What a gateway does
A mesh network is a local network: devices talk to their neighbours and pass messages along. Many applications also need something outside the mesh, such as a cloud service, a building management system or a phone that cannot speak the mesh’s protocol. A gateway is the device that connects the two.
To do that, a gateway sits on both networks at once. It has a radio or interface on the mesh side and another on the outside, such as Wi-Fi, Ethernet or cellular. Traffic that crosses it usually has to be translated, because the two sides use different radios, packet formats or addressing. A gateway is also a natural point to filter, since everything that enters or leaves the mesh passes through it.
Gateways in common standards
The idea appears under different names in most mesh and low-power standards.
Thread Border Router. Thread is an IPv6 mesh for home and building devices. A Thread Border Router connects a Thread network to other IP networks such as Wi-Fi or Ethernet, and OpenThread states that a Thread network needs one to reach other networks. At minimum it provides two-way IP connectivity, two-way service discovery between the Thread side and the Wi-Fi or Ethernet side, and external commissioning, so that a phone can authenticate a new device and join it to the network. It can also merge Thread partitions, groups of Thread devices that have lost radio contact with each other, over an IP link. Any Thread device may act as a Border Router, and a network can have several.
Bluetooth Mesh proxy. Bluetooth Mesh devices normally exchange messages using Bluetooth LE advertising. Some devices, such as phones whose operating system does not give apps suitable advertising access, cannot use that bearer. The Bluetooth SIG defines a proxy feature for them: a proxy node relays mesh messages between the advertising bearer and a GATT connection, using the proxy protocol. A phone connects to the proxy node like any Bluetooth LE peripheral and reaches the rest of the mesh through it.
LoRaWAN gateways. In LoRaWAN, gateways receive radio messages from end devices, convert them into IP packets, and forward them to a network server. Strictly, LoRaWAN is a star-of-stars network rather than a mesh, but its gateways play the same bridging role. Mesh networking vs LoRaWAN compares the two designs.
Gateway vs relay
A relay and a gateway both forward traffic, which makes them easy to confuse.
| Relay node | Gateway | |
|---|---|---|
| Connects | Devices within one mesh | The mesh to another network |
| Translates | Usually nothing; it passes messages on in the same format | Between radios, protocols or addressing schemes |
| If it fails | Traffic can take another path through the mesh | The mesh loses that route to the outside |
| Typical position | Anywhere in the mesh | At its edge, with a second connection |
One device can be both. A phone in a mesh might relay messages between neighbours over Bluetooth LE and also carry some of them to a server over its mobile data connection.
What a gateway should be trusted with
Because a gateway sees everything that crosses it, its position carries risk. If content is encrypted end to end, the gateway carries ciphertext it cannot read, but it can still see traffic volume and timing, and it can drop or delay messages.
A more subtle problem is what a gateway’s acknowledgment means. When a gateway accepts a message, it has received it; that does not mean the destination has. The server behind it might reject the message, crash before storing it, or never receive it if the gateway’s own uplink fails. An application that needs certainty should wait for an end-to-end delivery receipt from the destination, and treat delivery and acceptance as separate outcomes.
Offline Protocol’s documentation is explicit about both. A gateway is provisioned against a defined contract covering identity, delivery verdicts and recovery, and a device that happens to have internet access does not automatically become a trusted upload destination. Its security docs record that gateway delivery is not authenticated proof that the destination accepted a message, and tell applications to verify application receipts.
Designing with gateways
A few habits make gateways less of a weak point.
- Plan for more than one. Thread allows several Border Routers in one network. Where a deployment depends on reaching the outside, more than one gateway avoids a single point of failure.
- Expect the gateway to disappear. When a mesh loses its only gateway, it is cut off from the wider network, a network partition between the mesh and everything beyond it. Devices should keep working locally and queue outbound data, using store-and-forward delivery until a gateway returns.
- Choose gateways deliberately. Decide in advance which devices may act as gateways, how they authenticate to the outside service, and what they are allowed to forward.
- Confirm end to end. Treat a gateway’s acknowledgment as progress, not completion.