Terminate WireGuard inside your network
Run WireGuard between SIMSY SIMs and your infrastructure with addressing you define. SIMSY assigns each SIM a private address from a range you nominate, and terminates the tunnel directly against a peer running inside your own network. The pattern is small, fast and comfortable on cellular hardware.
Key advantages of our WireGuard integration.
SIMs come up on addressing you defined
Each SIM receives an IP from a range you pick, so the WireGuard config on either end refers to addresses that already make sense inside your estate. Every deployment sits inside a subnet plan you designed.
Direct routing to your peer
Your WireGuard peer lives on a private address inside your network, and SIMs reach it directly across the SIMSY core. The path is one hop end to end, with no relay or traversal step in the middle.
Your peer stays on a private address
The peer listens on the private breakout and is reachable only from your own SIMs. The wider internet has no way to see it, so the connection remains scoped to the estate that authored it.
Fits the hardware you already run
A small VM, an existing router that speaks WireGuard, or a physical box in your rack all work as the peer. The pattern adapts to whatever your infrastructure already looks like.
Three steps to a working integration
- STEP 01
Bring up a WireGuard peer on your side
On a small VM, an existing router that speaks WireGuard, or a box in your rack. Give it a private address inside your network and generate a key pair. It does not need a public address; it will only ever be reached from your SIMs.
- STEP 02
Register the integration with SIMSY
Create a WireGuard integration on your tenant, pointing at your peer's private endpoint and holding its public key. Decide the address pool SIMSY will allocate SIMs from — any RFC1918 range that does not clash with your existing addressing plan.
- STEP 03
Attach SIMs to the integration
One SIM, or a whole endpoint group. SIMSY generates a per-SIM key pair, provisions the SIM side, and hands you a peer config block to add to your server. Additions and removals are API calls after that.
# Illustrative - see API reference for current endpoints
import simsy
client = simsy.Client("your-api-key")
# Create a WireGuard integration for your tenant. SIMSY holds the SIM
# side of the key pair per SIM; you hold the server key pair.
wg = client.create_wireguard_integration(
name="fleet-vpn",
server_public_key=open("wg-server.pub").read().strip(),
server_endpoint="10.44.0.1:51820", # private address in your network
allowed_ips="10.44.0.0/24",
)
# Attach a SIM (or an endpoint group) to the integration. SIMSY
# provisions the SIM's wg config on next attachment.
client.attach_sims_to_wireguard(
integration_id=wg.id,
endpoint_group="edge-fleet-uk",
address_pool="10.44.0.0/24", # SIMSY hands each SIM a /32 in this range
)
# Pull the peer blocks to paste into wg0.conf (or write to your
# config management pipeline).
for peer in client.list_wireguard_peers(wg.id):
print(peer.to_config_block())
# /etc/wireguard/wg0.conf — peer running inside your network. # Listens on your private breakout IP, not a public one. Only SIMs # on your tenant can reach it. [Interface] PrivateKey = <server-private-key> Address = 10.44.0.1/24 ListenPort = 51820 # One peer per SIM. Public keys are generated when you provision # the SIM through the SIMSY API; a fleet-wide script pulls them # from your tenant and emits this block. [Peer] # sim: iccid 8944...001 PublicKey = <sim-public-key-1> AllowedIPs = 10.44.0.2/32 [Peer] # sim: iccid 8944...002 PublicKey = <sim-public-key-2> AllowedIPs = 10.44.0.3/32
The SIMSY method names and payloads are placeholders while the integration API stabilises. The shape (integration, address pool, per-SIM peer blocks) reflects how the finished endpoints will read.
Design decisions to fit into your set up.
MTU on cellular
WireGuard adds 60 bytes of overhead, which lands the tunnel interface at 1420 on a standard 1500-byte cellular MTU. Setting MTU=1420 explicitly on both ends gives you a predictable path across every carrier the SIM might roam onto.
Persistent keepalive
Cellular NAT bindings refresh at different intervals on different networks. A PersistentKeepalive of 25 seconds on the SIM side keeps the tunnel warm and reachable across the estate, without the device having to reconnect first.
Address pool sizing
A pool sized for growth up front saves renumbering later. A /24 covers 254 SIMs comfortably; a /16 covers a full fleet with room for regional structure. Pick something that fits your existing plan and leave headroom.
Key rotation
SIMSY rotates the SIM-side key on request and hands you the new peer block to swap in. Rotate the server-side key the way you do for the rest of your infrastructure, and SIMs pick up the new server key on next config sync.
Try it end to end.
Get a Launch SIM, stand a WireGuard peer up on a small VM, attach the SIM, and reach the VM by its private address from the SIM. All of it inside your own network, none of it on the public internet.
Works with any WireGuard-compatible peer