On this page
- Why VPNs and 5G go together
- The main VPN protocols
- Common VPN designs
- Making VPNs reliable over mobile
- MTU and fragmentation
- Performance over 5G
- Split tunnelling
- VPN with a static public IP
- VPN versus private APN
- Security considerations
- Choosing where the VPN server lives
- VPNs and failover
- Remote engineer access, done properly
- Troubleshooting a 5G VPN
- Questions people ask
Short answer. A 5G VPN router builds an encrypted tunnel over the mobile connection to another site, a data centre or a cloud service. It is the standard way to securely reach equipment behind a 5G router, link branch sites to head office and protect traffic over the public internet. Because the router starts the connection outwards, a VPN works even on standard SIMs behind carrier-grade NAT. WireGuard, OpenVPN and IPsec are the protocols most business 5G routers support.
Almost every serious 5G router deployment ends up using a VPN somewhere. Sometimes it is a site-to-site tunnel linking a shop to head office. Sometimes it is how engineers reach a PLC at a pumping station. Sometimes it is just the cleanest way around CGNAT. This guide covers the main VPN types, how they behave over mobile networks, and how to set them up so they stay up.
Why VPNs and 5G go together
Three reasons come up again and again:
Getting around CGNAT. Standard mobile SIMs cannot accept inbound connections. A VPN that the router initiates outwards solves this without needing a public IP SIM. See public and static IP on 5G.
Security. Traffic between sites, or between equipment and a control system, should not cross the internet unencrypted. A VPN protects it.
Consistency. A VPN gives remote sites stable private addresses on your network, whichever mobile network or SIM they happen to be using at the time.
Site-to-site VPN over 5G
- Remote site devicesPLC, cameras, tills, PCs
- 5G routerStarts the VPN outwards
- Mobile network and internetEncrypted tunnel passes through CGNAT
- VPN server or concentratorIn the office, data centre or cloud
- Head office networkUsers and systems reach the remote site as if it were local
The main VPN protocols
| Protocol | Strengths | Watch out for |
|---|---|---|
| WireGuard | Fast, simple configuration, reconnects quickly after IP changes, low overhead | Fewer enterprise management features, needs a keepalive behind NAT |
| OpenVPN | Very flexible, runs over UDP or TCP, works through most firewalls | Slower and heavier on router CPU than WireGuard |
| IPsec (IKEv2) | Industry standard, interoperates with most firewalls and cloud VPN gateways | More complex to configure, NAT traversal must be enabled |
| L2TP over IPsec | Widely supported by older equipment | Legacy, more overhead, avoid for new designs |
| GRE or other tunnels | Useful for carrying routing protocols or layer 2 traffic | Not encrypted on their own, usually combined with IPsec |
For new deployments, WireGuard is often the simplest and best performing choice where both ends support it. IPsec is the safe choice when connecting to an existing corporate firewall or a cloud provider’s VPN gateway. OpenVPN remains useful where flexibility or TCP fallback matters.
Common VPN designs
Site-to-site
The 5G router connects to a VPN gateway at head office or in the cloud. Networks at both ends can reach each other. This suits branches, retail sites and industrial sites that need to talk to central systems.
Hub and spoke
Many remote routers connect to one or two central hubs. Remote sites talk to the hub and, through it, to each other if needed. This is how most multi-site estates are built.
Remote access for engineers
The 5G router keeps a tunnel up to a central server. Engineers connect to the same server with their own VPN client and can then reach the remote site. Nobody connects directly to the remote router.
Cloud overlay
Services such as ZeroTier and Tailscale, supported on many routers, create a mesh of encrypted connections managed from the cloud. Quick to set up and handy for small numbers of sites or engineers.
Making VPNs reliable over mobile
Mobile connections change IP address, go through NAT and occasionally drop. VPNs need to cope with that gracefully.
- Always let the remote router initiate the tunnel. The central end should accept connections from any address.
- Use keepalives. NAT mappings in the operator’s network time out if idle. A keepalive every 25 seconds or so keeps them open.
- Enable dead peer detection. The router should notice when the tunnel has failed and rebuild it.
- Enable NAT traversal for IPsec. This wraps IPsec in UDP so it passes through CGNAT.
- Use DNS names for the central end if its address could ever change.
- Have a second hub for important estates, so one server failing does not cut off every site.
MTU and fragmentation
VPNs add overhead to each packet, and mobile networks sometimes have a lower maximum packet size than fixed lines. If the VPN connects but some applications hang, web pages half load or file transfers stall, MTU is a likely cause. Reducing the tunnel MTU, often to somewhere around 1380 to 1420 bytes depending on the protocol, and enabling MSS clamping on the router usually fixes it.
Performance over 5G
Encryption takes processing power. A router that can pass 500 Mbps unencrypted may manage much less through a VPN, especially with OpenVPN. Check the manufacturer’s VPN throughput figures if the tunnel will carry a lot of traffic, such as CCTV or file transfers. WireGuard and hardware-accelerated IPsec generally perform best.
Latency on 5G is usually low enough that VPN overhead is not noticeable for normal applications. Voice and remote desktop work well over a properly configured tunnel.
Split tunnelling
You do not always need to send all traffic through the VPN. Split tunnelling sends only traffic for private networks through the tunnel, while internet traffic goes directly out of the 5G connection. That reduces load on the central server and keeps internet performance high. The trade-off is that internet traffic does not pass through central security controls, so the router’s own firewall needs to be configured properly.
VPN with a static public IP
Some services give each router a fixed public IP at the VPN exit. Traffic from the site appears to come from that address whichever SIM or connection the router is using. That solves IP whitelisting problems and lets you host services without a static IP SIM, and the address survives failover.
VPN versus private APN
Both achieve a similar result: remote routers on private addresses that your systems can reach securely. A VPN runs on the router and works with any SIM, any network and any internet connection, including a fixed line. A private APN is provided by the operator or SIM provider and needs no VPN on the router at all, but only works with that provider’s SIMs. Many larger estates use both, a private APN for mobile sites and VPNs for sites on fixed lines, terminating in the same central network.
Security considerations
- Use certificates or strong pre-shared keys, unique per site
- Restrict what each remote site can reach through the tunnel
- Keep VPN software on routers and servers patched
- Revoke keys or certificates promptly when routers are decommissioned or lost
- Log tunnel status centrally and alert when a site’s tunnel goes down
Choosing where the VPN server lives
The central end of the VPN needs a public IP address and enough capacity for all the remote sites. Common choices are:
Head office firewall. Simple if the firewall supports the protocol and has spare capacity. The weak point is that every remote site depends on the head office connection being up.
Cloud VPN gateway. The major cloud providers offer managed IPsec gateways, and you can also run WireGuard or OpenVPN on a small cloud server. This keeps remote site connectivity independent of any one office, and is easy to scale.
Data centre. Where core systems live in a data centre, putting the VPN concentrator there keeps the path short.
Router manufacturer platforms. Some management platforms include VPN hubs as a service, which avoids running your own server at all.
Whichever you choose, plan for failure. A second VPN hub in a different location, with remote routers configured to try both, prevents one outage from cutting off the whole estate.
VPNs and failover
A VPN that the remote router initiates works well with failover. When the router switches from a fixed line to 5G, or from one SIM to another, the tunnel drops and the router rebuilds it over the new connection, usually within seconds with WireGuard and a little longer with IPsec or OpenVPN. From the central end, the site disappears briefly and comes back from a different public address. As long as the server accepts connections from any address and authenticates by key or certificate, nothing needs changing.
Some routers can keep tunnels up over both connections at once and switch traffic between them, which shortens the interruption further. That needs a dual modem router or a fixed line plus 5G.
Remote engineer access, done properly
A neat pattern for engineering access is to keep every remote router permanently connected to a central hub, and have engineers connect to the same hub with their own credentials. Access rules on the hub then decide which engineer can reach which site and which devices. Each connection is logged. When a contractor finishes a job, you remove their access in one place rather than touching every router. Nobody ever connects to a remote router directly, and no ports are open at the remote sites.
Troubleshooting a 5G VPN
- Check the router has a working mobile data connection first.
- Check the tunnel status and logs on both ends.
- Confirm the central server is reachable from the router.
- Check keys, certificates and settings match exactly on both ends.
- For IPsec, confirm NAT traversal is enabled and UDP ports 500 and 4500 are open at the server.
- If the tunnel is up but traffic does not flow, check routes and firewall rules.
- If some traffic works and some stalls, check MTU.
For help designing VPN connectivity across 5G sites, email sales@5grouter.co.uk.
Questions people ask
Does a VPN work on a 5G router behind CGNAT?
Yes, as long as the router starts the connection outwards to a VPN server with a public address. CGNAT only blocks connections that start from the internet side.
Which VPN protocol is best for 5G routers?
WireGuard is often the simplest and fastest where both ends support it. IPsec is best for connecting to existing corporate firewalls and cloud gateways. OpenVPN is flexible and works through restrictive networks.
Why does my VPN connect but some traffic stalls?
Often an MTU problem. VPN overhead plus a smaller mobile MTU causes large packets to fail. Lowering the tunnel MTU and enabling MSS clamping usually fixes it.
Does a VPN slow down a 5G router?
Encryption uses router CPU, so throughput through the tunnel can be lower than raw 5G speed, especially with OpenVPN. WireGuard and hardware-accelerated IPsec perform best.
How do I keep a VPN up over mobile?
Let the remote router initiate the tunnel, use keepalives, enable dead peer detection and NAT traversal, use a DNS name for the server, and consider a second hub for important sites.
Planning a deployment, or stuck with one that is not behaving? Email sales@5grouter.co.uk with the site, the equipment and what you need it to do.