SIMSY + VPN | Keep your VPN, drop the public entry point | SIMSY Developers
Back to tools
SIMSY + VPN

Carry your existing VPN across a SIMSY network

SIMSY carries whatever VPN you already operate — IPSec, OpenVPN, or a vendor concentrator you have run for years. Your SIMs reach the gateway through our private breakout, so the concentrator can listen on a private address inside your network and the connection remains inside a path you already trust.

Your VPN, delivered over a private path

SIMs reach the concentrator you already run

Point the SIMs at the address of your existing VPN concentrator, and their traffic reaches it through the SIMSY private breakout. Your gateway carries on doing exactly what it does today, on the same address, for the same clients.

The concentrator listens on a private address

Because the concentrator receives its cellular clients over the private breakout, it can live on a private IP inside your network. The internet-facing surface it presented before becomes optional.

Traffic is private end to end

Devices reach the concentrator through the SIMSY core, so authentication, key exchange and every packet after them stay inside a path you control. The device is off the public internet from the moment it attaches.

Your existing tooling continues to apply

The concentrator, client software, policy engine and audit trail all keep working the way they do today. This is a routing addition, not a migration.

Three steps to a working integration

  1. STEP 01

    Add a private listener on your concentrator

    Use the existing private interface if there is one, or add a listener on the interface that faces your SIMSY breakout. The public listener stays exactly as it is, running in parallel while you prove the private path.

  2. STEP 02

    Add a routing policy on SIMSY

    Create a routing policy that allows traffic from the SIM group to the concentrator's private address, with default-deny for everything else. From this point on, the SIM group speaks only to your VPN.

  3. STEP 03

    Cut the public listener when you are ready

    Once devices are authenticating cleanly through the private breakout, take the concentrator's public interface off the internet at a moment of your choosing. The VPN itself carries on unchanged, now scoped to your own network.

route-via-vpn.py (illustrative)
# Illustrative - see API reference for current endpoints
import simsy

client = simsy.Client("your-api-key")

# Create a routing policy that sends this SIM's traffic to your
# concentrator's private address (not a public one). The route
# lives inside the SIMSY core.
policy = client.create_routing_policy(
    name="via-corp-vpn",
    default_egress="deny",
    routes=[
        {
            "dest_cidr": "10.20.0.10/32",   # your concentrator, private IP
            "action":    "allow",
        },
    ],
)

# Attach the policy to an endpoint group so every SIM in that
# group breaks out through the concentrator rather than to the
# open internet.
client.set_endpoint_group_policy(
    endpoint_group="corp-devices-uk",
    policy_id=policy.id,
)

The exact API surface is placeholder while the SIMSY routing endpoints stabilise. The shape (policy, dest CIDR, endpoint group) reflects how the finished endpoints will read.

Works with whatever concentrator you already run

The pattern above is protocol-agnostic. Any concentrator that speaks a routable protocol on a listen-only port fits, and the four we see most often are:

IPSec (IKEv2)

The corporate default in a lot of estates. Point the SIM-side client at the concentrator's private address; certificates and phase-1 settings are unchanged.

OpenVPN

Popular for mixed fleets where clients are already installed on the endpoints. Same pattern: private listener, allow-list the CIDR in your SIMSY policy.

L2TP / PPTP (legacy)

Older estates still run these. They work end-to-end on SIMSY; whether you keep them is a separate conversation about the crypto.

Vendor-specific (Cisco AnyConnect, Fortinet, etc.)

The concentrator is the same appliance you already run. All SIMSY changes is the address the SIM dials.

Design decisions to fit into your set up.

Run public and private listeners in parallel

Keep the existing public listener running while SIMs move onto the private breakout. Once every fleet you care about is proven on the private path, retire the public interface at a moment of your choosing.

Refresh client configs on the cutover

VPN clients often cache the concentrator address. Push a config update through the tooling you already use, so every device points at the private endpoint on next connect.

MTU tuning on the tunnel interface

VPN overhead plus cellular MTU makes explicit tunnel MTU (or DF-clear) worthwhile. A short latency-sensitive test on the way in makes the numbers you settle on stick.

Auth path stays inside your network

If the concentrator authenticates via RADIUS or a directory on another subnet, keep that subnet reachable from the concentrator across the same private path. The SIMSY breakout carries the tunnel, not your internal routing.

Try it against your existing concentrator.

Get a Launch SIM, add a routing policy pointing at the private address of your VPN gateway, and connect. The public listener stays up while you confirm; once you are happy, retire it.

Works with any concentrator-based VPN