Why PWG
- Security — SIMs are not directly exposed to the internet
- Control — route traffic through your own firewall or DLP platform
- Direct access — devices are addressable on your corporate network like any other host
Architecture
PWGs connect to a VRF-defined network on Telnyx’s MPLS backbone. Virtual Cross Connects (VXC) or WireGuard interfaces (Cloud VPNs) bridge this to your corporate network. All interfaces on the same VRF can see each other.API
Assign a PWG to a SIM Card Group via group actions. All SIMs in the group route through the PWG.
IP Assignment
A PWG’saddress_mode determines how IPs are assigned to SIMs in its group. PWGs are dynamic by default. To create a static PWG, set address_mode to static via the Create PWG API. You can view an existing PWG’s mode via the Get PWG endpoint:
- Static — each SIM gets a fixed IP from the PWG’s IP range, preserved across sessions. The device must use the
data00.telnyxAPN. - Dynamic — IPs are assigned by the network at attach time and may change between sessions. The device must use the
data.netAPN.
Limitations
- Region — PWGs are available in multiple regions including Washington DC (
dc2), Frankfurt (fr5), and Sydney (sy1). - IP range — Static PWGs are limited to a
/18subnet. Dynamic PWGs assign IPs at attach time with a higher capacity. - Internet access — PWGs have no internet access by default. Contact support to open your VRF to the internet.