250929_LSS100100/LSS100200_SW_03.0

About the Document

Document Scope

This document outlines the features and programming interface for the spaceLYnk and Wiser for KNX controllers (referred to as the “controller”). The software programming interface is integrated within the controller and can be accessed via a web browser. It is essential to note that pre-programming and configuration tasks are only possible with the controller. Before proceeding with installation, operation, or maintenance, carefully review the instructions and become acquainted with the device.

Validity Note

This document is applicable to both the Wiser for KNX and spaceLYnk controllers. The information provided herein is relevant to the features, programming interfaces, and operational guidelines for these controllers. Ensure that you refer to this document for accurate and up-to-date instructions and specifications for both devices.

General Cybersecurity Information

In recent years, the growing number of networked machines and production plants has seen a corresponding increase in the potential for cyber threats, such as unauthorized access, data breaches, and operational disruptions. You must, therefore, consider all possible cybersecurity measures to help protect assets and systems against such threats.

To help keep your Schneider Electric products secure and protected, it is in your best interest to implement the cybersecurity best practices as described in the Cybersecurity Best Practices document.

Schneider Electric provides additional information and assistance:

Product Related Cybersecurity Information

To enhance the security of your controller, consider the following best practices:

  1. Network security:

    • Set up network security at an appropriate level.

    • Ensure that your controller is part of a secure network with limited access.

    • If connected to the Internet, strictly recommend using either a VPN or an HTTPS communication.

  2. Secure protocol access:

    • Use the secure protocol HTTPS://IP:Port to access your controller.

  3. Security measures:

    • Evaluate the security capabilities of other network elements, such as firewalls and protection against viruses and malware threats.

    • Store backup files in a safe location inaccessible to unauthorized individuals.

  4. Public IP address:

    • Verify that your controller does not have a publicly accessible IP address.

    • Avoid using port forwarding to access your controller from the public Internet.

  5. Network segmentation:

    • Place your controller on its own network segment.

    • If your router supports a guest network or VLAN, consider locating controller there.

  6. Cybersecurity incidents and vulnerabilities:

  7. HTTP communication warning:

    • If HTTP communication is detected, switch to HTTPS (encrypted mode).

    • Note that your controller comes with a self-signed SSL certificate, which encrypts information. Web browsers may display a warning message when confirming the exception to proceed.

  8. KNX installation security:

    • When accessing the KNX installation via the Internet, be aware that data traffic can be read by third parties.

    • Always use a VPN connection with secure encryption for all data packets.

    • Hardware requirements for VPN routers and features offered by mobile service providers may vary significantly.

  9. KNX data secure: If you have data secure devices in your KNX installation and need your controller to communicate directly with these devices (sending and receiving data secure telegrams), follow these steps:

    1. Add the controller secure dummy device:

      • Integrate the controller secure dummy device into your KNX installation.

      • You can use the SpaceLogic KNX Secure Dummy device provided by Schneider Electric available in the ETS catalogue.

      • Connect the individual group addresses of the data secure device to your controller dummy device.

    2. Controller as a router:

      • If your controller functions as a router (facilitating communication between KNX devices), you do not need the controller secure dummy device for secured KNX communication.

For additional details on system hardening, refer to Schneider Electric’s document: System Hardening Guidelines for Wiser for KNX and spaceLYnk Controllers.

Available Languages of the Document

The document is available in these languages:

Information on Non-Inclusive or Insensitive Terminology

As a responsible, inclusive company, Schneider Electric is constantly updating its communications and products that contain non-inclusive or insensitive terminology. However, despite these efforts, our content may still contain terms that are deemed inappropriate by some customers.

QR Code is a registered trademark of DENSO WAVE INCORPORATED in Japan and other countries.

Was this helpful?