As mobile networks become more distributed and cloud-native, a subtle but important challenge continues to surface for enterprises and operators alike: how do you keep a consistent IP address scheme for devices when sessions are no longer anchored to a single packet gateway?

For years, the default workaround was to assign devices fixed public IP addresses so they could always be reached in the same way. That approach worked when networks were centralised and security expectations were different. Today, however, public IPs introduce exposure, cost, and operational complexity that increasingly clash with modern zero-trust and edge-first network designs.

The real requirement has now shifted. It is no longer about giving a device a permanent public address. It is about preserving a stable private IP identity for each device, regardless of where it attaches in the world.

Why Traditional Mobile Cores Struggle With IP Consistency

In conventional EPC and 5G Core deployments, IP addressing is tightly coupled to the packet gateway serving the session. When a device attaches, the serving PGW allocates the IP address and anchors it locally. If that same device later re-attaches through a different gateway – because it has moved location, a closer edge is selected for latency, or a failover has occurred – the IP address will often change.

To avoid this, operators have historically been forced to “pin” traffic for fixed-IP devices back to a single central gateway. While this preserves the address, it creates a series of well-understood compromises:

  • Latency increases as traffic is backhauled across regions
  • Resilience is reduced because everything depends on one node
  • Sovereignty goals become harder to meet
  • Scaling the service becomes operationally fragile

The end result is a persistent tension between performance, resilience, and IP stability in traditional core architectures.

Why Public IPs on Devices Are Falling Out of Favour

Assigning public IP addresses directly to devices was once seen as the simplest way to guarantee reachability. In practice, however, this model no longer aligns with how enterprises want to operate secure networks.

Public device addressing introduces several structural issues:

  • Devices become directly internet-facing by default
  • The attack surface increases significantly
  • Firewall management becomes complex at scale
  • Public IPv4 availability and cost become real constraints

More importantly, public exposure runs counter to modern security models where no device should be reachable unless access is explicitly granted through secure channels. As a result, most enterprises now want devices to live entirely within private address space, with controlled access delivered via VPNs and secure proxies.

How Stacuity Preserves Private IP Identity Globally

Stacuity addresses this challenge by removing the tight coupling between a device’s IP identity and the physical packet gateway serving its session. Instead of the gateway “owning” the IP address, identity is handled at the platform layer and preserved as sessions move across the network.

With Stacuity’s distributed Edge PGW architecture:

  • Devices can attach at the nearest available gateway for performance
  • The same private IP address is maintained across attachments
  • IP identity remains consistent even as the gateway to which the device is anchored changes

This is enabled by Stacuity’s VSlice routing layer, which steers traffic across the distributed user plane while maintaining stable addressing. From the enterprise application’s perspective, the device has not moved – even though the underlying mobile session may now be anchored at a different edge location.

Secure Access Without Public Exposure

Because devices retain private IP addresses, secure access is delivered using native capabilities of the Stacuity platform, rather than relying on public internet exposure or third-party overlay networks. Enterprises typically access devices through:

  • Remote Access Proxy (RAP) services
  • IPsec or WireGuard VPNs
  • SSH, HTTPS, and application-level tunnels over encrypted links

This approach supports zero-trust architectures naturally. Devices are never publicly reachable, access is fully authenticated and auditable, and firewall policies can remain simple and predictable. From an operational standpoint, enterprises deal with stable private subnets rather than thousands of individual public IP endpoints.

Why Dynamic Gateway Selection Matters

Once IP identity is no longer tied to a single gateway, operators are free to anchor sessions wherever it makes the most technical or regulatory sense. A device can attach to the closest regional edge to minimise latency, while traffic can remain in-country to satisfy sovereignty requirements. If a gateway becomes unavailable, sessions can be re-established elsewhere without breaking enterprise integrations that rely on stable IP addressing.

This unlocks the true value of distributed user-plane architectures:

  • Low-latency regional breakout
  • Gateway-independent resilience
  • Predictable addressing for enterprise platforms
  • Easier global scaling without redesigning networks

All without forcing devices onto public internet addresses.

A More Natural Model for Global IoT and Enterprise Mobility

By combining persistent private IP addressing, distributed edge gateways, intelligent traffic steering and secure overlay access, Stacuity enables a far more natural networking model for global connected devices.

Enterprises no longer have to choose between performance and stability, or between security and reachability. Devices keep the same IP identity wherever they go. Traffic is anchored at the optimal edge. Access is delivered securely, without exposing endpoints to the public internet. And operators can evolve toward fully distributed, sovereign-ready cores without carrying forward the architectural compromises of legacy fixed-IP designs.

Learn more

Learn more about Stacuity’s edge solution here, or email sales@stacuity.com to book a meeting with our team.