@florian-duecker I’ve revolved the issue by using the off the shelf OpenVPN option T-Mobile offers: Summarized for others&future:
The IoT Easy Connect LTE-M connectivity assings a private IP-range (in my case 10.42.242.0/24) to the sim-cards.
The IoT Easy Connect Portal>Settings>OpenVPN describes how to setup an OpenVPN connection to T-Mobile.
Activating this tunnel on my server enabled me to ping the devices and to carry out various connectivity test.