BAS-SVX069F-EN
11
Qualifying Your Customer Site
The following questions have been designed to assist you in determining whether the Digi
Router firewall solution is appropriate for your customer.
IIss tthhee TTrraacceerr BBAASS oonn aa ““sshhaarreedd nneettwwoorrkk”” oorr aann ““iissoollaatteedd nneettwwoorrkk””??
A shared network is one in which the Tracer BAS controller exists on the same network as other
business related IT assets (for example, printers, PCs). An isolated network is one in which the
Tracer BAS controller (and other BAS related devices) are isolated on another network from
other business related IT assets.
If the Tracer BAS controller is on a shared network, careful consideration must be given to ensure
that business related IT assets are not disrupted. To avoid this possibility, it is recommended that
no changes be made to the existing networking equipment. This solution can be installed in front
of the Tracer BAS to block the inbound ports.
DDooeess tthhee ccuussttoommeerr hhaavvee aann IITT ssttaaffff??
This solution is meant to be deployed when the customer does not have an IT staff. If your
customer does have an IT staff and the Tracer BAS controller is on the customer’s network you
should communicate the proposed changes to existing network equipment to the IT staff in order
to follow Best Practices.
DDooeess yyoouurr ccuussttoommeerr nneeeedd rreemmoottee aacccceessss??
This solution is meant to block inbound IP ports to the Tracer BAS controller without making
changes to existing network equipment. Trane Connect Remote Access is the preferred method
for remote access for both Trane employees and customers. If needed, the Digi WR21 can be
configured to allow customer remote access through VPN (L2TP/IPSEC). Some configuration
changes may be required on the existing network equipment in order to facilitate this remote
access.
IIss tthheerree ootthheerr eeqquuiippmmeenntt oonn tthhiiss ssiittee tthhaatt iiss ccoommmmuunniiccaattiinngg wwiitthh tthhee TTrraacceerr BBAASS
ccoonnttrroolllleerr??
All BAS communicating devices must be installed behind the Digi WR21 Firewall on the BAS
Network in order for this solution to work. This includes Tracer BAS controllers, Tracer UC600s
communicating through BACnet/IP, and non-Trane BACnet devices. If you cannot place all BAS
communicating devices onto this BAS Network, this solution will not fit the needs of your project.