Intelligent IP-Enabled Access Control Solutions

Similar documents
Internet Access: Wireless WVU.Encrypted Network Connecting a Windows 7 Device

Network. NEC Portable Projector NP905/NP901W WPA Setting Guide. Security WPA. Supported Authentication Method WPA-PSK WPA-EAP WPA2-PSK WPA2-EAP

ENH200 LONG RANGE WIRELESS 11N OUTDOOR CB/AP PRODUCT OVERVIEW. IEEE802.11/b/g/n 1T+1R 150Mbps 25 km High Performance

Configuring a VAP on the WAP351, WAP131, and WAP371

EAP600 Dual Band Long Range Ceiling Mount Access Point

EAP300 v2. Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

Enterprise WiFi System. Datasheet. 4Gon Tel: +44 (0) Fax: +44 (0)

2.4GHz 300Mbps 11b/g/n 29dBm AP/Router/WDS Bridge/WDS AP/WDS station/cb/cr/up. Software Features System Requirement. Status

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-Pro, UAP-Outdoor, UAP-Outdoor5

EnGenius EAP-9550 Indoor Access Point

Wireless 300N Gigabit Gaming Router 2.4GHz Gigabit Ethernet / Stream Engine 11N 2x2 (300Mbps)

EOR7550. Dual Radio Multi-Function AP. 2.4GHz / 5GHz 300Mbps a/b/g/n Multi-Function

M a/b/g Outdoor Layer-2 MESH AP

PACKAGE CONTENT TECHNICAL SPECIFICATION. Ethernet: One 10/100 Fast Ethernet RJ-45. Power Jack Power Status. LAN (Internet connection)

2.4GHz / 5GHz 54Mbps a/b/g Flexible Application

Add a Wireless Network to an Existing Wired Network using a Wireless Access Point (WAP)

EAP150. Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

iconnect625w Copyright Disclaimer Enabling Basic Wireless Security

ECB7510. Wireless Gigabit Dual Band Concurrent Router AP PRODUCT DESCRIPTION

Dual Band Long Range Multi-Function Access Point/ Client Bridge. Software Features System Requirement. Status

PRODUCT OVERVIEW. Learn more about EnGenius Solutions at

EOA7530. Dual Radio Concurrent AP/CB. 2.4GHz / 5GHz 54Mbps a/b/g Flexible Application

GHz g. Wireless A+G. User Guide. Notebook Adapter. Dual-Band. Dual-Band WPC55AG a. A Division of Cisco Systems, Inc.

Using PEAP and WPA PEAP Authentication Security on a Zebra Wireless Tabletop Printer

Wireless-N. User Guide. USB Network Adapter WUSB300N WIRELESS. Model No.

Models: UniFi AP-Mini (UAP-Mini), UniFi AP (UAP), UniFi AP-Long Range (UAP-LR), UniFi AP-Outdoor (UAP-Outdoor)

EAP350 EAP350. Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

EOR7550 Dual Radio Multi-Function Repeater 2.4 GHz/ 5.0 GHz a/b/g/n 300 Mbps Multi-Function

Basic Wireless Settings on the CVR100W VPN Router

Enterprise WiFi System. Datasheet. Models: UAP, UAP-LR, UAP-Outdoor, UAP-Mini. Unlimited Indoor/Outdoor AP Scalability in a Unified Management System

Zebra Mobile Printer, Microsoft IAS, Cisco Controller TLS and WPA-TLS, Zebra Setup Utility

Cisco Exam Questions and Answers (PDF) Cisco Exam Questions BrainDumps

Enterprise WiFi System. Datasheet. 4Gon Tel: +44 (0) Fax: +44 (0)

PRODUCT OVERVIEW SOFTWARE FEATURES. System Windows Windows7, 98, ME, NT, XP, Mac OS X (10.4) System Status MAC, LAN MAC, Country, Current Time,

PRODUCT DESCRIPTION. Learn more about EnGenius Solutions at

Configuring 802.1X Authentication Client for Windows 8

Authentication and Security: IEEE 802.1x and protocols EAP based

EAP600 AU Datas heet Version SOFTWARE FEATURES. Dual Band Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

ECB N Multi-Function Client Bridge

ENH700EXT N Dual Radio Concurrent AP PRODUCT OVERVIEW

H210 AU. Point, Client Bridge, Client Router and WDS.

Figure 35: Active Directory Screen 6. Select the Group Policy tab, choose Default Domain Policy then click Edit.

ENH900EXT N Dual Radio Concurrent AP. 2.4GHz/5GHz 900Mbps a/b/g/n Flexible Application

NCR. Wi-Fi Setup Assistant. User guide

A Division of Cisco Systems, Inc. GHz g. Wireless-G. PCI Adapter with SRX 400. User Guide WIRELESS WMP54GX4. Model No.

Package Content IEEE g Wireless LAN USB Adapter... x 1 Product CD-ROM.x 1

EOC5611P. Wireless a/b/g Outdoor AP. Package Content PRODUCT DESCRIPTION. 2.4GHz / 5 GHz 54Mbps a/b/g 24V PoE

Windows 7 Configuration for ORU Wireless Networks

ECB3500 Wireless Long Range Multi-function 7+1 AP

11N Wall Mount Access Point / WDS AP / Universal Repeater. Features. Fully compatible with IEEE b/g/n devices

ECB3500 Wireless Long Range Multi-function 7+1 AP 2.4GHz Super G 108Mbps EIRP up to 2000mW

M5000. Wireless a/b/g Outdoor AP PRODUCT DESCRIPTION

Network User s Guide

Instructions for connecting to the FDIBA Wireless Network (Windows Vista)

EOC1650. Wireless Access Point / Client Bridge / Client Router PRODUCT DESCRIPTION. 2.4GHz 54Mbps b/g Superior Performance

Cisco Desktop Collaboration Experience DX650 Security Overview

UAP- Interior UAP OUTDOOR (UniFi)

EOC-2610 Long Range Wireless Access Point / Client Bridge

Install Certificate on the Cisco Secure ACS Appliance for PEAP Clients

ESR9855G Wireless 300N Gigabit Gaming Router

Quick Start Guide for Standalone EAP

EAP150 EAP150. Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

ENH1750 EXT ENH1750 EXT

EAP9550 is a powerful and multi-functioned 11n Access Point

Intelligraphics Qualcomm Atheros Windows CCXv4 Product Specification

Wireless Router at Home

M5000. Wireless a/b/g Outdoor AP PRODUCT DESCRIPTION

Connect to eduroam WiFi

EAP150 EAP150. Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

ECB GHz Super G 108Mbps Access Point/Client Bridge/Repeater/WDS AP/

Configuring Cipher Suites and WEP

M5000 Wireless a/b/g Outdoor AP

ECB N Multi-Function Gigabit Client Bridge

Configuring the Client Adapter through Windows CE.NET

EOC2611P. Long Range Wireless Access Point / Client Bridge PRODUCT DESCRIPTION. 2.4GHz 108Mbps b/g/super G MSSID, WDS

AmbiCom WL11-SD Wireless LAN SD Card. User Manual

EVR b/g/n VPN Router PRODUCT DESCRIPTION

simplifying... Wireless Access

PRODUCT OVERVIEW SOFTWARE FEATURES. Windows Windows7, 98, ME, NT, XP, Mac OS X (10.7) System Information. Current Wireless Setting

EOC5611P. Wireless a/b/g Outdoor AP PRODUCT DESCRIPTION. 2.4GHz / 5 GHz 54Mbps a/b/g 24V PoE

Instructions for connecting to winthropsecure

Access Connections 5.1 for Windows Vista: User Guide

EAP150 EAP150. Long Range Ceiling Mount Access Point PRODUCT OVERVIEW

2.4GHz 108Mbps b/g/Super G MSSID, WDS

A Division of Cisco Systems, Inc. GHz g. Wireless-G. USB Network Adapter. User Guide WIRELESS WUSB54G. Model No.

EOC1650. Wireless Access Point / Client Bridge / Client Router. 2.4GHz 54Mbps b/g Superior Performance

Instructions for connecting to the FDIBA Wireless Network. (Windows XP)

EOC Wireless a/b/g Outdoor AP 2.4GHz / 5GHz 54Mbps a/b/g 24V PoE

Configuring the WT-4 for ftp (Infrastructure Mode)

Configuring the EAPs Separately via Omada Controller

Using EAP-TTLS and WPA EAP-TTLS Authentication Security on a Wireless Zebra Tabletop Printer

MSM320, MSM410, MSM422, MSM430,

Rhodes University Wireless Network

ECB3500 Wireless Long Range Multi-function 7+1 AP

EOC GHz / 5GHz 54Mbps a/b/g 24V PoE

Configuring a Wireless LAN Connection

Software Manual Net Configuration Tool Rev. 4.05

ENH900 EXT ENH900 EXT. Wireless 11N Outdoor Dual Band Dual Concurrent AP /CB PRODUCT OVERVIEW

Datasheet. Enterprise WiFi System. Models: UAP, UAP-LR, UAP-Outdoor, UAP-Mini. Unlimited Indoor/Outdoor AP Scalability in a

AXIS M1065-LW Network Camera. User Manual

Transcription:

IP-Enabled Locks: Facts for IT

Intelligent IP-Enabled Access Control Solutions The information sent over a site-wide 100 lock deployment in 24 hours is the size of a standard email message PoE and ESD Because PoE locks may be more susceptible to electrostatic discharge (ESD), please note the following requirements: All PoE locks: Shielded Category 5/6 cable with drain wire from the lock to building or electrical ground Access 800 and Profile Series v.s1: Shielded cable with drain wire back to the PoE switch What is the Impact on Your Network? ASSA ABLOY IP-Enabled locks take advantage of Power over Ethernet (PoE) or WiFi network infrastructure to provide increased security and easier, more cost-effective installations. Like any other equipment you would consider adding to your network, you need the proper information to verify the security and other potential impacts of these devices. This document is intended to provide that information. If you have any concerns that this document does not address, please contact your local ASSA ABLOY Integrated Solutions Specialist for more information. Bandwidth On average, a PoE or WiFi lock transmits a total of 5-10 kb data per day. Each lock has a maximum memory of 3 MB and therefore can transmit no more than 3 MB of data. 3 MB transfers are only possible during initial setup or after a sustained network outage. IP Address Statically assigned DHCP Networks WiFi: IEEE 802.11b/g/n (2.4GHz) Power over Ethernet: IEEE 802.3af - Access 700 PIP1, Passport 1000 P1, IN220: Class 1 (3.84 watts max) - Access 800 IP1, Profile Series v.s1: Class 2 (6.49 watts max) Ports User-definable TCP port (default 2571 TCP inbound/outbound) Applicable Products Corbin Russwin Access 700 PWI1 Corbin Russwin IN120 Sargent IN120 Sargent Passport 1000 P2 Certificate Constraints (applies to both radios) All certificates must be DER encoded binaries. Binary file extension can be.cer,.der, or other. The Client Private Key must have its password removed.

Important Considerations Security Virtual Local Area Network (VLAN) Operation Although not required for a successful deployment, a common practice with IP-based security products is the creation of a security VLAN This typically consists of only the IP locks and their associated server When creating the VLAN, a unique SSID is created and tied to the security VLAN (the SSID is often hidden) By allowing for the VLAN to be administered separately, this helps alleviate issues related to changing wireless keys or encryption types WiFi ASSA ABLOY WiFi locks are configurable to connect to the facility s WiFi network as scheduled by the user At each connection, the radio is powered up, and the lock associates with the WiFi network to transmit/ receive 5-10kB of data to/from the server When it is not communicating with the server, the wireless radio is powered down, disconnecting it from the WiFi network completely Hard powered WiFi locks can be set to remain associated and online full time

PoE During initial power up, the ASSA ABLOY PoE lock establishes a connection and begins communication with the server The PoE lock transmits 5-10kB of data spaced out over the course of a 24-hour period The lockset remains online at all times as a standard Ethernet connected device This data transmission also includes typical daily management tasks Fallback Operation In the event of a network outage, the locks will continue to operate using a locally-stored database from the last contact with the server While the network is down, updates to the lock and transmission of event records or alarm notifications are not possible Failure of communication will be reported to the access control system administrator based on conditions set in the access control system

Security ASSA ABLOY IP-Enabled locks offer Data Security standard wireless security and ASSA ABLOY PoE and WiFi locks support an optional AES 128 bit encryption at the lock protocol level. This is in addition to any WiFi network encryption that may be used, and ensures data security, even on open networks. data encryption methods. WiFi Encryption & Authentication support for a wide range of ASSA ABLOY WiFi locks are equipped with GainSpan WiFi radios. The table below provides information on the encryption and authentication capabilities of these radios. GainSpan GS1500 Radio Firmware Version 3.5.5 Firmware Version 3.5.9/3.5.10 WiFi Encryption Types 802.1X (Enterprise) Encryption Types WPA(2) PEAP WPA(2) EAP-TTLS WPA(2) EAP-TLS Open WEP64 WEP128 WPA(2)-Personal (AES or TKIP) Open WEP64 WEP128 WPA(2)-Personal (AES or TKIP) WPA(2) PEAP WPA(2) EAP-TTLS WPA(2) EAP-TLS GainSpan GS2011 Radio Firmware Version 5.2.3/5.5.1 Open WEP64 WEP128 WPA(2)-Personal (AES or TKIP) WPA(2) PEAP WPA(2) EAP-TTLS WPA(2) EAP-TLS Maximum Hash Algorithm SHA1 SHA1* SHA2 Maximum Characters in Username and Password Fields 32 32 32 Maximum RSA Key Strength 1024 bits 1024 bits 4096 bits Certificate File Size Limit < 2KB per certificate/file (Root CA, Client, Client Private Key) < 4KB total < 2KB per certificate/file (Root CA, Client, Client Private Key) < 4KB total < 256KB for all three certificates/files (Root CA, Client, Client Private Key File) * On GainSpan GS1500 Firmware Version 3.5.9, the server certificate (the certificate initially presented to the client) can be encrypted using the SHA256 hash algorithm. However, all certificates loaded in the radio must be SHA1 or lower.

ASSA ABLOY Americas 110 Sargent Drive New Haven, CT 06511 (800) DSS-EZ4U (377-3948) (203) 624-5225 Copyright 2018 ASSA ABLOY Sales and Marketing Group Inc.; all rights reserved. Reproduction in whole or in part without the express written permission of ASSA ABLOY Sales and Marketing Group Inc. is prohibited. 2500-3791 5/18