What you’d build without Virtual Private Gateway | Deploy carrier-managed private APNs Build your own IPsec concentrators and network edge Expose devices to the public internet |
A dedicated private gateway for secure device communication, isolating IoT traffic from the public internet.
Soracom Virtual Private Gateway (VPG) creates an isolated network environment where your IoT devices communicate privately with your cloud or data center. Instead of relying on public internet paths, VPG enables private routing, custom IP address management, and enterprise-grade security controls—all built on Soracom’s cloud-native mobile core.
VPG extends your private network to your IoT devices by routing traffic through an isolated, virtualized gateway inside Soracom’s cloud-native core. You can assign private IP ranges, enforce firewall rules, and deliver traffic to AWS VPCs, on-prem systems, or secure tunnels without exposing devices to the public internet. VPG supports both NAT and NAT-less configurations, integrates seamlessly with IPSec VPN and VPC peering, and treats each SIM as part of your private infrastructure—no private APN or physical network equipment required.
Keep data off the public internet and route it securely into your private environment.
Replace complex private APNs and carrier hardware with a cloud-native private gateway.
Connect devices directly to VPCs, datacenters, or secure tunnels with flexible routing.
Each VPG provides an isolated network environment, complete with dedicated routing, firewall rules, and private IP address ranges. Devices assigned to a VPG operate as if they’re on your internal network—secured and unexposed—while still leveraging the flexibility of Soracom’s cellular core.
VPG supports IPsec VPN, AWS VPC Peering, AWS Transit Gateway, and private fiber connections. Whether you’re using AWS, Azure, GCP, or an on-prem data center, VPG routes device traffic without touching the public internet.
Choose NAT routing for simplicity, or NAT-less routing when you want full bidirectional communication and consistent IP address identity per device. This gives you granular control over access policies, logging, and backend visibility.
Keep all device traffic private and isolate fleets in their own controlled environment.
Remove the cost and complexity of private APNs and hardware-based VPN appliances.
Deliver device traffic directly into your cloud infrastructure with consistent, predictable routing.
What you’d build without Virtual Private Gateway | Deploy carrier-managed private APNs Build your own IPsec concentrators and network edge Expose devices to the public internet |
Virtual Private Gateway is built directly into Soracom’s cloud-native mobile core, allowing you to define private IP ranges, route traffic to cloud environments, and isolate subsets of your fleet. VPG supports NAT and NAT-less routing, multiple secure transport methods, and scales automatically across regions. Devices join the VPG when assigned at the SIM group level, inheriting its routing, security, and monitoring configuration.
Open the Soracom User Console and create a new Virtual Private Gateway (VPG) or select an existing one.
Choose the VPG type and configure options such as private IP ranges, routing behavior, firewall rules, and cloud connectivity settings.
The VPG acts as your private network anchor within Soracom, providing isolated routing for devices without exposing them to the public Internet.
Setup instructions are available in the Virtual Private Gateway documentation.
Navigate to the SIM group that contains the devices you want to place inside the private network and attach it to the VPG you created.
Once attached, all data traffic from devices in this group is routed through the VPG rather than through Soracom’s default public breakout.
This enables private connectivity patterns, including NAT-less routing, controlled egress, and secure integration with other Soracom services like Gate, Canal, or Direct.
Group attachment steps are detailed in the VPG group assignment guide.
Complete your private network by connecting the VPG to your cloud VPC or on-premises environment using options such as VPC Peering, IPsec VPN, or Direct for physical network extensions.
This connection allows your backend systems to communicate with devices using private IPs, without public exposure and without requiring a static IP on the device side.
Once connected, you can access devices, route data, or build end-to-end private architectures securely through the VPG.
Connectivity options are described in the VPG connectivity guide.
What you’d build without Virtual Private Gateway | Deploy carrier-managed private APNs Build your own IPsec concentrators and network edge Expose devices to the public internet |