
Page 6 of 22
Chapter 2:
Network Setup
Background
AXON® on-officer camera systems capture video and audio recordings. When the
AXON user(s) finish their shifts, the AXON system is docked into the EVIDENCE.com
Dock. The EVIDENCE.com Dock uploads the content securely via 256-bit SSL to
EVIDENCE.com. Using an agency account on EVIDENCE.com, AXON users can review
the content, create clips, share evidence with other personnel in the organization,
and download videos.
Network Requirements
To get the EVIDENCE.com Dock up and running, you may need some assistance from
your IT department.
Although the EVIDENCE.com Dock has been hardened against external intrusion, it is
STRONGLY recommended that the Dock be placed behind a standard firewall device.
CAUTION
DO NOT
place the EVIDENCE.com Dock directly on the Internet. Doing so could make your
system vulnerable.
The EVIDENCE.com Dock and AXON devices do not require any incoming data ports
for regular operation. All EVIDENCE.com Dock communications are outbound. All
video and data files are transmitted securely using HTTPS and 256-bit AES
encryption. For proper operation, the EVIDENCE.com Dock requires port 443 (TCP)
opened for outgoing traffic to prod.evidence.com. This is used by the EVIDENCE.com
Dock to send video and data files to EVIDENCE.com using the HTTPS protocol.
If the EVIDENCE.com Dock is placed on a network that utilizes external DNS servers,
then port 53 (UDP) must be opened for outgoing traffic to allow the EVIDENCE.com
Dock to access those servers.
The EVIDENCE.com Dock uses one of four methods to synchronize the clocks on the
AXON devices:
1.
HTTP over port 80 (TCP) to synchronize time from prod.evidence.com;
2.
HTTP over port 80 (TCP) to synchronize time from google.com;
3.
NTP over port 123 (UDP) to synchronize time from pool.ntp.org; or
4.
NTP over port 123 (UDP) to synchronize time from a Network Time Server
located on the default gateway assigned to the EVIDENCE.com Dock.
The EVIDENCE.com Dock requires only one of the above methods to be available.
Method #4 is the most secure, requiring no additional ports to be opened in a