Using the Customer Corporate Network for Aircloud Internet Connectivity

Using the Customer Corporate Network for Aircloud Internet Connectivity

The Airmatics Cloudgate can provide internet connectivity to Airmatics devices through the customer's existing Corporate LAN instead of using the Cloudgate's cellular capability.

This configuration allows the Cloudgate to access AirCloud services, VPN services, time synchronisation services and software updates using internet WWAN access through a customer's Corporate LAN infrastructure.


Definitions

LAN
Local Area Network

Corporate LAN
Customers existing Ethernet network infrastructure

Airmatics Private LAN
Private LAN used by Airmatics devices

WWAN
World Wide Area Network; Internet access

AirCloud
Airmatics cloud based services

Cloudgate
Airmatics device providing:
  • Cellular access to the Internet (if SIM installed and Antenna fitted)
  • WWAN port access to a customers Corporate LAN to provide remote Internet access to AirCloud services
  • Airmatics Private LAN DHCP and DNS services

Purpose

This article describes how to provide internet connectivity to the Airmatics Cloudgate through the customers corporate network instead of using the Cloudgate's cellular capability.

This configuration allows the Cloudgate to access AirCloud services, VPN services, time synchronisation services and software updates using Internet WWAN access through a customers Corporate LAN infrastructure.


When to Use This Configuration

Use this configuration when:

  1. A customer requires all internet traffic to pass through their managed network.
  2. Cellular coverage is unavailable or unsuitable.
  3. Site IT policies require cloud-connected devices to utilise corporate internet access.

Architecture Overview

In this architecture:

  1. The Cloudgate WWAN port is connected to the customer network.
  2. The Cloudgate obtains internet connectivity through the customer's network infrastructure.
  3. The Cloudgate device remains connected, with SIM and antenna removed; Airmatics devices continue to communicate with the Cloudgate device for local Airmatics network DHCP and DNS services.
  4. The Cloudgate provides AirCloud and VPN connectivity using the customers internet service.

Prerequisites

Before beginning:

  1. Customer network access is available at the Cloudgate installation location.
  2. Customer firewall rules can be modified as required to permit access to the domains and services specified in this article.
  3. Required domains can be resolved and accessed.
  4. Appropriate customer IT approval has been obtained.


Cloudgate Configuration

SIM Removal

Remove the installed SIM card from the Cloudgate; this forces the Cloudgate to utilise the Ethernet WWAN interface instead of the cellular connection.

WWAN Port Connection

Connect the Cloudgate WWAN port to the customer network port.

The Cloudgate is designed to obtain its network configuration from the customers DHCP server.


Info
A fixed IP address may be assigned but is not the recommended configuration.


IP Addressing Requirements

The Cloudgate WWAN interface must have:

  1. A valid IP address.
  2. A default gateway.
  3. Access to a DNS server capable of resolving the required domains.
  4. Cloudgate can obtain an IP address from DHCP or a static IP can be assigned in the customers network settings.

Firewall and Internet Access Requirements

Port Requirements

The customer firewall must permit outbound and some inbound traffic using the following ports:

ServicePortProtocolPurpose
NTP123UDPTime synchronisation
MQTT + TLS8883TCPCumulocity communication
MQTT + TLS8884TCPVPN communication
HTTPS443TCPSoftware updates
OpenVPN1194UDPRemote maintenance
VPN Activation18283TCPInitial VPN activation

Warning
Inbound communication is necessary on the VPN and Cumulocity ports!

Domain Allow-List

The customer network must be capable of resolving and accessing the following domains:

Time Synchronisation
  • 0.openembedded.pool.ntp.org
Cloud Services

  • Airmatics.cumulocity.com
VPN Services
Mandatory:
  1. platform.5abox.com
  2. mqtt.5abox.com
  3. vpn-de1.5abox.com
Diagnostics
Mandatory (at least 1):
  • clients3.google.com
  • apple.com
  • msftncsi.com
  • connectivity-check.ubuntu.com
  • fedoraproject.org
Wildcard allow-listing is recommended for the 5abox, Cumulocity and ntp domains, but is not strictly needed.
No new domains are planned to be added. Additions will be communicated if they should arise.
Allow-listing should be done on domain names, not IP-level, as some of the IP addresses may change.

Network Behaviour and Security

The Cloudgate continues to provide DHCP and DNS services to local Airmatics devices connected to the Airmatics Private LAN.

The customer network provides internet access to the Cloudgate.

The Cloudgate distributes the customer's internet connectivity to Airmatics devices connected to the Airmatics Private LAN.

Warning
The customers network WWAN connection must never be connected directly to the Airmatics Private LAN.

The CloudGate performs network address translation (NAT) and routing between the Airmatics Private LAN and the customer's network.

Cloudgate operates as a firewall with default policies:

  1. LAN->WAN: Accept
  2. LAN->LAN: Accept
  3. LAN->Local: Accept
  4. WAN->Local: Drop

Customer devices can access the Airmatics subnet.

By default, traffic from the WAN interface to local services is blocked. As a result, Airmatics devices cannot access the customers network.

Packet Flow: Devices → Cloudgate LAN → Cloudgate WAN → Internet via customer network

Validation Procedure

After configuration, verify:

  1. Cloudgate has obtained a valid WAN address.
  2. Cloudgate can resolve required domains.
  3. Cloudgate can establish cloud connectivity.
  4. All Airmatics devices report successful Cloudgate connectivity.
  5. For Metacentre Core product: Check the dropdown on the user interface, it should show "Cloud connected: yes".
  6. The "Comm. Cloud" LED on the Airmatics Aero’s ‘Uni-TAG’ or Metacentre Core’s ‘Core Engine’ should be on.

Troubleshooting

SymptomPossible Cause
Cloudgate offlineNo WWAN connectivity
VPN unavailableRequired ports blocked
Device data not updatingMQTT communications blocked
Time synchronisation failureNTP access blocked
Software updates failHTTPS access restricted

Connectivity Issues

Check LEDs
Check all three LEDs on the Cloudgate are on.

Check DHCP
  1. Connect a laptop or other device directly to the Cloudgate LAN port.
  2. Verify that it receives an IP address.
  3. If it does not receive an IP address, verify that DHCP is enabled on the Cloudgate.
Check Domain Access
Verify that:
  • The required domains can be resolved.
  • The required domains can be reached from the customer network.
Check Cables
Replace Ethernet cables one at a time to eliminate cabling faults.

Firewall and Domain Issues

Verify:

  1. Domain access
  2. Port access


Support Boundary

Airmatics supports:

  1. Cloudgate hardware.
  2. Cloudgate configuration.
  3. AirCloud services; excluding remote Internet connectivity path through customer network.

Customer IT is responsible for:

  1. WWAN connectivity.
  2. DHCP services provided to the Cloudgate WWAN interface.
  3. Firewall configuration.
  4. DNS resolution.
  5. Remote Internet access availability.

Recap

Here's a quick summary of the configuration:

Corporate LAN – Provides internet connectivity to the Cloudgate.

WWAN Port – Connects the Cloudgate to the customer's Corporate LAN.

Airmatics Private LAN – Continues to provide local connectivity for Airmatics devices.

Firewall & Domains – Required ports and domains must be accessible through the customer network.

⚠️ WWAN connection – The customers network WWAN connection must never be connected directly to the Airmatics Private LAN.

The Cloudgate provides the required DHCP, DNS, NAT and routing functionality while using the customer's Corporate LAN for internet access.