Set the breakout region
Every service policy specifies which emnify breakout region its devices use to reach the internet. You can either pick a fixed region or let the network choose one automatically for each data session. New service policies use automatic selection by default.
Automatic selection keeps latency low for fleets that move, but it isn’t right for every setup. This page explains how to check which region your devices use, how to change the setting, and what to do if your current configuration is at risk.
Automatic or fixed selection
Choose automatic selection when your devices reach the public internet and you want the lowest latency wherever they are.
Choose a fixed region when your devices reach your application through Cloud Connect or OpenVPN.
For background on breakout regions, see Local data routing.
Don’t use automatic selection together with Cloud Connect or OpenVPN. Both terminate on emnify resources allocated in one specific breakout region, so end-to-end connectivity only works while the devices break out in that same region. Under automatic selection a roaming device can move to another region at any time, which breaks the connection.
Check which region a device is using
You can see the breakout region a device is connected through in its device details.
Open device details for an online device and select the General tab.
The pop-up shows the connectivity details for the current session, including Breakout IP. Match that address against List of emnify’s public IPs to identify the region.
The address shown belongs to the region the current data session is using. Under automatic selection it can differ between devices, and it can change when a device roams onto another operator.
Which applies to you
Both sections below assume a service policy set to Automatic Breakout Region, which is the default. A policy already pinned to a fixed region keeps using that region and needs no action.
- Your devices reach your application over the public internet: see If your devices use internet breakout.
- Your devices reach your application through Cloud Connect or OpenVPN: see If your devices use Cloud Connect or OpenVPN.
If both apply, for example because you use Cloud Connect and also protect servers on the public internet with a firewall, follow both sections. If neither applies, no action is needed. Your devices may take a different route, but nothing you configured depends on which route that is.
If your devices use internet breakout
This applies when your devices reach your application over the public internet, and you protect that application with firewall rules that allow traffic only from specific IP addresses. The firewall is one you control, in infrastructure you control such as your own AWS account, not something emnify operates on your behalf.
Your devices have private IP addresses. The emnify packet gateway translates them to a public IP address through source NAT, and that public address is what your application sees and what your firewall rules match on.
Which public address it is depends on the breakout region the device is connected through. When automatic selection moves a device to a different region, the address changes with it. If your firewall doesn’t allow the new address, your devices still create a data session and show as Online in the Portal, but they can’t reach your application.
This isn’t caused by the Automatic Breakout Region setting, so you don’t need to change it. The fix is in your firewall.
Allowlist every emnify public IP address, across all breakout regions, rather than only the addresses of the region your devices use today. That keeps your application reachable whichever region your devices connect through, now and for any future change.
See List of emnify’s public IPs in the emnify Knowledge Base.
You can also retrieve the current ranges from GET /api/v1/breakout_ip_range, which returns the public IPv4 egress ranges grouped by breakout region.
The ranges are updated periodically, so check them whenever you review your firewall rules.
If your devices use Cloud Connect or OpenVPN
This applies when your devices reach your application over a private path rather than the public internet.
Cloud Connect and OpenVPN both terminate on emnify resources allocated in one specific breakout region, such as an AWS Transit Gateway, an IPsec gateway endpoint, or an OpenVPN server. End-to-end connectivity only works while your devices break out in that same region.
Under automatic selection a device can move to another region at any time, for example when it roams onto a different operator. If your setup works today, it’s because every operator your devices currently use happens to map to your integration’s region. That isn’t guaranteed to hold.
Change the service policy from automatic selection to the fixed region that matches your integration.
Cloud Connect
Use the fixed region that matches your Cloud Connect integration, which is the breakout region selected when the integration was created. See Cloud Connect.
OpenVPN
Use the fixed region that matches the region in your OpenVPN client configuration. If you want to move to a different region, change the service policy and download a new client configuration file for that same region. See OpenVPN.
Set the breakout region
Navigate to Service Policies and expand the policy you want to change.
Changes save automatically.
You can also set the region through the breakout_region field of the service profile in the emnify REST API.
Changing the breakout region doesn’t interrupt your devices. Data sessions that are already established continue in the region where they were created, and the next sessions use the newly configured region.
How automatic selection picks a region
Automatic selection maps the operator a device is connected to, identified by its MCC and MNC, to the breakout region with the lowest measured latency between that operator and the emnify platform. emnify monitors those latencies continuously and revises the assignments as the network grows, so the region a device uses can change over time.
To see the region a specific device is using right now, see Check which region a device is using.
Frequently asked questions
My configuration uses automatic selection with OpenVPN or Cloud Connect and works today. Will it keep working?
Not reliably. It works today only because every operator your devices currently use happens to map to your integration’s region, and that can change at any time. See If your devices use Cloud Connect or OpenVPN.
Will the breakout region assignments change again?
Yes. As emnify extends and optimizes its connectivity to operators worldwide, latencies improve and the operator assignments are revisited. Expect these updates on a regular basis rather than as a one-off.