iSTAR Edge G2 Controller Installation and Configuration Guide 80
Chapter 9 - Diagnostics
Digital Certificate Signing Troubleshooting
The iSTAR Edge G2 uses TLS 1.3 encryption and controller-based certificates for Panel-Host communications. To take
advantage of this more secure method of communication, port 28013 on the Host, and port 28014 on the panel, in addition to
the standard ports for Host and iSTAR communication, must be unblocked by firewalls to enable Certificate Signing Requests
to be communicated between the panel and the Host after the initial configuration is complete.
Common Certificate Signing Request (CSR) Errors
Common CSR errors can often be rectified by trouleshooting the items in Table 25. Further troubleshooting steps for Host PCs
are detailed in.
Table 25:CSR State and Troubleshooting
State
ID
State Description LCD Error Message
(If Error occurs)
Possible Causes Common Solutions
1 Connect To
CSR Port
Panel attempts to make a
connection to host port 28013
• Err: Conn Refused
• Invld IP or Port
1. Host IP and port is
unreachable
2. Firewallis blocking
communication
(port)
3. Port 28013 may not
be open.
4. Port 28013 may be
blocked.
• Check your firewall
status with
Resource Monitor.
• Ensure firewalls
are not preventing
CSR
communications.
• Ensure the correct
ports are open and
unblocked.
2 Send CSR Panel sends CSR to host and wait
for acknowledgment from host
• Err: CSR Sent!
• No Ack from Host
1. Host does not
receive CSR
2. Host internal error
(See
Troubleshooting the
Host PC)
• Ensure firewalls
are not preventing
CSR
communications.
3 Open
Certificate
Port
Panel tries to open certificate
receive port 28014 for host's
response
• Err: Open CSRcev
• Port 28014 Fail!
1. Port 28014 may be
blocked.
2. Panel internal error
• Ensure firewalls
are not preventing
CSR
communications.
• Collect panel log
and send to SWH
support.
4 Wait For
Certificates
Panel successfully opens 28014
port and is waiting for connection
from host to deliver certificates or
reject
• Err: No Conn from
• Host. Rcv Timeout
1. Firewallis blocking
communication
(port)
2. Cluster/Controller is
disabled
3. Host and panel IP
mode (IPv4/IPv6) or
address do not
match
• Ensure firewalls
are not preventing
CSR
communications.
• Ensure Host and
panel IP modes
and address
match.