Best Practices
Network
Network
- This is not a requirement, but can be considered a best practice for IoT style devices.
- High traffic devices(such as IP cameras) that share the same subnet as reader-controllersmay negatively impactthe controller’s ability to maintain a stable path of communication with Zentra.
- The # switch should have enough power to run all ports and account for in-rush.
- Although the IEEE specification allows for cable length to be up to 328 feet (100 meters), we recommend that the cable length be a short as practical, not exceeding 100 feet, to minimize voltage drop between the switch and the device.
- Online devices cannot navigate DHCP credential-oriented landing pages. For example, a Hotel Wi-Fi that would require you to sign in using your room number and last name or a university that would require credentials and a EULA acceptance to be able to access the internet.
Port Speeds
We recommend that the network switch/switches your reader controllers are running on are set to
10Mb full duplex
and that auto-negotiate is disabled
.Firewall
- IfIntrusion Detection and Preventionis enabled, double check the firewall logs for dropped packets with a source IP that matches a device and create bypass rules as needed.
- Afirewall egress ruleallowing the IP addresses of the devices is required.
- Note: The devicesdo not proxy.
- Multiple NATsandmultiple firewallsarestrongly discouragedas they can cause communication issues for the ISONAS devices.
- If these must be used for security purposes, ensure that all rules are configured properly and that the IP address and ports are free to communicate through the multiple layers of firewall and/or NAT.
Recommendation
: Create a group or VLAN for Zentra devices. Firewall rules will need to be created to allow traffic to the internet on ports 55533, 80, and 443 for both TCP and UDP. For any network admins looking to restrict access to only the destination IP addresses needed to communicate with Zentra’s web APIs, the list of IPs can be found at https://www.cloudflare.com/ips/. Please note that this list of IP addresses is subject to change. We strongly recommend that automation be used to keep the firewall ACL up to date with the listed Cloudflare IP ranges.
Contact your network administrator for help configuring your network.