How to Verify a Fixed-IP SIM Reaches Your SCADA Host
A fixed-IP SIM is meant to give a gateway a known, unchanging address so your host can find it and your firewall rules can trust it, but a fixed IP that is assigned on paper and not actually routed is a common and confusing failure. Verifying it means confirming the address the gateway holds matches the one on record, and that traffic actually flows both ways between the gateway and your host. This procedure is for the technician commissioning or troubleshooting a fixed-IP site where the address looks right but nothing connects.
Verify a fixed-IP SIM reaches your SCADA host in one line: To verify a fixed-IP SIM reaches your SCADA host, confirm the gateway holds the exact address on record, prove the route in both directions between the gateway and the host, and check the firewall rules along the path that reference that fixed address. A correct address that cannot be reached usually means a routing or firewall gap between the carrier's network and your host, not a bad SIM.
Confirm the Assigned Address Matches the Record
Read the address the gateway actually holds from its cellular status page and compare it exactly to the fixed address on record for that SIM. A fixed-IP arrangement only works if the gateway receives the specific address you documented, and a mismatch means either the wrong SIM is in the device or the provisioning assigned a different address than you think. The purpose of the arrangement is described in the guide to a fixed-IP SIM, and confirming the SIM is on the private path at all is the subject of verifying private-APN connectivity.
If the address is wrong, stop and fix the provisioning or the SIM before chasing anything downstream, because every firewall rule and every route you build assumes the documented address. Troubleshooting a routing problem against the wrong address wastes the whole session. Only once the gateway holds exactly the address on record does the rest of the verification mean anything.
Prove the Route Both Ways
Connectivity is directional, so test it both ways. From the gateway, reach the host and confirm a response, which proves the outbound path from the field to your server. Then, from the host side, reach the gateway at its fixed address, because a fixed IP exists precisely so your host or management system can initiate a connection to the device, and that inbound path can be broken even when the outbound one works. A site where the gateway can reach the host but the host cannot reach the gateway has a one-way problem that a single-direction test would miss.
When a direction fails, the fixed address itself is rarely the culprit if it matched the record. The break is almost always a routing rule or a firewall between the carrier's network and your host that does not pass traffic to or from that address. Walk the path: the carrier's private network, any tunnel or peering to your environment, and your own firewall, and confirm each hop permits the fixed address. This is the same kind of path reasoning used in the guide to secure remote access for SCADA, where deliberate rules decide exactly what may reach the device.
Check the Firewall Rules and Record the Path
Inspect the firewall rules that reference the fixed address, because a fixed IP is only useful if your rules actually name it correctly. A rule that permits the wrong address, or a rule order that blocks the intended traffic before the permit is reached, will drop connections to an address that is otherwise perfectly routed. Confirm the rule matches the exact fixed address, allows the specific traffic your SCADA link needs, and sits in the rule order where it will actually take effect.
Record the verified fixed address, the confirmed bidirectional route, and the firewall rules that permit it, so the fixed-IP arrangement is documented rather than tribal knowledge. When a fixed-IP site later stops connecting, the first question is always whether the address changed or a rule was edited, and a recorded path answers it immediately.
Once live, a platform such as Merobix sees the gateway reachable at its fixed address and trends its connectivity, so a fixed-IP site that suddenly becomes unreachable while still holding its address points straight at a routing or firewall change rather than a field fault. The verification proves the path today; the record and the trend are how you tell what changed if it breaks.
Frequently Asked Questions
My fixed-IP SIM has the right address but the host cannot reach it - why?
Connectivity is directional, and a correct fixed address that is unreachable inbound almost always means a routing or firewall gap between the carrier's network and your host, not a bad SIM. Test the route both ways, then walk the path hop by hop and confirm each firewall and route permits the fixed address in the direction that is failing.
Why use a fixed-IP SIM instead of a dynamic one?
A fixed address lets your host or management system initiate connections to the gateway and lets your firewall rules trust a known, unchanging address. A dynamic address can change, breaking inbound reachability and any rule that named it. The trade-off is that the fixed arrangement must be provisioned and routed correctly, which is exactly what this verification confirms.
Do I need to test connectivity in both directions?
Yes. A gateway can reach the host outbound while the host cannot reach the gateway inbound, and a single-direction test misses that. Since a fixed IP exists largely so your host can initiate connections to the device, verify both the field-to-host and host-to-field paths before declaring the SIM verified.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.