Automation Glossary • Private APN vs public cellular SCADA

Private APN vs Public Cellular for SCADA SIMs

Merobix Engineering • • 6 min read

Every cellular SCADA site runs on a SIM, and that SIM connects through either the carrier's public APN or a private APN provisioned for your fleet. The choice looks like a billing detail but decides whether your remote sites are reachable from the public internet, how they are addressed, and how much of your security posture the carrier handles. This page compares the two for an engineer specifying a cellular deployment.

Back to Blog

Private APN vs public cellular SCADA in one line: Public cellular uses the carrier's shared APN, which is simple and needs no setup but places your SIMs on the public internet where they can be scanned and reached. A private APN is a carrier-provisioned network for your fleet, keeping traffic off the public internet, giving you controlled addressing, and enabling inbound reachability without exposing sites publicly. Choose a private APN once you have more than a handful of sites or any inbound-access need.

Decide by Internet Exposure and Addressing

The defining difference is where your SIMs live on the network. On a public APN, the concept covered in the explainer on an APN, your devices generally receive addresses that sit on or behind the carrier's public infrastructure, exposed to the same scanning and reachability as anything else on the internet. That is fine for a single hobbyist device but a poor posture for a fleet of control-network gateways, each of which is a door into an operational system.

A private APN moves the whole fleet onto a carrier-isolated network dedicated to you. Traffic between your sites and your central system does not traverse the public internet, you get a controlled address range you can plan and segment, and you can allow inbound connections to devices without exposing them to the world. This is what makes reaching a remote gateway practical without the awkward workarounds that public cellular forces, and it is why serious cellular SCADA fleets move to a private APN as they scale.

Compare the Two APN Models

The table sets the models against the factors that matter for a control-network SIM rather than a consumer device.

FactorPublic cellularPrivate APN
On the public internetYes - exposed to scanningNo - carrier-isolated
AddressingCarrier-assigned, often dynamicControlled range you plan
Inbound reachabilityHard - NAT and exposureSupported without public exposure
Setup effortNone - works out of the boxCarrier provisioning required
CostLowest per SIMService fee for the private network
Right whenOne or few sites, outbound-onlyA fleet, or any inbound-access need

Addressing is the practical driver people underestimate. On public cellular, a dynamic, carrier-NAT address makes reaching a device inbound genuinely hard, which is why public-APN designs lean on outbound-initiated connections and NAT traversal. A private APN with a planned address range removes that friction, letting you reach a gateway for support or push a command without fighting the carrier's network.

A private APN also becomes the enforcement point for a whitelist posture. Restricting which destinations a SIM may talk to through an APN whitelist means a compromised gateway cannot reach arbitrary internet hosts, only the addresses your operation uses. That kind of egress control is straightforward on a private APN and awkward or impossible on a shared public one, which is a security argument on top of the exposure argument.

When Each Model Wins

Public cellular wins for a single site or a very small deployment that only ever connects outbound to a cloud endpoint and never needs to be reached inbound. The zero setup and lowest per-SIM cost are genuine advantages when the fleet is tiny and the security exposure of a couple of well-configured gateways is acceptable. Many pilots and single-well monitors start here correctly.

A private APN wins as the fleet grows past a handful of sites or the moment any inbound access is required. Controlled addressing, no public-internet exposure, practical inbound reachability, and egress whitelisting together change the security and operability of the whole fleet, and the per-SIM service fee is small against the cost of managing exposure and NAT workarounds across many public-APN sites. Distributed operations that must reach their gateways belong on a private APN.

A private APN is also the natural foundation to layer a VPN on top of when payload confidentiality is required, since the APN isolates the path and the VPN encrypts the traffic. For a cloud-native operation reading tags from many cellular sites, such as one built on Merobix, a private APN gives the addressing and reduced exposure that make a large gateway fleet manageable, while control still lives in the field devices those gateways front.

Pitfalls in the APN Decision

The most common pitfall is scaling a public-APN pilot into a production fleet without revisiting the exposure, so dozens of control-network gateways end up individually reachable on the public internet, each a potential entry point. What was an acceptable risk for one gateway becomes an unmanaged attack surface across many, and the right time to move to a private APN is before that surface grows, not after an incident.

A second trap is treating a private APN as if it encrypts traffic; it isolates the path but does not by itself provide end-to-end payload confidentiality, so layer a VPN where that matters. The final pitfall is over-relying on carrier-NAT workarounds to reach public-APN devices inbound, building fragile hole-punching or relay schemes that a private APN with planned addressing would make unnecessary. If you find yourself engineering around the addressing, that is the signal the deployment has outgrown the public APN.

Frequently Asked Questions

Is a private APN worth it for SCADA?

Once you have more than a handful of cellular sites or any need to reach devices inbound, yes. A private APN keeps your SIMs off the public internet, gives you controlled addressing you can plan and segment, and supports inbound access without exposing gateways publicly, plus egress whitelisting. For a single outbound-only pilot the public APN is fine, but a growing fleet gains security and operability that outweigh the per-SIM service fee.

Does a private APN encrypt my data?

No. A private APN isolates the network path so your traffic does not traverse the public internet, which reduces exposure, but it does not by itself provide end-to-end payload encryption. Where confidentiality of the payload matters, layer a VPN inside the private APN so you get both the isolation of the private path and the encryption of the tunnel. Treating the APN alone as encryption is a common and risky misunderstanding.

Why is inbound access hard on public cellular?

Because public-APN devices typically sit behind carrier NAT with dynamic, non-routable addresses, so there is no stable public address to connect to. Designs work around this with outbound-initiated connections and NAT-traversal tricks, which are fragile at scale. A private APN with a planned address range gives each site a reachable address without public exposure, removing the friction and the need for hole-punching or relay workarounds.

More in Industrial Networking & Communications
Commission a cellular SCADA gateway  •  Diagnose a cellular gateway that keeps dropping  •  Diagnose high latency on a cellular SCADA link  •  Estimate monthly cellular data for a SCADA site  •  Harden a cellular SCADA gateway configuration  •  All Industrial Networking & Communications →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →