Carry your existing VPN across a SIMSY network
SIMSY carries whatever VPN you already operate — IPSec, OpenVPN, or a vendor concentrator you have run for years. Your SIMs reach the gateway through our private breakout, so the concentrator can listen on a private address inside your network and the connection remains inside a path you already trust.
Your VPN, delivered over a private path
SIMs reach the concentrator you already run
Point the SIMs at the address of your existing VPN concentrator, and their traffic reaches it through the SIMSY private breakout. Your gateway carries on doing exactly what it does today, on the same address, for the same clients.
The concentrator listens on a private address
Because the concentrator receives its cellular clients over the private breakout, it can live on a private IP inside your network. The internet-facing surface it presented before becomes optional.
Traffic is private end to end
Devices reach the concentrator through the SIMSY core, so authentication, key exchange and every packet after them stay inside a path you control. The device is off the public internet from the moment it attaches.
Your existing tooling continues to apply
The concentrator, client software, policy engine and audit trail all keep working the way they do today. This is a routing addition, not a migration.
Three steps to a working integration
- STEP 01
Add a private listener on your concentrator
Use the existing private interface if there is one, or add a listener on the interface that faces your SIMSY breakout. The public listener stays exactly as it is, running in parallel while you prove the private path.
- STEP 02
Add a routing policy on SIMSY
Create a routing policy that allows traffic from the SIM group to the concentrator's private address, with default-deny for everything else. From this point on, the SIM group speaks only to your VPN.
- STEP 03
Cut the public listener when you are ready
Once devices are authenticating cleanly through the private breakout, take the concentrator's public interface off the internet at a moment of your choosing. The VPN itself carries on unchanged, now scoped to your own network.
# Illustrative - see API reference for current endpoints
import simsy
client = simsy.Client("your-api-key")
# Create a routing policy that sends this SIM's traffic to your
# concentrator's private address (not a public one). The route
# lives inside the SIMSY core.
policy = client.create_routing_policy(
name="via-corp-vpn",
default_egress="deny",
routes=[
{
"dest_cidr": "10.20.0.10/32", # your concentrator, private IP
"action": "allow",
},
],
)
# Attach the policy to an endpoint group so every SIM in that
# group breaks out through the concentrator rather than to the
# open internet.
client.set_endpoint_group_policy(
endpoint_group="corp-devices-uk",
policy_id=policy.id,
)
The exact API surface is placeholder while the SIMSY routing endpoints stabilise. The shape (policy, dest CIDR, endpoint group) reflects how the finished endpoints will read.
Works with whatever concentrator you already run
The pattern above is protocol-agnostic. Any concentrator that speaks a routable protocol on a listen-only port fits, and the four we see most often are:
IPSec (IKEv2)
The corporate default in a lot of estates. Point the SIM-side client at the concentrator's private address; certificates and phase-1 settings are unchanged.
OpenVPN
Popular for mixed fleets where clients are already installed on the endpoints. Same pattern: private listener, allow-list the CIDR in your SIMSY policy.
L2TP / PPTP (legacy)
Older estates still run these. They work end-to-end on SIMSY; whether you keep them is a separate conversation about the crypto.
Vendor-specific (Cisco AnyConnect, Fortinet, etc.)
The concentrator is the same appliance you already run. All SIMSY changes is the address the SIM dials.
Design decisions to fit into your set up.
Run public and private listeners in parallel
Keep the existing public listener running while SIMs move onto the private breakout. Once every fleet you care about is proven on the private path, retire the public interface at a moment of your choosing.
Refresh client configs on the cutover
VPN clients often cache the concentrator address. Push a config update through the tooling you already use, so every device points at the private endpoint on next connect.
MTU tuning on the tunnel interface
VPN overhead plus cellular MTU makes explicit tunnel MTU (or DF-clear) worthwhile. A short latency-sensitive test on the way in makes the numbers you settle on stick.
Auth path stays inside your network
If the concentrator authenticates via RADIUS or a directory on another subnet, keep that subnet reachable from the concentrator across the same private path. The SIMSY breakout carries the tunnel, not your internal routing.
Try it against your existing concentrator.
Get a Launch SIM, add a routing policy pointing at the private address of your VPN gateway, and connect. The public listener stays up while you confirm; once you are happy, retire it.
Works with any concentrator-based VPN