The Airmatics Cloudgate can provide internet connectivity to Airmatics devices through the customer's existing Corporate LAN instead of using the Cloudgate's cellular capability.
This configuration allows the Cloudgate to access AirCloud services, VPN services, time synchronisation services and software updates using internet WWAN access through a customer's Corporate LAN infrastructure.
Definitions
LAN
Local Area Network
Corporate LAN
Customers existing Ethernet network infrastructure
Airmatics Private LAN
Private LAN used by Airmatics devices
WWAN
World Wide Area Network; Internet access
AirCloud
Airmatics cloud based services
Cloudgate
Airmatics device providing:
Cellular access to the Internet (if SIM installed and Antenna fitted)
WWAN port access to a customers Corporate LAN to provide remote Internet access to AirCloud services
Airmatics Private LAN DHCP and DNS services
Purpose
This article describes how to provide internet connectivity to the Airmatics Cloudgate through the customers corporate network instead of using the Cloudgate's cellular capability.
This configuration allows the Cloudgate to access AirCloud services, VPN services, time synchronisation services and software updates using Internet WWAN access through a customers Corporate LAN infrastructure.
When to Use This Configuration
Use this configuration when:
- A customer requires all internet traffic to pass through their managed network.
- Cellular coverage is unavailable or unsuitable.
- Site IT policies require cloud-connected devices to utilise corporate internet access.
Architecture Overview
In this architecture:
- The Cloudgate WWAN port is connected to the customer network.
- The Cloudgate obtains internet connectivity through the customer's network infrastructure.
- The Cloudgate device remains connected, with SIM and antenna removed; Airmatics devices continue to communicate with the Cloudgate device for local Airmatics network DHCP and DNS services.
- The Cloudgate provides AirCloud and VPN connectivity using the customers internet service.
Prerequisites
Before beginning:
- Customer network access is available at the Cloudgate installation location.
- Customer firewall rules can be modified as required to permit access to the domains and services specified in this article.
- Required domains can be resolved and accessed.
- Appropriate customer IT approval has been obtained.
Cloudgate Configuration
SIM Removal
Remove the installed SIM card from the Cloudgate; this forces the Cloudgate to utilise the Ethernet WWAN interface instead of the cellular connection.
WWAN Port Connection
Connect the Cloudgate WWAN port to the customer network port.
The Cloudgate is designed to obtain its network configuration from the customers DHCP server.
A fixed IP address may be assigned but is not the recommended configuration.
IP Addressing Requirements
The Cloudgate WWAN interface must have:
- A valid IP address.
- A default gateway.
- Access to a DNS server capable of resolving the required domains.
- Cloudgate can obtain an IP address from DHCP or a static IP can be assigned in the customers network settings.
Firewall and Internet Access Requirements
Port Requirements
The customer firewall must permit outbound and some inbound traffic using the following ports:
| Service | Port | Protocol | Purpose |
|---|
| NTP | 123 | UDP | Time synchronisation |
| MQTT + TLS | 8883 | TCP | Cumulocity communication |
| MQTT + TLS | 8884 | TCP | VPN communication |
| HTTPS | 443 | TCP | Software updates |
| OpenVPN | 1194 | UDP | Remote maintenance |
| VPN Activation | 18283 | TCP | Initial VPN activation |
Inbound communication is necessary on the VPN and Cumulocity ports!
Domain Allow-List
The customer network must be capable of resolving and accessing the following domains:
Time Synchronisation
Cloud Services
VPN Services
Mandatory:
- platform.5abox.com
- mqtt.5abox.com
- vpn-de1.5abox.com
Diagnostics
Mandatory (at least 1):
Wildcard allow-listing is recommended for the 5abox, Cumulocity and ntp domains, but is not strictly needed.
No new domains are planned to be added. Additions will be communicated if they should arise.
Allow-listing should be done on domain names, not IP-level, as some of the IP addresses may change.
Network Behaviour and Security
The Cloudgate continues to provide DHCP and DNS services to local Airmatics devices connected to the Airmatics Private LAN.
The customer network provides internet access to the Cloudgate.
The Cloudgate distributes the customer's internet connectivity to Airmatics devices connected to the Airmatics Private LAN.
The customers network WWAN connection must never be connected directly to the Airmatics Private LAN.
The CloudGate performs network address translation (NAT) and routing between the Airmatics Private LAN and the customer's network.
Cloudgate operates as a firewall with default policies:
- LAN->WAN: Accept
- LAN->LAN: Accept
- LAN->Local: Accept
- WAN->Local: Drop
Customer devices can access the Airmatics subnet.
By default, traffic from the WAN interface to local services is blocked. As a result, Airmatics devices cannot access the customers network.
Packet Flow: Devices → Cloudgate LAN → Cloudgate WAN → Internet via customer network
Validation Procedure
After configuration, verify:
- Cloudgate has obtained a valid WAN address.
- Cloudgate can resolve required domains.
- Cloudgate can establish cloud connectivity.
- All Airmatics devices report successful Cloudgate connectivity.
- For Metacentre Core product: Check the dropdown on the user interface, it should show "Cloud connected: yes".
- The "Comm. Cloud" LED on the Airmatics Aero’s ‘Uni-TAG’ or Metacentre Core’s ‘Core Engine’ should be on.
Troubleshooting
| Symptom | Possible Cause |
|---|
| Cloudgate offline | No WWAN connectivity |
| VPN unavailable | Required ports blocked |
| Device data not updating | MQTT communications blocked |
| Time synchronisation failure | NTP access blocked |
| Software updates fail | HTTPS access restricted |
Connectivity Issues
Check LEDs
Check all three LEDs on the Cloudgate are on.
Check DHCP
- Connect a laptop or other device directly to the Cloudgate LAN port.
- Verify that it receives an IP address.
- If it does not receive an IP address, verify that DHCP is enabled on the Cloudgate.
Check Domain Access
Verify that:
Check Cables
Replace Ethernet cables one at a time to eliminate cabling faults.
Firewall and Domain Issues
Verify:
- Domain access
- Port access
Support Boundary
Airmatics supports:
- Cloudgate hardware.
- Cloudgate configuration.
- AirCloud services; excluding remote Internet connectivity path through customer network.
Customer IT is responsible for:
- WWAN connectivity.
- DHCP services provided to the Cloudgate WWAN interface.
- Firewall configuration.
- DNS resolution.
- Remote Internet access availability.
Recap
Here's a quick summary of the configuration:
✅ Corporate LAN – Provides internet connectivity to the Cloudgate.
✅ WWAN Port – Connects the Cloudgate to the customer's Corporate LAN.
✅ Airmatics Private LAN – Continues to provide local connectivity for Airmatics devices.
✅ Firewall & Domains – Required ports and domains must be accessible through the customer network.
⚠️ WWAN connection – The customers network WWAN connection must never be connected directly to the Airmatics Private LAN.
The Cloudgate provides the required DHCP, DNS, NAT and routing functionality while using the customer's Corporate LAN for internet access.