> For the complete documentation index, see [llms.txt](https://docs.eseye.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.eseye.com/anynet-sim/connectivity/security.md).

# Security

This topic describes the security options available with the AnyNet solution to protect devices and data in transit, particularly over the internet, so that your IoT deployment will work effectively.

{% hint style="info" %}
Contact your Account Manager if you want to set up additional security options for your devices.
{% endhint %}

## About AnyNet security

The simplified diagram below shows connectivity between IoT devices, the Eseye PoPs and the central systems that devices are communicating with (which might exist in a private or public cloud, PoP, or on-premises servers).

![Security overview](https://2995386447-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzlTL8FVu6GaQkB5i1TRY%2Fuploads%2Fnekk7VdhjcK6gkqTntoA%2FConnectivity_Security-overview.png?alt=media)

It also shows how data is secured:

* **Device security**

  Customers are responsible for their device security. For best practice recommendations, including which IoT protocols to use, see [Device configuration best practices](/anynet-sim/connectivity/device-configuration-best-practices.md).
* **Mobile network security**

  With a cellular solution, connectivity between devices and the internet is provided by mobile networks. Cellular connectivity is based on GSMA standards and is covered by stringent regulations and quality of service requirements. Cellular networks provide inherent security for data transmission, including encryption of data in transit.
* **Additional AnyNet solution security**

  Eseye can apply additional security options, such as VPNs and ACL rules, for routing data securely between the Eseye network and the customer or their partner systems. This ensures that data is not intercepted or lost as it transits over the internet, and prevents rogue actors gaining access to devices.

  Eseye provides the following security:

  * **Private IP addresses and Network Address Translation (NAT)** – ensure IP addresses are hidden from the internet so that they are not used to access a device directly.

    For more information, see [IP addressing and routing](/anynet-sim/connectivity/ip-addressing-and-routing.md) and [About Network Address Translation (NAT)](/anynet-sim/connectivity/ip-addressing-and-routing/about-network-address-translation-nat.md).
  * **Secure subnets** – enable VPN configuration and ACL rules to control and route traffic

    For more information, see [About secure subnets](/anynet-sim/connectivity/ip-addressing-and-routing/about-secure-subnets.md).

    * **VPNs** – enable a high level of security and control for data transfer across the internet. Data is encrypted and access to the VPN is authorised and controlled.

      For more information, see [Understanding VPNs](/anynet-sim/connectivity/security/understanding-vpns.md).
    * **ACL** – checks network traffic against an Access Control List (ACL) provided by the customer and discards the traffic unless the destination matches one of the destinations in the list. Recommended for routing non-VPN traffic.

      For more information, see [Routing non-VPN network traffic](/anynet-sim/connectivity/ip-addressing-and-routing/routing-non-vpn-network-traffic.md).

      The public IP addresses for AnyNet PoPs are available for configuring customer-side ACL rules. See [Egress IP addresses](/anynet-sim/connectivity/ip-addressing-and-routing/egress-ip-addresses.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.eseye.com/anynet-sim/connectivity/security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
