Private APN and IPsec VPN Architectures for Distributed Water Utility RTU Networks
- Why Modbus traffic needs the network to do the work
- Four ways to build the link
- What IPsec actually provides
- Designing the private APN side
- Remote maintenance without opening the network
- Resilience and field cost
- How this maps to Quanqiu IoT
- FAQ
- Is a private APN secure enough without IPsec?
- Should IPsec terminate on the RTU or on a router?
- Can we use Modbus/TCP Security instead of a VPN?
- How much extra data does IPsec use?
- What should we ask an operator about a private APN?
- Official References
- Lecturas relacionadas
Definition: A private APN with IPsec gives water utility RTUs a cellular path that bypasses the public internet: the APN restricts where traffic can go, and IPsec encrypts and authenticates it between the field router and the SCADA network.
For a utility with dozens or hundreds of pump stations, reservoirs and pressure-monitoring sites, the usual recommendation is to use both layers. A private APN alone separates traffic from the internet but leaves it unencrypted across the operator network and the interconnect to your control center. IPsec alone can work on a public APN, but every RTU router then has an internet-reachable address to defend. Together they give a closed routing domain plus cryptographic protection, which suits Modbus and other legacy protocols that carry no security of their own.
Why Modbus traffic needs the network to do the work
Classic Modbus TCP on port 502 has no authentication or encryption. Any host that can reach an RTU on that port can read registers and, if the device allows it, write coils and setpoints. The Modbus Organization’s Modbus/TCP Security specification addresses this by wrapping Modbus in TLS on port 802, requiring TLS 1.2 or later, mutual authentication with X.509v3 certificates and an optional role extension in the certificate that the device can use for authorization.
That is the right long-term direction, but most installed RTUs and PLCs in water networks do not support it, and replacing field hardware takes years. Until then, the cellular design has to stop unauthorized hosts from reaching port 502 at all.
Four ways to build the link
| Architecture | Internet exposure of RTU routers | Encryption across operator and interconnect | Operational effort | Typical fit |
|---|---|---|---|---|
| Public APN, port forwarding to RTU | High | None for plain Modbus | Low at first, high once incidents start | Not recommended for control systems |
| Public APN plus IPsec from each router | Router reachable, only VPN ports open | Yes, end to end between router and headend | Moderate: certificates or keys per site | Small networks or where a private APN is unavailable |
| Private APN only | None from the internet | No; traffic is isolated but not encrypted | Moderate: APN setup and IP plan with the operator | Telemetry with low sensitivity |
| Private APN plus IPsec | None from the internet | Yes | Highest setup, simplest to audit | SCADA and remote control of critical assets |
What IPsec actually provides
RFC 4301 defines the IPsec security architecture. Each router keeps a Security Policy Database that decides, per traffic selector, whether packets are protected, bypassed or discarded, and a Security Association Database holding the keys and parameters for each protected flow. For site-to-control-center links, ESP in tunnel mode is the usual choice: it encrypts and authenticates the original IP packet and adds a new outer header. Keys are normally negotiated with IKEv2.
Two practical details catch field teams. First, ESP tunnel mode adds header, padding and integrity-check bytes to every packet, and if the router sits behind carrier NAT, UDP encapsulation on port 4500 adds a little more. Set the tunnel MTU or TCP MSS clamping so Modbus frames are not fragmented. Second, dead peer detection and rekeying generate traffic of their own. On low-volume sites that overhead can be a noticeable share of the monthly data, so include it in the plan sizing.
Designing the private APN side
With a private APN, the operator routes sessions on that APN to your network rather than to the internet, usually through a dedicated interconnect or a VPN between the operator core and the utility’s data center. Points to settle with the operator and your integrator:
- Addressing. Static IP addresses per SIM simplify SCADA polling and firewall rules. Agree the address plan early so it does not clash with plant networks.
- Device-to-device traffic. Decide whether RTUs may talk to each other inside the APN. For most utilities the answer should be no; all traffic goes to the control center.
- Authentication. Some private APNs add RADIUS or username checks on top of the SIM, which helps if a SIM is removed from a router and used elsewhere.
- Interconnect redundancy. One interconnect to one data center is a single point of failure. Ask how the path fails over, whether a second data center or a backup VPN is supported, and what SLA, if any, covers the interconnect.
Remote maintenance without opening the network
Integrators and RTU vendors need access during system integration and later for configuration and fault-finding. Do not give them their own path into the APN. Route maintenance through a jump host or remote-access gateway in the control center, with named accounts, multi-factor authentication, time-limited sessions and recording. This keeps a clear boundary between operation and maintenance and gives you a log when something changes on a pump controller. Our guide to Modbus TCP security segmentation and remote maintenance goes deeper into this pattern.
Resilience and field cost
Water sites are often unmanned and far apart, so a lost link can mean a truck roll just to power-cycle a router. Use routers with hardware watchdogs and VPN health checks that restart the tunnel automatically. For critical sites, consider a dual-SIM router with failover to a second operator; note that the backup SIM needs its own APN arrangement, or the IPsec tunnel must be able to run over a public APN as a fallback. Test the failover at a real site before standardizing it.
How this maps to Quanqiu IoT
The utility-specific operations side is covered in our guides to Modbus water utility RTU maintenance windows and alarm backhaul and DNP3 RTUs and utility SCADA links. Router selection is in IoT SIM for industrial routers, RTUs and DTUs, and the smart city and utilities scenario page lists related use cases.
A Global IoT SIM from the catalog is fine for testing a router and tunnel design on a public APN, and the CMP shows data per SIM so you can measure tunnel overhead during the pilot. Private APN, static addressing and interconnect options vary by operator and country, so they are confirmed during project validation rather than assumed. For procurement, the site count, data per site, target regions, phased rollout plan and the need for a private APN or dual-SIM failover all shape the commercial model. Once the design is settled, request a project quote with those details and a short description of the SCADA deployment.
FAQ
Is a private APN secure enough without IPsec?
It removes internet exposure, which is the biggest single risk. It does not encrypt traffic, and it does not guarantee that only your devices are inside the APN if a SIM is misused. For SCADA and control traffic, adding IPsec or another authenticated, encrypted tunnel is the safer baseline.
Should IPsec terminate on the RTU or on a router?
Usually on the cellular router in front of the RTU. Few RTUs implement IPsec, and terminating on the router keeps key management in one type of device across the fleet.
Can we use Modbus/TCP Security instead of a VPN?
Where both the RTU and the SCADA master support it, it adds authentication and encryption at the protocol level. Most utilities will run mixed fleets for years, so network-level protection is still needed for the devices that cannot use it.
How much extra data does IPsec use?
It depends on packet sizes, polling frequency, keep-alive and rekey intervals. Measure tunnel overhead on a pilot site for a few weeks and size plans from those figures.
What should we ask an operator about a private APN?
Ask about static IP support, interconnect options and redundancy, whether device-to-device traffic can be blocked, lead time to set up, and how SIMs are added to or removed from the APN.