical-infrastructure%2F&title=Turning+Cellular+into+Secure+Transport+for+Critical+Infrastructure&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www2.paloaltonetworks.com/blog/network-security/turning-cellular-into-secure-transport-for-critical-infrastructure/&ts=markdown) \[\](mailto:?subject=Turning Cellular into Secure Transport for Critical Infrastructure) Link copied By [Mitch Rappard](https://www.paloaltonetworks.com/blog/author/mitch-rappard/?ts=markdown "Posts by Mitch Rappard") Aug 22, 2026 6 minutes [5G Security](https://www.paloaltonetworks.com/blog/network-security/category/5g-security/?ts=markdown) [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown) [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown) [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) *Security and Identity for a Cellular Access Network* Author: Mario Penner Utility providers operate tens or even hundreds of thousands of field devices, including meters, reclosures, operational technology, IT systems, surveillance equipment, and sensors at remote sites. Given the wide operational geography, cellular technology such as private LTE and 5G is proving to be the ideal access network to consolidate communications. However, many of these devices do not have their own SIM card or cellular interface and achieve connectivity through cellular routers. This approach solves the connectivity problem very well, but it also introduces new architectural questions that directly impact security: endpoint identity, device-level visibility, carrier dependency, IP planning, and operational scale. Some of the key challenges with cellular field connectivity - with or without private APN - are the following: 1. **Lack of Visibility** Often the network owner lacks visibility into the devices and the traffic they send. If multiple devices are present, this challenge is especially difficult to solve since the wireless router often NATs all the traffic. 2. **Limited or no threat prevention** In order to adhere to Zero Trust best practices, we must continuously monitor the traffic traversing the network, especially traffic from critical assets. Often organizations use firewalls to help with the security of traffic to and from these wireless routers, but lack comprehensive defense against known and unknown malware, malicious DNS queries or attacks, malicious URLs and other related threats. 3. **SIMs and carrier IPs are not enough as endpoint identity:** A SIM, APN, or carrier-assigned IP connects the router, but it may change or be spoofed and can therefore not be used as solid proof of identity. Instead, an inseparable identity criterion tightly bound to the box is needed. 4. **Carrier design can become carrier lock-in** Utility IT departments need to coordinate address ranges, routing, private APNs, NAT behavior, redundancy, and failover with each carrier. Different carriers may not offer the same design, coverage, availability, or private addressing models. And private APNs have a cost. Changing carriers or adding a second SIM does not become a network redesign but a simple, transparent transport change. 5. **Manual security does not scale** In cases where VPNs are used, per-router VPN settings, certificates, tunnel status, routes, renewals, revocation, and firewall policy cannot be handled manually across thousands of field routers. Either operations would slow down, or teams fall back to shared secrets, inconsistent templates, or stale configuration. ## **The Solution: A VPN Overlay -- Make Cellular the Transport, Not the Architecture** The separation of concerns seems natural: Cellular providers supply radio access and transport, the utility owns the end to end traffic. To achieve this, the architecture uses identity-bound secure access: a certificate-based IPSec VPN approach that makes cellular the transport layer, while the utility keeps control of identity, addressing, segmentation, visibility, and security policy. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/06/Semtech-IPSec-JSB-Jun2026-scaled.png) By abstracting field connectivity from the underlying cellular carrier, the architecture delivers the following benefits to utility providers: 1. **Comprehensive visibility.** As the architecture above shows, traffic is sent to a centralized NGFW for IPSec tunnel termination and traffic inspection. Using App-ID, the NGFW helps verify valid traffic is sent to and from the connected devices. Any anomalous traffic can be alerted on so that no spurious devices or traffic are on the network. 2. **AI-enabled threat prevention. Operational Technology (OT) traffic is secured by products powered by [Precision AI](https://www.paloaltonetworks.com/precision-ai-security)® , our proprietary AI system that blends machine learning, deep learning, and generative AI to deliver autonomous, real-time protection. Precision AI technologies are built directly into the Next-Generation Firewalls (NGFW), this AI-driven approach provides non-intrusive, passive discovery to analyzing behavior rather than relying solely on static signatures. Precision AI technologies enable inline prevention of zero-day attacks and evasive command-and-control (C2) threats targeting cyber-physical systems** . 3. **Identity-driven router authentication.** The IPSec endpoints are not trusted merely because traffic came from a certain carrier IP address. A SIM could be moved and an IP address could change or be spoofed. Fully automated Certificate enrollment based on protocols like EST (Enrollment over Secure Transport) ties the router HW to the identity of the box: The issued certificate is inseparably bound to the router's serial number, and the VPN uses that certificate to identify the specific router --- independent of SIM, carrier, or IP address. 4. **Carrier independent IP planning.** The cellular connection can use whatever carrier IP, SIM, APN, or mobile network is available. Inside the IPSec tunnel, the utility preserves its own end-to-end addressing plan for the actual devices behind the router. A router can use one carrier, change carrier, or use multiple SIMs for redundancy, while application traffic and security policy between field devices and the data center remain unchanged. ## **Lower Opex, Better Control and Stronger Security by Automation** This architecture pays back operationally. It reduces carrier dependency, manual configuration, troubleshooting effort, and the risk of inconsistent security design. The main operational benefits are: * **Granular application control and threat prevention:** Every protocol can be dissected and individual message types be blocked or allowed only in one direction. Threats like message-floods, exploits or malicious traffic are detected at one central point. * **Carrier changes become transport changes:** A new SIM, carrier, or mobile-side IP address does not require the utility to redesign its field addressing or security policy, private APNs are not a requirement for end-to-end IP-planning. * **Less manual configuration means fewer errors:** Routers enroll automatically, receive the right configuration, build the VPN presenting the correct identity without field teams manually handling secrets or tunnel parameters. * **Certificate lifecycles are manageable:** Certs can be issued, renewed, revoked, and tracked through enrollment records, revocation lists and online status checks * **Troubleshooting becomes easier:** Operations teams can distinguish between carrier transport issues, router issues, endpoint issues, and application/security policy issues. A VPN from the cellular modem/router to the utility data center is therefore not just encryption. It gives the utility a controlled architecture where identity, visibility, segmentation, application inspection, and operations are managed independently of the carrier network while allowing the utility to focus on its core mission of delivering safe, reliable, and efficient power while maintaining complete ownership and security of its operational data. For an example of a joint solution leveraging the technology above, check out our [Joint Solution Brief](https://technologypartners.paloaltonetworks.com/English/listing/semtech) with Semtech Corporation and their Airlink routers. *** ** * ** *** ## Related Blogs ### [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [SD-WAN](https://www.paloaltonetworks.com/blog/sase/category/sd-wan/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown) [#### The CISO's Guide to SD-WAN Controller Security: Why Architecture is Your Top Risk](https://www2.paloaltonetworks.com/blog/sase/the-cisos-guide-to-sd-wan-controller-security-why-architecture-is-your-top-risk/) ### [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### The Dangerous Momentum of Autodownload Phishing](https://www2.paloaltonetworks.com/blog/2026/05/dangerous-momentum-autodownload-phishing/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Defender's Guide to the Frontier AI Impact on Cybersecurity](https://www2.paloaltonetworks.com/blog/2026/04/defenders-guide-frontier-ai-impact-cybersecurity/) ### [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Why Your EDR Strategy Needs a Backup Plan](https://www2.paloaltonetworks.com/blog/security-operations/why-your-edr-strategy-needs-a-backup-plan/) ### [Industrial OT Security](https://www.paloaltonetworks.com/blog/network-security/category/industrial-ot-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing OT Infrastructure: 10 Transformative Use Cases](https://www2.paloaltonetworks.com/blog/network-security/securing-ot-infrastructure-10-transformative-use-cases/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Points of View](https://www.paloaltonetworks.com/blog/category/points-of-view/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Ransomware Attacks: Why Your Endpoint Protection Can't Keep Up](https://www2.paloaltonetworks.com/blog/security-operations/ransomware-attacks-why-your-endpoint-protection-cant-keep-up/) ### Subscribe to Network Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www2.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language