Does Thinka support KNX IP Secure (Secure Tunneling)?

KNX

No. Thinka's built-in KNX/IP tunneling interface supports plain (unencrypted, unauthenticated) KNXnet/IP tunneling only. Clients such as Home Assistant or ETS connect using a regular tunnel; the KNX IP Secure session handshake and Secure Wrapper are not implemented.

The Thinka KNX Secure upgrade adds KNX Data Secure: telegram-level authentication and encryption for the group addresses you secure in ETS, enabled by importing your .knxkeys file. It does not add KNX IP Secure.

To keep untrusted devices on your local network from reaching the KNX bus through Thinka, we recommend:

  • Secure critical group addresses with KNX Data Secure in ETS (where your devices support it) and import the keyring into Thinka. Telegrams for those addresses stay encrypted, even over a plain tunnel.
  • Disable Thinka's KNX IP server when you do not need Thinka as a tunneling interface.
  • Place Thinka and its IP clients on a dedicated, access-controlled network (VLAN), so untrusted devices cannot reach the tunneling port at all.