Semtech links AirLink with Palo Alto security

Semtech links AirLink with Palo Alto security

Semtech and Palo Alto Networks are linking industrial edge security. The integration combines AirLink connectivity, next-generation firewalls, encrypted links, and automated certificate management for utilities and critical infrastructure operating large fleets of distributed connected assets.


IN Brief:

  • Semtech AirLink routers are integrated with Palo Alto Networks next-generation firewalls and security services.
  • Encrypted tunnels and automated certificate lifecycle management extend controls from remote assets towards core networks.
  • The architecture targets utilities and critical infrastructure using cellular, satellite, and wired connections across distributed fleets.

Semtech and Palo Alto Networks have completed an integration between AirLink industrial networking systems and Palo Alto Networks next-generation firewalls, extending security policy, encrypted connectivity, and automated machine identity management across remote operational assets.

The architecture combines Semtech AirLink 5G and LTE routers and network management with Palo Alto Networks firewalls, Next-Generation Trust Security, and Zero Touch Public Key Infrastructure. It is intended for utilities and critical infrastructure operators managing large numbers of field assets over cellular, satellite, and wired connections.

Encrypted tunnels can be established automatically from AirLink-connected equipment to the firewall environment, while integration with PAN-OS gives security teams visibility into traffic moving between field sites and wider networks. Certificate provisioning, renewal, and machine identity management are handled through Zero Touch PKI and AirLink management rather than being configured manually for each remote device.

That certificate element becomes increasingly important as fleets scale. A single remote router can be provisioned and maintained manually without much difficulty; thousands of devices spread across substations, pumping stations, renewable assets, transport systems, and other infrastructure create a different operational problem.

Each device needs an identity that can be issued, renewed, revoked, and associated with the right security policy. Poorly coordinated certificate management can create two opposite risks: credentials may remain active longer than intended, or legitimate equipment may lose connectivity when a certificate expires unexpectedly.

Automating that lifecycle reduces repetitive administration, but it also makes the management platforms themselves part of the operational dependency. Utilities consequently need to understand what happens when a field connection is intermittent, a certificate service cannot be reached, or a router has to recover after an extended communications outage.

The integration is therefore more significant than attaching a Zero Trust label to an industrial router. Semtech provides the communications path and edge management, while Palo Alto Networks adds policy enforcement, inspection, threat prevention, and credential management. Linking those functions gives operators a way to apply security controls across assets that may use different underlying communications technologies.

Operational technology makes that harder than conventional branch networking. Remote assets may contain equipment with long service lives, limited patching options, proprietary protocols, and maintenance windows dictated by physical operations rather than IT schedules. A security control that interrupts telemetry or remote operation can create a larger problem than the vulnerability it was intended to mitigate.

Policy enforcement therefore has to account for continuity as well as threat detection. Industrial traffic is often relatively predictable, which can make unexpected communications easier to identify, but legitimate maintenance, failover, and emergency behaviour still need to pass through the architecture without creating unnecessary outages.

The use of multiple connection types adds another practical requirement. Cellular links may provide primary or backup connectivity at one site, while satellite is used where terrestrial coverage is poor and wired infrastructure remains preferable elsewhere. Applying common identity and firewall policy across those links can reduce differences between sites even though the physical networks remain heterogeneous.

Palo Alto Networks describes the combined approach as edge-to-core security, with AirLink providing resilient connectivity and IPsec protection while the firewall environment applies application classification and threat-prevention functions. The engineering test will be how consistently that model behaves at fleet scale, especially where bandwidth, latency, and availability vary significantly between locations.

Semtech and Palo Alto Networks plan to demonstrate the integration at the Utility Broadband Alliance Summit & Plugfest in Fort Worth from 13 to 15 October. Production deployments will provide the more useful evidence: certificate rollover, failure recovery, policy updates, intermittent links, and support for ageing field devices will determine whether the integration reduces operating complexity as well as improving security coverage.


Stories for you


  • Semtech links AirLink with Palo Alto security

    Semtech links AirLink with Palo Alto security

    Semtech and Palo Alto Networks are linking industrial edge security. The integration combines AirLink connectivity, next-generation firewalls, encrypted links, and automated certificate management for utilities and critical infrastructure operating large fleets of distributed connected assets.


  • Hygon brings C86 processors to industrial edge

    Hygon brings C86 processors to industrial edge

    Hygon is moving C86 processors into embedded industrial systems worldwide. The 1000 series combines four cores, eight threads, DDR4 or DDR5 support, and local graphics processing for robotics, machine vision, factory automation, and edge computing.