> For the complete documentation index, see [llms.txt](https://support.simbase.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.simbase.com/platform/public-ips.md).

# Public IPs

<figure><img src="/files/l9x2NWIFlbbkDXjXcLCP" alt=""><figcaption></figcaption></figure>

A SIM card with a public IP address is a SIM card that is assigned a unique, publicly-routable IP address. This allows devices connected to the cellular network via the SIM card to be directly accessible from the internet.

This type of SIM card is typically used in Internet of Things (IoT) applications, such as remote monitoring and control of industrial equipment, mobile video cameras and/or devices using VPN services.

Having a public IP address on the SIM card allows devices to communicate with each other over the internet. This can simplify the architecture and reduce the cost of deploying IoT solutions.

Every public IP is a **static IPv4 address** that stays with the SIM. The traffic is not NAT-ed in between, so the address your device uses is the address you see in the dashboard and the address the internet sees. When you assign the IP you also choose where the traffic breaks out: a **US** POP or a **European** POP. Pick the region closest to the servers your device talks to.

## Assign a public IP

{% @supademo/embed url="<https://app.supademo.com/demo/cmbqo7w30btwgsn1r6fpiiujy>" demoId="cmbqo7w30btwgsn1r6fpiiujy" %}

## How it works

By default, our SIM cards sit behind a firewall that does not allow any incoming traffic from the internet. Assigning a public IP removes that barrier. The SIM receives its own static, publicly routable IPv4 address at the carrier, and traffic from the internet reaches your device directly.

You select the breakout region, US or Europe, at the moment you assign the IP.

{% hint style="danger" %}
**A public IP is fully open.**

There is no filtering on our side. Anything on the internet can reach your device, on any port. The firewall on your own device is the only thing protecting it.

Configure that firewall before you put the SIM into production, and only expose the ports you actually need.
{% endhint %}

If the SIM is already in use, please reboot your device (or reset the connection), because the changes take effect when the device starts a new data session. Most SIM profiles also need an APN change after a public IP is assigned. Please check the overview below.

## Considerations

{% hint style="danger" %}
**APN settings based on ICCID format**

Depending on your SIM card type, adjusting the APN settings on your device may be necessary after assigning a Public IP.

The APN needs to be changed to ***fixedip.us or fixedip.eu (depending on the selected breakout)*** for the following Profiles:

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252F4dJBN1F1gLvDgv99q5ZL%252Fimage.png%3Falt%3Dmedia%26token%3D877520cd-8cfb-495b-a1d1-d2b290e7cc8a&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=e25236a2&#x26;sv=2" alt="" data-size="line"> **Black**

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252F1HvcgE3AD7TwleIHxjYp%252Fimage.png%3Falt%3Dmedia%26token%3D70258e4d-40d9-4388-81d7-c4303934e757&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=9999d745&#x26;sv=2" alt="" data-size="line"> **Red**

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252FBrd1dfKl089ttdGowcYs%252Fimage.png%3Falt%3Dmedia%26token%3Df742026c-5c28-4496-99d2-cb1a56c55045&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=f0e32258&#x26;sv=2" alt="" data-size="line"> **Green**

**These SIMs can also be recognized based on the ICCID format: 89103\*\*\*\*.**

The APN needs to be changed to ***fixedip.m2m*** for the following Profiles:

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252FzCuo8XiheFTvAYOwJdo6%252Fimage.png%3Falt%3Dmedia%26token%3Db8acab7f-4b0e-4628-81b1-4b6f32056a1d&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=f0d8621&#x26;sv=2" alt="" data-size="line"> **Blue**

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252F4PgJDHv3uVu7VGhZToYR%252Fimage.png%3Falt%3Dmedia%26token%3Dbb214dab-ee4b-4834-92ef-b9e8533f69a6&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=6b405f46&#x26;sv=2" alt="" data-size="line"> **Yellow**

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252Fv0EVzHnNwnhimUqS7PnR%252Fimage.png%3Falt%3Dmedia%26token%3D3de06422-fc5a-45d3-9bb8-a0502a5fe6d3&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=f8b48388&#x26;sv=2" alt="" data-size="line"> **Cyan**

<img src="https://support.simbase.com/~gitbook/image?url=https%3A%2F%2F2653492456-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FYV3zfJTXLR73Umqnex88%252Fuploads%252FqDQZMr5kqKYDp7QrKz3A%252Fimage.png%3Falt%3Dmedia%26token%3D42f837de-085d-4336-a6a5-e28f2d0f6948&#x26;width=40&#x26;dpr=3&#x26;quality=100&#x26;sign=5fca2532&#x26;sv=2" alt="" data-size="line"> **Purple**

**These SIMs can also be recognized based on the ICCID format: 8944\*\*\*\***
{% endhint %}

Things to note:

* Make sure to restart the data connection on your device after deploying the public IP.
* It can take up to 2 minutes for the public IP to be assigned. Wait for it to fully deploy. Do not make any changes or re-deploys in the meantime.
* Your device has a built-in firewall that is beyond our control. Because there is no filtering on our side, this is your only protection: allow only the source IPs and ports you actually need. Please consult your hardware manufacturer in case of problems.
* Just like outbound traffic is billable, inbound traffic is also billable, so please note that if anybody on the internet accesses your device remotely, the inbound data usage is billed.
