SORACOM, Inc. (Headquarters: Minato-ku, Tokyo; President and CEO: Ken Tamagawa) announced today that it will launch "VPG Traffic Filtering," a new function to enhance network security as an added-value service for its Virtual Private Gateway (VPG), on July 7, 2026, within its IoT platform "SORACOM."
IoT has enabled us to connect all things to the network and treat the real world as data. Furthermore, as we move towards the era of Physical AI, where devices recognize their surroundings and operate in conjunction with the cloud and servers, the number of connected things and the importance of communication are steadily increasing.
In particular, industries with high security requirements such as manufacturing, finance, and security services are expanding their efforts to strengthen product and network security, driven by stricter regulations and guidelines. The "VPG Traffic Filtering" function supports the network-level security enhancements demanded by these industries.
SORACOM has been committed to security through multiple layers, including authentication, encryption, and access control. Closed-network connections are central to network security. VPG is a dedicated network gateway built on the SORACOM platform, allowing customers to filter unauthorized access destinations and establish private connections with their own networks. VPG has enabled services that allow communication from servers to devices and between devices, achieving bidirectional security.
The "VPG Traffic Filtering" function is a firewall function on the SORACOM platform. It allows customers to flexibly control communications from IoT devices using SORACOM Air for Cellular and SORACOM Arc based on custom-defined conditions. By finely filtering outbound traffic from devices based on conditions combining destination IP address, port number, protocol, and domain name, it enables centralized management of security for the entire IoT system. The allowlist method permits communication only to trusted destinations and blocks other unintended communications, thereby minimizing the spread of damage even if a device is compromised by malware.
Potential use cases include sending IoT data collected from sensors and equipment to specific entry points, or strictly limiting communication destinations to only permitted senders in response to IT controls, information security rules, industry standards, and various regulations. Furthermore, if an operational IoT device is maliciously rewritten, it can prevent data transmission even if commanded to send data to an unintended destination.
These settings can be intuitively configured via the SORACOM user console, and programmable changes are also supported using the SORACOM API.
The "VPG Traffic Filtering" function is compatible with VPG Type-F, Type-F2, and Type-G. Separate application is required to use this service.
SORACOM aims to create many use cases and innovations by providing the latest technologies more easily, centered around IoT, under the banner of "Democratizing IoT Technology."
Details of VPG Traffic Filtering Function
Launch Date
July 7, 2026
Service Overview
A cloud-based firewall function that allows control of destinations directly accessible by SORACOM Air for Cellular and SORACOM Arc using VPG, based on conditions for IP address, port number, protocol, and domain name (FQDN).
Two Filtering Methods
IP Filtering (IP Rules): Permits (allow) / denies (deny) outbound traffic from devices based on destination IP address, protocol, and port number.
FQDN Filtering (Domain Rules): Controls outbound traffic from devices based on destination FQDN, protocol, and port number. Domain name specification supports wildcard pattern matching (e.g., *.example.com).
Usage Image
Key Benefits
Enhanced Security: Blocks unnecessary communication with the allowlist method, permitting only trusted destinations. Fine-grained control at the protocol and port level.
Cost Optimization: Prevents unexpected or unauthorized communication in advance, reducing data usage. Efficiently manages numerous devices with group-based settings.
Compliance Support: Implements network control compliant with industry regulations and security policies.
Expected Use Cases
IoT Device Communication Restriction: Restricts sensor devices to communicate only with specific cloud servers, rejecting all others to minimize damage in case of device compromise.
Regional Access Restriction: Supports data sovereignty requirements and compliance with regulations prohibiting data transmission to specific regions by allowing only server IP ranges in designated regions.
Protocol Restriction: Permits only HTTPS, blocking unencrypted communication. Prevents plain text communication and reduces the risk of man-in-the-middle attacks.
Multi-stage/Multi-tenant Environments: Applies different filtering settings per VPG. Enables operations such as lenient control in development environments and strict allowlist control in production environments.
Compatible VPG Types
VPG Type-F, Type-F2, Type-G
Pricing
Varies depending on usage form and configuration.
How to Use
Separate application is required to use this service. Please contact us from the link below.
https://soracom.jp/contact/
About SORACOM
SORACOM, an AI/IoT platform, provides one-stop solutions including IoT communication that connects to over 200 countries and regions worldwide, as well as applications and devices necessary for utilizing IoT. It is used by customers of various industries and scales, from industrial DX in manufacturing, energy, and payments, to innovative startups, and initiatives supporting sustainable local communities such as agriculture and disaster prevention.
Corporate Site https://soracom.co
FACT BOX
- Source: PR TIMES
- Category: 製品リリース
- Organizations: SORACOM / VPG