Skip to main content

Network requirements

Check this with whoever runs your network before the reader arrives. Network rules cause almost every reader that doesn't come online on day one.

For each reader​

NeedDetail
PowerPower over Ethernet from a switch port or injector that supports 802.3at (PoE+) or 802.3bt. Check your switch has enough PoE budget left for every reader you plan to connect.
An addressThe reader gets its IP address from DHCP. It doesn't need a fixed IP, and Titan doesn't need to know what it is.
DNSThe reader has to be able to look up mqtt.titanrfid.com.
Outbound connectionAllow TCP 8883 outbound to mqtt.titanrfid.com. This is the only connection the reader makes to Titan. Tag reads go up it and Start/Stop commands come back down it.
Correct timeThe reader checks Titan's certificate, and that check fails if its clock is badly wrong. If your network blocks outbound NTP (UDP 123), tell us before we ship so we can point the reader at a time server you allow.

No inbound rules are needed. Titan never connects into your network. Don't open ports or set up port forwarding, and don't put the reader in a DMZ.

Things that commonly break it​

  • Firewalls that allow only web ports. Many networks allow 80 and 443 outbound and block everything else. Port 8883 has to be allowed explicitly.
  • TLS inspection proxies. A firewall that decrypts and re-encrypts traffic will break the reader's connection, because the reader and Titan each check the other's certificate. Exempt mqtt.titanrfid.com from inspection.
  • Guest or isolated VLANs that have no route to the internet at all.
  • Not enough PoE. A reader on an underpowered port may boot and then reset, or never fully start.

For the people using Titan​

NeedDetail
BrowserA current version of Chrome, Edge, Firefox or Safari, on a desktop or tablet.
Outbound connectionHTTPS (TCP 443) to hub.titanrfid.com. If your account uses single sign-on, also allow the sign-in page your browser is redirected to.

For systems using the API​

Outbound HTTPS (TCP 443) to hub.titanrfid.com. If your integration uses the live event stream, make sure any proxy in the path allows long-lived HTTP responses and doesn't buffer them.

Quick check from the reader's network​

From a laptop plugged into the same network segment the reader will use:

# Should print "succeeded" or "open"
nc -vz mqtt.titanrfid.com 8883

If this fails, the reader will fail too. Fix the network path first, then plug in the reader.