Turning Cellular into Secure Transport for Critical Infrastructure

Aug 22, 2026
7 minutes

Security and Identity for a Cellular Access Network

Author: Mario Penners, Mitch Rappard

Utility providers operate tens or even hundreds of thousands of field assets — meters, reclosers, operational technology, IT systems, surveillance equipment, and sensors — spread across vast geographies. Connecting and securing these devices reliably, at scale, requires solving two distinct problems.

Cellular technology such as private LTE and 5G has emerged as the ideal access network to consolidate communications. However, most existing field devices were not built with cellular connectivity in mind and lack a native SIM card or cellular interface. For this reason, mission-critical organizations have increasingly turned to Semtech® AirLink® routers to enable devices to connect over cellular networks.

Operating cellular infrastructure across thousands of endpoints, however, introduces a distinct set of architectural considerations — from endpoint identity and visibility into the traffic flowing through those devices, to carrier dependency, IP planning, and operational scale. With or without a private APN, these gaps need to be addressed:

  1. Lack of visibility

While cellular routers provide their own management and visibility at the device level, the field devices operating behind them and the traffic they generate are often opaque to the network owner. This challenge is compounded when multiple devices share a single router, as all their traffic appears to come from a single source.

  1. Limited or no threat prevention

Zero Trust pillars demand that no device or connection be implicitly trusted, require continuous monitoring and learning, and use the strongest available protection for communications.  Often organizations use firewalls to aid in the security of traffic to and from cellular routers, but lack comprehensive network defense against known and unknown malware, malicious DNS queries or attacks, malicious URLs, and other related threats. 

  1. SIMs, private APN and carrier IPs do not ensure endpoint identity, confidentiality or data integrity

Zero Trust pillars also guide that resources, or field asset devices in the case of a Utility, must be properly identified before network access is granted.  A SIM, APN, or carrier-assigned IP connects the cellular router, but each can change or be spoofed and therefore cannot serve as reliable proof of identity. Private APNs help with security, but do not guarantee data integrity and confidentiality.

  1. Carrier design can become carrier lock-in

Utility IT departments need to coordinate address ranges, routing, private APNs, NAT behavior, redundancy, and failover with each carrier. Different carriers may not offer the same design, coverage, availability, or private addressing models, and multiple private APNs drive a higher operational cost.

What’s more, changing carriers or adding a second carrier, should not require a network redesign – it should be a simple, transparent transport change.

  1. Manual security does not scale

Managing VPN settings, certificates, tunnel status, routes, renewals, revocation, and firewall policy manually across thousands of field routers is not operationally viable. Either operations slow down, or teams revert back to shared secrets, inconsistent templates, or static layer 3-based firewall policies – each of which introduces its own security risk. 

The Solution: Make Cellular the Transport, Not the Architecture

The separation of concerns seems natural: Cellular providers supply radio access and transport, while the Utility owns the end-to-end traffic. This is achieved by using identity-bound secure access: a certificate-based IPSec VPN approach that allows the cellular network to simply act as the transport layer. The established VPN enables the Utility to retain full control of identity, addressing, segmentation, visibility, and security policy.  

Semtech AirLink cellular routers support the EST (Enrollment over Secure Transport) protocol, enabling fully automated certificate enrollment at scale through Palo Alto Networks PKI solutions – eliminating manual configuration, and ensuring every cellular router is provisioned with a verified, hardware-bound identity.

Unified Zero Trust Edge-to-Cloud Security
Unified zero trust edge to cloud security with Semtech airlink routers and palo alto networks next generation firewalls and PKI certificate lifecycle management.

By decoupling field connectivity from the underlying cellular carrier, the architecture delivers the following benefits to utility providers:

  1. Comprehensive visibility. All traffic is routed through a centralized NGFW for IPSec tunnel termination and traffic inspection.  Using Palo Alto Networks-patented App-ID the NGFW continuously monitors, identifies, and enforces security policies ensuring only valid traffic is sent to and from the connected devices and networks.  Various actions can be taken on any anomalous traffic to ensure no spurious devices or traffic are on the network.
  2. AI-enabled threat prevention. Operational Technology (OT) traffic is secured through Palo Alto Networks Precision AI™ engine, a system that blends machine learning, deep learning, and generative AI to deliver autonomous, real-time protection. Built directly into Palo Alto Networks Next-Generation Firewalls (NGFW), this AI-driven approach analyzes behavior rather than relying solely on static signatures, providing non-intrusive, passive discovery of threats.  Precision AI enables inline prevention of zero-day attacks, evasive command-and-control (C2) threats and other threats targeting cyber-physical systems.
  3. Identity-driven device authentication at scale. The AirLink router’s IPSec connection is not trusted merely because traffic comes from a certain IP address range, or has a utility-issued SIM card. A SIM could be moved and an IP address could change or be spoofed. Fully automated Certificate enrollment based on protocols like EST (Enrollment over Secure Transport) ties the AirLink cellular router HW to the identity of a certificate. The issued certificate is bound to the router’s serial number, and the VPN uses the certificate to provide a source identity for the specific AirLink cellular router – independent of SIM, carrier, or IP address.
  4. Network independent IP planning. Inside the IPSec tunnel, the utility preserves its own end-to-end addressing plan for the actual devices behind the AirLink cellular router. An AirLink cellular router can use one carrier, change carriers, or use multiple SIMs for redundancy, while application traffic and security policy between field devices and the data center remain unchanged. 

Because AirLink cellular routers have built-in WAN selection intelligence, the connectivity story does not end with cellular. Fixed copper, fiber, and/or satellite-based transports can be seamlessly layered alongside cellular for resiliency, while the architecture, traffic, and security policies remain completely unchanged. 

Operational Benefits: Control, Security and Scale through Automation 

Together, these capabilities reduce carrier dependency, manual configuration, troubleshooting effort, and the risk of inconsistent security design – delivering operational value at scale.

  • Granular application control and threat prevention: Every protocol can be dissected and individual message types can be blocked or allowed in either traffic direction. Once an application or protocol is allowed, it is further inspected with Content-ID to identify and prevent threats like message-floods, exploits or malicious traffic.
  • Carrier changes become transport changes: A new SIM, carrier, or mobile-side IP address does not require the utility to redesign its field addressing or security policy.   New or existing private APNs will not dictate end-to-end IP planning.
  • Less manual configuration means fewer errors: Routers enroll automatically, receive the correct configuration, and establish the VPN using a verified identity - without field teams manually handling keys, secret credentials, or tunnel parameters.
  • Certificate lifecycle management at scale: Certificates can be issued, renewed, revoked, and tracked through enrollment records, revocation lists and online status checks, with the AirLink Management System (ALMS) providing centralized orchestration and lifecycle management across tens of thousands of field routers.
  • Simplified troubleshooting: Operations teams can distinguish between carrier transport issues, router issues, endpoint issues, and application or security policy issues – reducing mean time to resolution.

A VPN from the AirLink cellular router to the utility data center is more than encryption – this Semtech AirLink + Palo Alto Networks solution gives the utility a controlled architecture where identity, visibility, segmentation, application inspection, and operations are deployed and managed efficiently, and reliably, independent of the carrier network. This frees utility providers to focus on their core mission: delivering safe, reliable, and efficient power with complete ownership and security of its operational data.

To see the Airlink networking solution and NGFW architecture in action, explore the Joint Solution Brief from Semtech Corporation and Palo Alto Networks.


Subscribe to Network Security Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.