Questions & Answers
Public Questions & Answers
The Conversation Around Comset
These pages turn the business source material into practical answers, comparisons, visual examples and confirmation points for people researching this business.
Not always. Many mobile services use private addressing or carrier-grade NAT, which means the old habit of expecting inbound access on a public IP no longer tells the whole story. Some deployments use VPNs initiated from the remote router outwards, while others use managed remote-access methods that work around the lack of a public address. Comset generally looks at the end goal first: do you need a permanent site-to-site tunnel, occasional technician acc…
VPN Security and Private Connectivity · 2026-07-19 I want to check a remote site from home. What is the safest way to do that?The safest answer is to use the router’s supported secure remote-access or VPN method rather than exposing open ports directly to the internet. The exact option depends on the router, the carrier constraints and the wider security policy, but the design should always be deliberate: authenticated access, clear user permissions and a manageable support process. Comset can usually steer the discussion towards secure remote access without turning the project …
VPN Security and Private Connectivity · 2026-06-04 How much can encryption and VPN processing reduce the usable throughput of an industrial router?VPN encryption consumes processor time and adds packet overhead. The reduction depends on the router CPU, encryption algorithm, packet size and number of tunnels. A modem capable of high cellular speed may still deliver much lower encrypted throughput if the router’s processor is the limiting factor. For low-volume telemetry the impact may be negligible. For 5G, cameras or large file transfers, ask for tested VPN performance rather than assuming the modem…
A site-to-site VPN is usually best when two networks need ongoing communication, such as a branch, plant or remote cabinet connecting to a central office. The routers maintain the tunnel automatically and devices can communicate according to fixed firewall rules without each user starting a VPN client. Individual remote-access accounts are better for people who need temporary or personal access from different locations. They allow user-level credentials a…
VPN Security and Private Connectivity · 2026-06-03 How does carrier-grade NAT affect inbound VPN and remote-access options on a cellular service?Carrier-grade NAT means the mobile carrier shares a public IP among many customers. The router receives a private address, so unsolicited inbound connections from the internet cannot be forwarded directly to it. Ordinary port forwarding or hosting a traditional inbound VPN server may therefore fail even when the router is configured correctly. Options include an outbound VPN to a server with a reachable address, a managed remote-access platform, ZeroTier-…
