Issue
Clarification is required on whether BACnet/IP communication for MP-C, AS-P, and EcoStruxure Building Operation can use TCP instead of UDP, and which devices must be whitelisted in firewall configurations.
There may also be uncertainty regarding BACnet/SC support and communication paths for BACnet/IP Controllers, such as the MP-C, RP-C range of devices, and third-party devices.
Product Line
EcoStruxure Building Operation
Environment
-
EcoStruxure Building Operation (EBO) 3.2 or later
-
Automation Servers
- BACnet/IP, BACnet/SC, BACnet MS/TP
- SpaceLogic MP‑C / MP‑C Pro / MP‑V
- SpaceLogic RP‑C / RP‑C Pro / RP‑V
Cause
BACnet/IP communication runs over UDP and does not support TCP. BACnet/SC is a separate communication method that uses TCP-based secure connections. Additionally, standard EcoStruxure Building Operation communication routes MP-C traffic through the AS-P rather than directly to the Enterprise Server.
Resolution
BACnet/IP must remain UDP-based and cannot be changed to operate over TCP. If TCP-based communication is required, BACnet/SC must be used as it provides TLS-encrypted WebSocket communication over TCP and requires certificate-based trust between devices.
For firewall configuration:
- For BACnet/SC: All devices that need to communicate with the BACnet/SC hub must be allowed through the firewall, as communication uses a hub-and-spoke architecture with outbound connections to the hub.
- For standard EcoStruxure Building Operation communication (non-BACnet/SC), MP-C devices communicate via the AS-P, so only the AS-P needs to be whitelisted on the Enterprise Server firewall.
If a third-party device does not support BACnet/SC, it cannot participate in BACnet/SC communication.
Other considerations:
Before recommending firewall rules or BACnet/SC adoption, ensure the customer's complete network and security requirements are understood. Requests for "whitelisting" or replacing UDP with TCP can sometimes indicate a broader network segmentation or security requirement rather than a BACnet protocol limitation.
Consider gathering additional information regarding:
- The overall system architecture and communication paths.
- The specific security or compliance requirement driving the request.
- Whether network segmentation, isolation, or traffic restriction is the primary objective.
Alternative approaches that may satisfy the requirement include:
- Network switch-based access controls, such as MAC address filtering, port security, or other switch-level whitelisting mechanisms.
- VLAN segmentation to isolate BACnet/IP networks, including secondary or site-specific BACnet networks.
- Deploying edge servers with multiple network interfaces, where a secondary BACnet network can be connected through a dedicated interface or VLAN.
- Isolating the Building Management System (BMS) / Operational Technology (OT) network within the network infrastructure rather than relying solely on host-based firewall restrictions.
Understanding the customer's full architectural requirements helps ensure the most appropriate network design is recommended rather than focusing only on protocol-level configuration options.