Subnetz-Isolierung

Subnet Isolation is an additional security feature for KNX installations in which only some of the installed devices support KNX Data Secure.

It prevents modifications to devices that do not support KNX Data Secure across the coupler unless the correct ETS project with the required access keys is used.

To implement this feature, the coupler maintains a list for the temporary forwarding of telegrams.

For commissioning and diagnostic purposes, the ETS automatically adds the required addresses and their validity period to this list.

Changes to this list are only possible using the access key stored in the ETS project.

When Subnet Isolation is enabled and the coupler receives a telegram with a broadcast address or a physical address, it verifies:

  • whether a corresponding entry exists in the list, and

  • whether the validity period of that entry has not expired.

The telegram is forwarded only if both conditions are met.

Otherwise, the coupler blocks the telegram.

Subnet Isolation is automatically enabled by the ETS whenever the coupler is configured to operate as a Secure Proxy.

It can also be enabled or disabled manually.

Note

If the parameters for physical addresses or broadcast addresses on the "Telegram Forwarding" page are set to "Block", these telegrams are not forwarded regardless of the Subnet Isolation setting.

If the Pass IA button is pressed, the coupler forwards telegrams with physical and broadcast addresses regardless of the Subnet Isolation setting or the configured forwarding parameters.


///