Secure Remote Access to BACnet Systems
The Internet makes it possible for sys- sages through the IP router to its partner BBMD practice to change this port to a non-standard
tems integrators to easily manage build- devices. The receiving BBMD device retrans- port if communicating over the Internet. The IP
ings from the comfort of their home or mits it as a broadcast message to its local net- routers/firewalls also provide additional features
office. Initial commissioning, remote diag- work. You can configure each BBMD with the IP that should be utilized. A list of IP addresses that
nostics and troubleshooting of the building addresses of all other BBMDs or have all BBMDs can communicate through the firewall can be
provide additional savings over the build- send their broadcast messages to one cen- specified on the Internet facing firewall. Some
ing’s lifetime. tral BBMD, however, all client devices must uti- BACnet routers also provide this Allowlist fea-
lize the central BBMD. These entries go into the ture. BACnet/IP communication occurs over
Remote access can be achieved using various BBMD’s Broadcast Distribution Table (BDT). It is UDP and is unencrypted. Using VPNs can pro-
methods – some are more secure than oth- possible to have more than one BBMD device on vide additional security by encrypting the traf-
ers. Fortunately, the Building Automation indus- a single subnet and care must be taken while fic over the Internet and restricting communica-
try is dominated by the BACnet protocol, and configuring BDT entries. A duplicate entry in tion to only authorized VPN endpoints. There is
its IP version, BACnet/IP, lends itself well to all BBMD devices will result in broadcast loops. no need to use non-standard BACnet UDP Ports
Simplify BACnet/BMS Integration
Typical Typical setup connecting 2 Buildings using Port Forwarding and BBMDs. © Contemporary Controls
the enhancements and techniques deployed in Many BACnet/IP devices or applications also with VPNs. Setting up firewall rules or VPNs • BACnet routers link IP networks to
the Information Technology (IT) world. Common support a feature called Foreign Device Regis- requires help from the IT department while the BACnet MS/TP
techniques for remote access involve the use of tration (FDR). FDR allows the BACnet/IP device BMS professional can configure the non-stan-
Port Forwarding through a firewall, setting up or application to send its messages to a BBMD dard BACnet UDP port on their own. • Gateways adapt Modbus and EnOcean
BBMDs, and the use of VPNs. But the security which then forwards broadcast messages to all Supervisors Routers devices to BACnet
provided and their ease of setup for BACnet sys- other BBMDs and all other FDR devices. If a sub- Security with BACnet/SC Datalink
tems varies. IP routing with Firewalls and VPNs net has only FDR supported devices, then it does • Supervisors provide BACnet/IP client
The open nature of BACnet/IP and broadcast
traffic created some pushback from IT departments. BACnet Secure Connect (BACnet/SC)
was released to address these concerns by
incorporating the widely used IT security practices. BACnet/SC used connection-oriented
Remote Access with BACnet/IP net. This setup is used to connect buildings or incorporating the widely used IT security prac-
TCP instead of UDP and TLS 1.3 for security
with encrypted communications. Each device
tially discover other devices. BACnet communi- with encrypted communications. Each device
must be authorized to be on the network and
assigned a certificate and key. The broadcast
discovery protocol and BBMD have been eliminated. BACnet/SC uses a hub and node model.
Devices/nodes primarily communicate via the
BACnet/SC hub with standard provisions for
BACnet broadcast messages as directed mes- standard BACnet UDP Port 47808. It is good BACnet/SC hub with standard provisions for
Providing Solutions to Your Automation Needs
