Orbalux - Integration & connectivity
A high-level connectivity overview of how on-site systems publish secure outbound telemetry to Orbalux.
Purpose
On-site systems connect to Orbalux by sending outbound-only, encrypted telemetry through either a software gateway or a hardware gateway appliance. Both options authenticate via client certificate or token and publish to a managed cloud broker over MQTT over TLS or HTTPS. This article is a connectivity summary, not a configuration guide.
Connectivity model summary
-
How does Orbalux receive data from on-site systems?
Orbalux receives data over outbound-only connections from the customer network using
MQTToverTLSorHTTPS. Orbalux never initiates inbound connections to site hosts. Client authentication is certificate-based or token-based and is managed per gateway instance. The cloud broker runs as a managed service in a certified cloud region with redundancy, monitoring, and logging under WISE Group control. Private peering or VPN options are available for customers who require traffic to remain off the public internet.Cellular (mobile) connectivity is also supported for sites where fixed internet access is unavailable or undesirable. In this case, a SIM-equipped gateway device connects to the cloud broker over a carrier APN; data volume estimates and APN configuration should be agreed with the carrier and WISE Group during integration planning.
-
Client authentication is certificate-based or token-based and managed per gateway instance.
-
The cloud broker runs as a managed broker service in a certified cloud region and is operated with redundancy, monitoring and logging under WISE Group control.
-
Private peering or VPN options are available for customers who require traffic to remain off the public internet.
Gateway options
Software gateway
-
An integrated software gateway runs on the on-site host or a designated gateway host; it accepts structured messages from the on-site data acquisition system and publishes securely to the cloud broker.
-
Suitable when the host has controlled outbound internet access.
Hardware gateway
-
A dedicated gateway appliance provides physical and network isolation. The on-site data acquisition host connects to the appliance over an isolated interface (for example serial using JSON messages); the appliance publishes outbound to the cloud broker.
-
Preferred for stricter isolation or high-security deployments.
Both approaches keep the primary data acquisition host isolated from direct inbound network access while allowing secure outbound cloud publishing.
Protocols, endpoints and authentication
-
Primary transport: MQTT over TLS; HTTPS supported for alternate ingestion.
-
Connections are outbound-only from site; the cloud broker does not open inbound sessions to site hosts.
-
Authentication: client certificate and key pair per gateway instance (or an agreed equivalent).
-
Broker: managed broker service with redundancy and operational monitoring; private peering or VPN is available where required.
Resilience and operational behaviour
-
Resilience and Operational Behaviour
The managed broker service provides redundancy and endpoint failover automatically. Edge systems buffer telemetry during outages and forward cached data when connectivity is restored; buffering policy and acceptable replay latency must be agreed before integration.
-
Edge systems buffer telemetry during outages and forward cached data when connectivity is restored. Buffering policy and acceptable replay latency should be agreed.
-
The hardware gateway option is used in high-security deployments to provide serial isolation and remove direct IP communication from the main data acquisition host.
Security posture
-
Security Posture
Transport encryption (
TLS) and client authentication are standard on all connections. The managed cloud tenancy is operated with logging and monitoring controls. -
The managed cloud tenancy is operated with logging and monitoring controls.
-
Private peering or VPN arrangements are available where required for compliance or security.
Systems preparation checklist
-
Choose gateway approach and confirm interface (serial or IP).
-
Agree authentication and certificate lifecycle.
-
Record required outbound firewall rules and broker endpoints.
-
Define buffering and acceptable replay latency.
-
Estimate data volumes and plan carrier/APN details for cellular links.
-
Agree acceptance tests for cloud ingestion and central monitoring.
Key takeaway
Orbalux accepts secure, outbound-only telemetry from a range of on-site systems using managed broker services and gateway patterns that preserve on-site isolation where required. Agree gateway approach, authentication, buffering and acceptance tests before integration so cloud ingestion and operations are predictable and secure.