August 20, 2026 How to Send PLC and Data Logger Data to a Remote Server over 4G

You've got machines in the field that should never be reachable from the internet, and a server at head office that needs their data yesterday. Here's the practical way to make it happen with an industrial 4G LTE router.

1. Start with a real-world picture

A network manager for a renewable-energy fleet recently laid out his situation in a public thread: more than 50 solar plants, 10+ storage sites and 10 hydro stations scattered across the country. Every site runs the same small network — an LTE router with a data SIM, a couple of unmanaged switches, 7–15 IP cameras feeding an NVR, and an alarm system. Almost all of the plants are too remote for fiber, so LTE is the only uplink. His next project is a second-level SCADA, which means data from the PLCs and data loggers on every site now has to flow to an external server.
His shopping list: VLAN support for 2–3 zones, industrial protocols (MQTT, Modbus TCP/IP, OPC UA), out-of-the-box traffic visibility, DDNS, VPN/IPsec, and — a nice-to-have — serial ports for the data loggers. Budget: under €500 per site.
If this sounds familiar, the good news is that a well-equipped industrial 4G LTE router covers all of it. The not-so-good news: no single box under €500 does everything beautifully. So the practical approach is to keep the router focused on WAN, VPN and protocol duties, and let a cheap managed switch handle the VLAN splitting. That split-role design is where most experienced integrators end up — the router stays simple and reliable, and the LAN layer does the segmentation.

2. Three paths your data can take

2.1 MQTT — for telemetry. 

The data logger or PLC publishes to a broker (your own or a cloud platform) over TLS, and the SCADA side subscribes. This is the lightest option, and it survives flaky LTE links by design. Perfect for periodic readings: power output, temperatures, status, alarms.

2.2 Modbus TCP, with serial-to-TCP conversion. 

PLCs and sensors that still speak RS485 Modbus RTU get bridged by the router into Modbus TCP and forwarded to the server. One device on the wall replaces what used to be a separate protocol-converter box.

2.3 VPN back to head office. 

The site router dials out to your OpenVPN or IPsec server. Because the tunnel is initiated from the site, nothing on-site needs a public IP — your SCADA engineers can reach the PLC's programming port or HMI as if it were on the office LAN. This route gives you full remote maintenance, not just data.

A decent industrial router gives you all three; you decide per site which to switch on.

3. Doing it, step by step

Step 1 — Zoning. Give SCADA its own VLAN before you need it. PLCs and data loggers on one tagged VLAN, cameras and NVR on another, inter-VLAN routing on the router. As one experienced voice in that thread put it: "if SCADA is coming, put it on its own VLAN now, even if it feels like overkill. You'll thank yourself later."
Step 2 — Get online. Drop in the SIM, set the APN, confirm LTE, then enable failover: cellular ↔ wired ↔ Wi-Fi, with automatic switchover when the primary link dies. On a hydro or PV site, this is what keeps the link alive through outages.
Step 3 — Publish MQTT. On the router's MQTT settings, enter your broker address and port, client ID and TLS certificate. Use QoS 1 for alarm topics so a message isn't silently lost, and keep the keep-alive interval realistic for cellular.
Step 4 — Bridge the serial data logger. Connect the logger's RS485 line to the router's serial port. Enable transparent transmission (the server sees a plain TCP/UDP socket) or Modbus gateway mode if the server expects Modbus TCP. Either way, no extra converter hardware.
Step 5 — Dial the VPN. Configure the OpenVPN client with the .ovpn file from your server — a one-click import removes the usual pain — or set up IPsec for site-to-site if your SCADA vendor insists. The router initiates the tunnel, so NAT and the missing public IP stop being problems. If you'd rather have the SCADA side poll sockets directly, enable DDNS so head office always resolves the right address.
Step 6 — Watch the data, not the bill. The biggest annoyance in that thread: SIMs running out of data and nobody knowing which device ate it. The community's diagnosis was almost always one camera or NVR doing cloud sync behind everyone's back. Fix it with per-VLAN accounting and router-side data monitoring: usage stats per device, plus an alarm when traffic crosses a threshold, pushed by email or SMS before the cap hits.
Step 7 — Lock it down. Change default credentials, enable the firewall and ACLs, keep encryption on for every tunnel, and stay current on firmware. It sounds basic, but most "mystery" issues in field networks trace back to an open port or an old password.

4. What to put on the wall

For the single-plant LTE uplink, the USR-G806w is the workhorse: 4G with three Ethernet ports, enhanced Wi-Fi for local devices, five VPN protocols (PPTP, L2TP, IPSec, enhanced OpenVPN, GRE), WAN failover across cellular/wired/Wi-Fi, and real-time alarms for offline status, weak signal and traffic overrun — pushed via email or SMS. It's built for exactly these cabinets: dual hardware/software watchdog, surge/EFT/ESD protection, -20 to +70°C, DIN-rail or wall mounting, and redundant power inputs. The enhanced OpenVPN also means one-click .ovpn import and compatibility with common servers (OpenVPN Access Server, pfSense, OPNsense, AWS EC2), so the "no budget for central management software" constraint doesn't bite.

When a site grows past a few devices, the USR-G809s gigabit edge router steps up: dual RS232/RS485 serial ports plus DI/DO for alarms, dual SIM redundancy, and built-in protocol libraries for Modbus TCP/RTU, MQTT and OPC UA — the exact list that thread asked for. It also runs Python edge scripts and caches data locally, so a site can buffer days of history and push it when the link recovers, instead of losing it during an outage.
If a site also backhauls HD camera video or moves large files, the USR-G816 5G router adds the bandwidth headroom. For pure PLC and data-logger traffic, though, LTE is honestly enough — spend the difference on redundancy and visibility, not on speed you'll never use.

5. The checklist before you order

Confirm the router speaks the protocols your SCADA expects (MQTT, Modbus, OPC UA — or will a VPN do the talking instead).
Make sure the serial side matches your data logger (RS232 vs RS485).
Check data monitoring and alarm features — that's what saves your SIM budget every month.
Look at the environment: temperature range, DIN-rail mount, voltage input, surge protection.
Ask about remote management, firmware updates, and security certifications (e.g., EU RED / EN 18031) so you don't drive to a mountaintop to fix a config.

The missing-public-IP problem is a solved problem. Pick an industrial 4G LTE router with MQTT/Modbus support, a VPN client and real traffic visibility, split the roles sensibly — and the PLC and data-logger data will be sitting on your server, from every site, without a single static IP or a single site visit.



REQUEST A QUOTE
Industrial loT Gateways Ranked First in China by Online Sales for Seven Consecutive Years **Data from China's Industrial IoT Gateways Market Research in 2023 by Frost & Sullivan
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy
Reliable products and services around you !
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy