Connectivity
How private APNs and VPNs work: a guide for cellular IoT teams
A private APN keeps cellular IoT data off the public internet, and a VPN encrypts that data in transit. Many deployments use both.

Cellular IoT teams often hear "private APN" (access point name) and "VPN" (virtual private network) used as if they mean the same thing. They solve different problems. This guide answers the question "how do private APNs and VPNs work?" in plain terms, with tables, a decision guide, and questions for your provider.
Key takeaways
- A private APN controls the path: It routes a device's cellular data into a private network instead of the public internet.
- A VPN protects the content: It wraps traffic in an encrypted tunnel between two endpoints.
- A private APN doesn't guarantee encryption: Routing keeps traffic separate, but encryption needs its own layer.
- Many deployments layer both: A private APN isolates devices, and a VPN links that network to a company data center or cloud.
- Not every device needs either: Devices that only send data out over encrypted protocols often work well on a standard setup.
How do private APNs and VPNs work?
A private APN routes a device's cellular data into a private network instead of the public internet. A VPN wraps that data in an encrypted tunnel between two endpoints, such as a router and a server. One controls the path, and the other protects the content.
Think of a private APN as a private road and a VPN as an armored truck. The road decides who can drive where. The truck keeps the cargo sealed for the whole trip.
What is an APN?
APN stands for Access Point Name. It's the gateway between a cellular network and another network, such as the internet or a company network. Every cellular data session uses one.
When a device connects, the APN tells the carrier which network to join, which security rules apply, and how to assign IP addresses. Our guide to APN structure explains its two parts: a network identifier that names the destination network and an operator identifier that names the carrier. As that guide explains, the operator identifier uses the carrier's mobile network code (MNC) and mobile country code (MCC).
Public APN vs. private APN
Many customers share a public APN. It sends traffic to the public internet and usually gives devices dynamic IP addresses that change over time.
A private APN keeps your devices' traffic separate and routes it to your company network or cloud. It can also assign a static IP, which is an address that stays the same, so your systems always know where to find each device.
| Factor | Public APN | Private APN |
|---|---|---|
| Who uses it | Many customers | Only your devices |
| Where traffic goes | Public internet | Your company network or cloud |
| IP addresses | Usually dynamic | Dynamic or static, private or public |
| Inbound access | Usually limited | Possible with static IPs and routing |
| Setup | Ready out of the box | Set up with your provider |
| Best fit | Simple devices that only send data out | Fleets that need control and isolation |
How a private APN works
A private APN works inside the carrier's core network, before your traffic reaches the internet. Here's the data path, step by step:
- The device attaches to the cellular network and asks for the APN name set on its SIM or modem.
- The carrier's core network recognizes the APN and checks that the SIM has permission to use it.
- The core keeps that device's traffic separate from every other customer's traffic.
- The carrier hands the traffic off to your network, often through a secure link to your data center or cloud.
This design can reduce your attack surface, because devices don't sit on the open internet. It can also give you policy control over who can connect and predictable addressing for each device.
Segmentation matters on any connected network. Palo Alto Networks studied 27 million devices across 1,803 enterprise networks. Its 2025 device security threat report found that "77.74% of networks have poor segmentation."
That study covers enterprise networks rather than cellular fleets. The lesson still carries over: isolation is a design choice worth making early.
How a VPN works
A VPN builds an encrypted tunnel between two endpoints across an IP network. Data enters the tunnel at one end, travels scrambled, and leaves the other end readable again. Anyone in between sees only encrypted packets.
IPsec, short for Internet Protocol Security, is the common standard for IoT VPNs. The IETF IPsec architecture RFC states that "IPsec is designed to provide interoperable, high quality, cryptographically-based security for IPv4 and IPv6." It works at the IP layer, so it protects traffic from every app above it.
Most IoT VPNs take one of two shapes:
- The device builds its own tunnel to your server, which uses processing power and memory on the device.
- A gateway or cellular router builds one tunnel for every device behind it, which keeps the devices simpler.
VPNs bring ongoing work. Your team manages keys, certificates, and tunnel settings across the fleet for its whole life. To see each step, learn how IPsec tunnels work.
Private APN vs. VPN: side-by-side comparison
The two tools act on different layers, so they compare best side by side. Our breakdown of APN vs. VPN in IoT security goes deeper on the security trade-offs.
| Factor | Private APN | VPN |
|---|---|---|
| What it acts on | The path traffic takes | The content of the traffic |
| Encryption | Not by itself | Yes, between tunnel endpoints |
| Network layer | Carrier core network | IP layer |
| Device effort | Set the APN name | Tunnel software or a VPN-capable router |
| Operating effort | Low after setup | Ongoing key, certificate, and tunnel management |
| Provider dependence | Often high, because it lives in the carrier network | Often lower, because you control both ends |
| Best fit | Isolating fleets and controlling access | Protecting sensitive data in transit |
Neither tool protects you from a compromised device. If an attacker controls the device itself, the private path and the tunnel carry that traffic too. Device hardening still matters.
Does a private APN encrypt your data?
Not by itself. A private APN isolates traffic through routing, and routing is different from encryption. The radio link is a good example.
As of Release 18, the 3GPP 5G security architecture states: "Confidentiality protection of user data between the UE and the gNB is optional to use." Here, UE is the device and gNB is the 5G base station. The same spec says base stations need to support this encryption, but using it is optional.
GSMA's guidelines (version 2.2, 2020) recommend a private APN as a medium-priority control, and they're clear about its limits. Per the GSMA IoT security guidelines, "a private APN does not mitigate the risk of an adversary compromising the communication link between the Endpoint and the private APN." When data confidentiality matters, add an IPsec VPN or Transport Layer Security (TLS), the protocol behind HTTPS.
How private APNs, VPNs, and static IPs work together
These three tools stack into layers. Each one handles a different job, and together they form a private wide area network (WAN) for your fleet.
| Layer | Job | Example |
|---|---|---|
| Private APN | Isolates device traffic from other customers and the internet | Only your SIMs can reach your back end |
| VPN | Encrypts traffic between the carrier and your network | An IPsec tunnel to your data center or cloud |
| Static IP | Gives each device or tunnel endpoint a fixed address | A server polls a meter at the same address every day |
This layered setup is common. Companies that set up a private APN often add a VPN link to their own network, on-premises or in the cloud.
When to use a private APN, a VPN, or both
Two questions sort most use cases. Does anything need to reach the device from outside? Does the data need encryption beyond what your app already uses?
- Telemetry that only flows out over HTTPS often needs neither, because the device starts every connection.
- Remote polling, such as supervisory control and data acquisition (SCADA) systems, suits a private APN with static IPs.
- Sensitive data, such as readings from healthcare devices, calls for a VPN on top of the private APN.
- Occasional remote access, such as field debugging, can use lighter tools like secure device tunneling or cloud-to-device messaging.
Inbound access takes extra planning on public networks. Many cellular networks share addresses through carrier-grade network address translation (CGNAT), which places many devices behind one public address.
The IETF's RFC 6269 on address sharing explains that "Unsolicited inbound UDP will be dropped by address sharing mechanisms as they have no live mapping." So outside servers often can't start a connection unless the network sets up a mapping first. Our guide to communicating with remote IoT devices shows how to work around that.
Hologram's view is that every cellular device uses an APN, but not every device needs a VPN. VPNs can be complex to set up and raise total cost of ownership, so choose based on your use case.
Alternatives to a traditional private APN
In our experience at Hologram, traditional private APNs can be costly and slow to set up, often with custom carrier work, dedicated links, and on-site hardware. Software-defined private networking offers a faster path.
A shared private APN backed by a software-defined network (SDN) lets you segment devices and set policies without building physical infrastructure. See how Hologram approaches software-defined network security.
Application-layer security is still best practice. Encrypt data in your app with TLS, even on a private network.
Roaming, 5G, and the DNN
A private APN can help keep the same routing and addressing rules as devices move between networks, depending on your provider. That consistency makes roaming fleets easier to plan for.
The GSMA EPS roaming guidelines say roaming behavior is "dependent on whether the users' traffic is Home Routed, broken out from the Visited Network." Home routing sends traffic back through the home network, and local breakout is the other option. Your provider decides which one applies, so ask before you plan around it.
5G uses a new name for the same idea. The 3GPP numbering and addressing standard puts it plainly: "In 5GS, the Data Network Name (DNN) is equivalent to an APN in EPS." Here, 5GS is the 5G system and EPS is the 4G Evolved Packet System.
Key features of secure cellular connectivity with Hologram
By Hologram's count, each Hologram global IoT SIM connects across 550+ carriers in 190+ countries and includes a REST API. Here's how Hologram describes its security features:
- Private APN, fraud detection, and device locking: Every Hologram Hyper SIM includes these security features.
- Custom private APN or VPN options: Hologram offers a custom private APN or VPN for teams that need more control.
- Dashboard and APIs: Hologram gives teams a dashboard and APIs to manage their SIMs.
- Global multi-carrier coverage: Hologram's IoT SIM connects devices across multiple carriers worldwide.
Questions to ask your connectivity provider
Use this checklist when you compare providers:
- Do devices get public or private IP addresses?
- Are IP addresses fixed or dynamic?
- How will your servers reach devices in the field?
- Which tunnel methods does the provider support?
- Does the provider allow or block SIM-to-SIM traffic?
- Where does internet breakout happen?
- What happens to your private APN and IP plan if you change providers?
A private APN is one strong part of a secure design. Pair it with encryption, device hardening, and the IoT security best practices your team already follows. With the right layers in place, cellular IoT gives your fleet a secure, global foundation to grow on.
FAQs
Is a private APN the same as a private IP address?
No. A private IP is a reserved address the public internet can't route, while a private APN is the path your traffic takes.
Can I use a VPN without a private APN?
Yes. A device or router on a standard public APN can build a VPN tunnel to your server over the internet.
Does a private APN still have internet access?
It can. Your provider can route internet traffic through a breakout point, or you can send it through your own network and firewall first.
Do I need a private APN for MQTT?
Usually not, because your device "opens the Network Connection to the Server" (the broker), per the MQTT v5.0 client definition. A private APN matters when you need private routing or inbound access to devices.
