CSP G – TIER 1 EUROPEAN MOBILE OPERATOR
IoT Connectivity Control
CSP G, a leading Tier 1 European mobile operator, leverages the Enea AAA Server as an IoT Connectivity Control Function (ICCF), operating in concert with the existing Aeris IoT Connectivity Management Platform. Delivered as a comprehensive ‘as-a-service’ offering hosted on Amazon Web Services (AWS), the Enea solution utilizes the Enea AAA Server to manage the control plane, while Enea-deployed FortiGate next-generation firewalls handle the traffic plane.
Explore seven additional case studies by downloading the full Why Intellegent AAA is the Swiss Army Knife of Telecom paper below. You can also go here to learn more about theĀ Enea AAA Server.

Scaling Secure Connectivity for the SME “Long Tail”
As cybersecurity threats increase, secure cellular IoT connectivity has transitioned from a competitive advantage to a baseline requirement. However, the traditional method of delivering security via Private Access Point Names (APNs) does not scale for the “long tail” of small and medium-sized enterprise (SME) customers.
Limitations of Traditional Private APNs:
- High Operational Costs: Configuring and maintaining unique Private APNs for thousands of SMEs is resource-intensive for the mobile core.
- Manual VPN Provisioning: Establishing Enterprise VPNs between the Packet Gateway and customer networks often takes weeks and consumes significant engineering resources.
- Rigid 1:1 Architecture: Standard Private APNs typically support only one Enterprise VPN. Moving devices to a new VPN requires a complete re-configuration of the APN name on every physical device.
- Localization Risks: When using eSIMs for localization in countries with permanent roaming restrictions, IoT customers often lose control over IP addresses and security policies as the device is handled as part of the local MNO partnerās network.
Furthermore, for the traffic going outside the Private APN directly to the internet, CSP G could previously only offer “blanket” firewall settings across all customers, rather than unique, per-customer security policies.

Multi-tenant Private APN Innovation
To address these challenges, Enea offered its ICCF solution to CSP G leveraging the Enea AAA Serverās built-in Business Logic Engine and IP allocation through RADIUS. This combination enables the Multi-tenant Private APN functionalityāan industry-recognized Enea innovation that decouples the APN from the underlying Enterprise VPN.
How it works
The Enea ICCF utilizes advanced IP Address Management (IPAM) and Policy-Based Routing (PBR). Because the Enea AAA is aware of which enterprise a specific IP address belongs to, it can intelligently route traffic to a dedicated Enterprise Firewall function within the ICCF solution.
One shared APN is routed to the Enea ICCF solution and then separated to many enterprises.
This allows thousands of independent enterprises to share a single APN while maintaining completely isolated security environments.
End Customer Self-Service Empowerment
Through a web-based self-service GUI provided by CSP G, IoT customers can directly manage their connectivity stack. While SIM management and related functions are handled via APIs to the Aeris CMP, the Enea AAA Server provides the underlying logic for:
- Software-Defined Traffic Routing to any Enterprise VPN destination or directly out to the internet, protected by the customer-unique Enterprise Firewall function.
- Custom Firewall Rules (Allowlists/Denylists and destination blocking).
- Automated Enterprise VPN Setup (reducing provisioning time from weeks to minutes).
Key Comparison: Traditional APN vs. Enea ICCF:
Potential Future Extension for CSP G: The Enea IoT Cloud Gateway Appliance (CGA)
While the current ICCF solution successfully automates the CSPās side of the VPN connection, the enterprise customer is still responsible for configuring their own network endpoint. To address this final stage of complexity, Enea has developed the IoT Cloud Gateway Appliance (CGA) conceptāa strategic innovation designed for hyperscalers such as AWS, Microsoft Azure, and Google Cloud.
This roadmap concept, which has been well received by CSP G and other IoT connectivity customers aligns with the significant trend of enterprise customers migrating their IoT application backends to the cloud. The CGA is designed to facilitate true 100% Zero-Touch Provisioning (ZTP) of Enterprise VPNs by providing a pre-configured, cloud-ready appliance that can be instantly deployed within the customerās hyperscaler environment.
How the CGA Concept Will Work:
- License Allocation: The CSP provides a CGA license key to the enterprise administrator.
- Instant Deployment: The enterprise installs the CGA in their target cloud environment.
- Automated Activation: Upon startup, the CGA validates the license key via the Enea License Server (1), which then replies with an API URL (2) triggering the Enea AAA Server API to automatically establish the VPN tunnel (3).
By introducing this concept, Enea is demonstrating a clear path toward a fully automated, SD-WAN-like experience for cellular IoT, where the VPN configuration is completely eliminated for the enterprise customer.
A Strategic Guide to AAA Replacement
Legacy AAA systems are struggling to keep up with increasing data volumes, cloud-native architectures, rising complexity, and ever-increasing operational costs. This white paper gives CSPs practical insights on when and how to modernize their AAA infrastructure – delivering higher performance, greater flexibility, lower TCO, and a future-proof foundation for next-generation services.
Access
Why Intelligent AAA is the Swiss Army Knife of Telecom
The AAA server is no longer a static gatekeeper. It's now a Programmable Core capable of intelligent mediation, multi-generation interworking, and policy-driven orchestration at the network edge. Drawing on 8 Tier 1 operator case studies, this white paper shows how the Enea AAA Server turns operational complexity into scalable, revenue-generating services.
Access
