You own and operate the core on your own infrastructure, on premise, with a RAN you run yourself or take through a carrier arrangement. Cellular networks were built for carriers, not enterprise IT/OT teams. OneLayer bridges that gap, bringing the coverage and control you expect from every other part of your network.
Supported Local cores
The Challenge
Cellular networks were designed for carriers, not enterprise IT/OT teams. Manufacturing plants, mines, ports, and oil and gas sites deploy a private local core for dedicated capacity, data sovereignty, and full operational control on premise. But cellular is the one conduit your security and IT frameworks weren't built to see: it breaks the Purdue model's zone boundaries, because the core authenticates by SIM, not device, with no record of type, ownership, or whether it belongs on the network. As AGVs, cobots, and sensors multiply on the floor, that gap gets harder to close by hand.
Your core confirms the subscription is valid. It can't tell you the device type, manufacturer, or whether it was swapped on the floor overnight.
Every new AGV, camera, or sensor added to the network means another manual provisioning step, another gap between when it connects and when your ITSM or CMDB knows about it.
Your NGFW and SIEM act on IP addresses, not IMEI or IMSI. Without device identity, policy enforcement and anomaly detection stop at the cellular network's edge.
The Solution
How OneLayer Fits: A Security and
Management Layer for the Core You
Already Operate
OneLayer Bridge connects to your private core's management interface, across Nokia, Ericsson, Celona, Druid, Athonet, Cisco, and GE Vernova alike, adding the device visibility, automated onboarding, and security context the core was never designed to provide. Read-only, no agents, no cellular expertise required, with a single pane of glass across every site and vendor you run.
Onboard
Automated SIM provisioning and activation at fleet scale, triggered from your ITSM or CMDB. Every new device gets the same security policy automatically, managed from one interface with no per-site setup.
Observe
Automatic fingerprinting classifies make, model, vendor, and protocol, extending discovery to assets behind edge and cellular routers your NGFW and SIEM can’t see today. Out-of-policy tethering and unauthorized device types get flagged in real time, alongside behavioral anomalies.
Protect
OneLayer feeds verified device identity to the firewalls you already run, like Palo Alto, Fortinet, and Check Point, revoking access automatically the moment behavior changes. A flagged device gets blocked at the firewall instead of just logged.
What Our Customers Are Saying
“We initiated a program called ‘No Asset Left Behind’ because we realized we needed to know about and manage all assets, not just network traffic. We needed this to apply to our private cellular networks in worldwide manufacturing sites. OneLayer seamlessly provided us with that visibility, including to non-cellular devices connected to the LTE/5G networks.”
No. OneLayer extends your existing Zero Trust architecture to cover your private cellular core, which most ZTNA tools were never designed to reach. Your current stack (NAC, MDM, ISE, SIEM) continues to operate as is. OneLayer integrates with it, surfacing cellular connection events and policy decisions into the same workflows your security team already uses.
OneLayer uses signature-based fingerprinting for unmanaged OT devices. A device identity is built from stable, device-specific attributes: IMEI, radio behavior, connection patterns, and other observable characteristics, extending discovery to devices behind edge routers that your NGFW and SIEM can’t see today. That signature becomes the identity assertion at connection time. Certificate-based validation is used for managed endpoints that support it.
Cellular is the one conduit most IT and OT security frameworks weren’t built to see, and it breaks the Purdue model’s zone boundaries because the core authenticates by SIM, not device. OneLayer adds the missing device layer: verified identity, make, model, and vendor for every AGV, camera, and sensor, so cellular traffic can be governed by the same zone and conduit logic as the rest of your OT environment, enforced through the firewalls you already run.
No. OneLayer connects to your private core’s existing management interface, across Nokia, Ericsson, Celona, Druid, Athonet, Cisco, and GE Vernova alike, without requiring changes to your SIMs, devices, or network hardware. It’s read-only, agentless, and requires no cellular expertise on your team to run.