Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

We Value Your Feedback!
Could you please spare a few minutes to share your thoughts on Cloud Connected vs On-Premise Services. Your feedback can help us shape the future of services.
Learn more about the survey or Click here to Launch the survey
Schneider Electric Services Innovation Team!

Niagara 4.9+ and IT Network Scanners

Building Automation Knowledge Base

Schneider Electric Building Automation Knowledge Base is a self-service resource to answer all your questions about EcoStruxure Building suite, Andover Continuum, Satchwell, TAC…

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Building Automation Knowledge Base
  • Niagara 4.9+ and IT Network Scanners
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • Intelligent Devices Forum

Previous Next
Contributors
  • JonGreen
    JonGreen
  • RandyDavis
    RandyDavis

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Building Automation Knowledge Base
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
0 Likes
1426 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

Niagara 4.9+ and IT Network Scanners

Guinan RandyDavis Guinan
‎2021-04-30 10:45 AM

Last Updated: Guinan RobertAndriolo Guinan ‎2021-05-02 05:38 PM

Issue

Network scanning software causes a loss of Jace network communication.

Product Line

TAC IA Series

Environment

I/A Series Jace 8000 N4.9 and later

Cause

As network security awareness continues to expand, software-based scanners, such as industry-standard Qualys and Nessus, intended to detect and report on vulnerabilities within internal networks will likely continue to gain popularity.  Today, Tridium is seeing these scanners being deployed and run against Niagara-based platforms like the JACE-8000 and Edge 10.  In some cases, these scans are causing Niagara platforms to become unresponsive or reboot via an Engine Watchdog Timeout, all of which are not acceptable for the critical applications that Niagara facilitates.

Resolution

While Tridium has no control over how these scanners behave, or how and when they are executed within an organization, Niagara 4.9 introduces a number of changes intended to allow a Niagara-based hardware platform to appropriately respond to the scanning utilities, and also maintain operation.  Below is a brief explanation of how Niagara will function under the different known circumstances currently employed by these scanners, and how to interpret the results.

 

Recognition of non-Niagara Traffic on the platform
In the event a scanner is interrogating a Niagara 4.9+ platform connection, the Niagara Daemon has been modified to recognize non-Niagara traffic over a period of time, shut down the connection if necessary, and wait for a pre-determined amount of time before re-enabling connectivity.  Under these conditions, a scanning utility may report that the Niagara instance has encountered denial of service, when in fact, Niagara has simply disabled the communication mechanism by which the scanner was attempting its interrogation. During this time, normal platform communication will also be affected; however, the Niagara platform and station will continue to run.

 

Prioritization of Internal vs. External Communication on the Niagara station
In the event, a scanner is interrogating a Niagara 4.9+ station (external communication) and Niagara detects that this interrogation may cause an Engine Watchdog Timeout, the station’s web server will be stopped and restarted. Under these conditions, a scanning utility may report that the Niagara instance abruptly stopped communicating, and may have encountered denial of service.  During this time period, normal/expected client web connections to the station will also be affected; however, the Niagara platform and station will continue to run.

As mentioned, these scanners are outside the control of Tridium, and likely always evolving to meet the needs of the various threats they are intended to protect against. As a best practice, Tridium recommends not scanning in production if possible, as any findings would be just as legitimate during scheduled downtime. Additionally, it may be prudent to work with the scanning tools to configure the appropriate priority of a scan, as the intensity of which you scan a production multicore, failover redundant web server host, is likely not the best choice for scanning a single-core JACE.

Should you encounter an issue with a network scanning utility and Niagara 4.9 and above, please contact your support organization.

Labels (1)
Labels:
  • TAC IA Series
Tags (1)
  • Find more articles tagged with:
  • RandyDavis21
Was this article helpful? Yes No
0% helpful (0/1)

Link copied. Please paste this link to share this article on your social media post.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of