LK-IP/KNXs
REG
Operating Manual
7
LK-IP/KNXs REG
90403
3.2.4
KNX Data Security for the device
The LK-IP/KNXs REG also supports KNX Data Security to protect the device from unauthorised
access from the KNX bus. If the KNX IP router is programmed via the KNX bus, this is done with
encrypted telegrams.
3.2.5
KNX Data Security for group telegrams
Telegrams from the bus that do not address the KNX IP router as a device are forwarded or blocked
according to the filter settings (parameters and filter table). It does not matter whether the tele
-
grams are unencrypted or encrypted. Forwarding takes place exclusively on the basis of the desti
-
nation address. The security properties are checked by the respective recipient.
KNX Data Security and KNX IP Security can be used in parallel. In this case, for example, a KNX
sensor would send a group telegram encrypted with KNX Data Security to the bus. When
forwarding via KNX IP with KNX IP Security, the encrypted telegram would be encrypted again just
like unencrypted ones. All participants on the KNX IP level that support KNX IP Security can decode
the IP encryption, but not the data security.
Thus the telegram from the other KNX IP routers is again transmitted to the target line(s) with KNX
Data Security. Only devices that know the key used for data security can interpret the telegram.
3.2.6
Coupler function (KNXnet/IP Routing)
The LK-IP/KNXs REG operates as a line or backbone coupler. In both cases, the LAN (IP) is used as a
backbone.
The following table shows the application possibilities of the LK-IP/KNXs REG compared to the
classic topology:
INFO
Encrypted telegrams!
Encrypted telegrams are longer than the previously used unencrypted ones. For secure
programming via the bus, it is therefore necessary that the interface used (e. g. USB) and
any intermediate line couplers support the so-called KNX long frames.
Classical Topologie
(without IP)
IP coupling
of areas
(IP area coupler)
IP coupling
of lines
(IP line coupler)
Area
(Backbone)
TP
IP
IP
Coupling
KNX line coupler
(max. 15 pcs.)
KNX IP router
(max. 15 pcs)
direct via
LAN switch
Main line
TP
TP
IP
Coupling
KNX line coupler
(max. 15 x 15 = 225 pcs.)
KNX line coupler
(max. 15 x 15 = 225 pcs.)
KNX-IP-router
(max. 15 x 15 = 225 pcs.)
Line
TP
TP
TP