Network requirements
Check this with whoever runs your network before the reader arrives. Network rules cause almost every reader that doesn't come online on day one.
For each reader
| Need | Detail |
|---|---|
| Power | Power over Ethernet from a switch port or injector that supports 802.3at (PoE+) or 802.3bt. Check your switch has enough PoE budget left for every reader you plan to connect. |
| An address | The reader gets its IP address from DHCP. It doesn't need a fixed IP, and Titan doesn't need to know what it is. |
| DNS | The reader has to be able to look up mqtt.titanrfid.com. |
| Outbound connection | Allow TCP 8883 outbound to mqtt.titanrfid.com. This is the only connection the reader makes to Titan. Tag reads go up it and Start/Stop commands come back down it. |
| Correct time | The reader checks Titan's certificate, and that check fails if its clock is badly wrong. If your network blocks outbound NTP (UDP 123), tell us before we ship so we can point the reader at a time server you allow. |
No inbound rules are needed. Titan never connects into your network. Don't open ports or set up port forwarding, and don't put the reader in a DMZ.
Things that commonly break it
- Firewalls that allow only web ports. Many networks allow 80 and 443 outbound and block everything else. Port 8883 has to be allowed explicitly.
- TLS inspection proxies. A firewall that decrypts and re-encrypts traffic will break the reader's connection, because the reader and Titan each check the other's certificate. Exempt
mqtt.titanrfid.comfrom inspection. - Guest or isolated VLANs that have no route to the internet at all.
- Not enough PoE. A reader on an underpowered port may boot and then reset, or never fully start.
For the people using Titan
| Need | Detail |
|---|---|
| Browser | A current version of Chrome, Edge, Firefox or Safari, on a desktop or tablet. |
| Outbound connection | HTTPS (TCP 443) to hub.titanrfid.com. If your account uses single sign-on, also allow the sign-in page your browser is redirected to. |
For systems using the API
Outbound HTTPS (TCP 443) to hub.titanrfid.com. If your integration uses the live event stream, make sure any proxy in the path allows long-lived HTTP responses and doesn't buffer them.
Quick check from the reader's network
From a laptop plugged into the same network segment the reader will use:
# Should print "succeeded" or "open"
nc -vz mqtt.titanrfid.com 8883
If this fails, the reader will fail too. Fix the network path first, then plug in the reader.