How to set up KNX IP Secure with Thinka

KNX

KNX IP Secure with Thinka — Setup Guide


KNX IP Secure is the KNX standard's way of securing a KNX/IP tunnel. Thinka supports it on its own interface, so ETS and other clients connect with credentials over an encrypted session.

Enable Secure Tunnel


In Thinka's web interface, open the Settings page, go to the Integrations -> KNX and scroll down to KNX IP Secure at the bottom. Press Enable secure tunnelling, and Thinka generates its own credentials and shows them there.
image.png 105.81 KB


When you enable KNX IP Secure, it will appear as follows:

image.png 330.18 KB


Connect from ETS


The login dialog appears the first time you actually use the connection, such as starting a group monitor or downloading the project to a device. ETS then reports that the connection is secured and asks for two values: 
  • Commissioning Password  <->  "Management password" in Thinka
  • Authentication Code            <->  "Device authentication code" in Thinka

image.png 92.97 KB


After entering the values, press OK. You should now be securely connected to the Thinka IP Server.
 

Connect as a Tunnel User


Some applications ask you to log in as a tunnel user. They want three things: a User ID, password, and the device authentication code.
Give every application its own user, from 2 to 5.

image.png 152.71 KB


You can change the four addresses. Each one must be unused on the bus and stay in Thinka's own area and line. Derive from Thinka's address fills in a set for you. Save addresses applies them and restarts the interface

Issuing new credentials


Issue new credentials replaces every credentials on the page. Every client that uses the old ones stops working until you update it.
image.png 25.78 KB