> For the complete documentation index, see [llms.txt](https://docs.eseye.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.eseye.com/anynet-sim/connectivity/ip-addressing-and-routing/about-secure-subnets.md).

# About secure subnets

Each mobile network operator (MNO) supplies Eseye with a pool of private IP addresses to distribute to customer devices. To differentiate between customers that are connected on a single mobile network, Eseye uses secure subnets, which are segmented sections of these private IP address ranges. Eseye provides each customer with one subnet for every operator network that their devices use.

![](https://2995386447-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzlTL8FVu6GaQkB5i1TRY%2Fuploads%2FJnk5CpzUacjdXqo1Yq77%2FConnectivity_SubnetIPAddressAllocation.png?alt=media)

## How IP addresses are allocated to a SIM

During the device authentication process, Eseye allocates the IP addresses from within a customer’s subnet to the customer’s provisioned SIMs. Usually, a SIM is allocated a dedicated (static) [IPv4 address](/anynet-sim/connectivity/ip-addressing-and-routing.md) for each profile or IMSI that is installed on it. This IP address is assigned for the lifetime of the device. For those SIMs where this is unnecessary, the IP address is dynamic, which means that it will change every time the SIM is authenticated.

The following diagram shows how an IP address is assigned to a specific IMSI. For the purposes of simplicity, the diagram does not describe any translation that occurs on the IP address:

![](https://2995386447-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzlTL8FVu6GaQkB5i1TRY%2Fuploads%2FLO45QYj9MWSNhsYRlB8T%2FConnectivity_IPAddressAllocation.png?alt=media)

For more information, see [About Network Address Translation (NAT)](/anynet-sim/connectivity/ip-addressing-and-routing/about-network-address-translation-nat.md).

## How IMSI switching affects IP address allocation

The following diagram shows how, depending on which SIM profile is currently in use, Eseye will allocate a different IP address (and the data may route through a different PoP). In other words, the device may have multiple IP addresses assigned to it during its lifetime as connectivity shifts between mobile networks:

![](https://2995386447-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzlTL8FVu6GaQkB5i1TRY%2Fuploads%2FA4Hd2WCqg7UKatAFDWSK%2FConnectivity_IPAddressAllocationAllNetworks.png?alt=media)

The secure subnets ensure that all devices within a specific subnet are allocated IP addresses within a contiguous range. This enables efficient device management and is required for security options, such as VPNs and ACL rules, which we will discuss later. For more information, see [Understanding VPNs](/anynet-sim/connectivity/security/understanding-vpns.md) and [Routing non-VPN network traffic](/anynet-sim/connectivity/ip-addressing-and-routing/routing-non-vpn-network-traffic.md).

Eseye usually uses Network Address Translation to process the IP addresses for data routing across the internet. For more information, see [About Network Address Translation (NAT)](/anynet-sim/connectivity/ip-addressing-and-routing/about-network-address-translation-nat.md).

## What happens next?

Eseye manages the complexities of mobile network switching between multiple IMSIs on a single SIM, ensuring that data can move securely and quickly between the device and the customer network.

Devices may have multiple static private IP addresses, depending on the number of IMSIs that exist on the SIM. This enables the device to access multiple mobile networks for increased connectivity.

After connectivity is established, the device can send data to the customer network.

You can learn about:

* How the data traverses the Eseye MPLS network. For more information, see [Section B – Connecting over Eseye's MPLS network](/anynet-sim/connectivity/section-a-connecting-over-the-mobile-network/section-b-connecting-over-eseyes-mpls-network.md).
* The options you have for configuring how data enters your network or third party network (such as the cloud). For more information, see [Section C – Connecting over the internet](/anynet-sim/connectivity/section-a-connecting-over-the-mobile-network/section-c-connecting-over-the-internet.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.eseye.com/anynet-sim/connectivity/ip-addressing-and-routing/about-secure-subnets.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
