Showing posts with label CCTV Audit. Show all posts
Showing posts with label CCTV Audit. Show all posts

Tuesday, September 15, 2026

Difference Between Active vs. Passive PoE

Difference Between Active vs. Passive PoE 

Power over Ethernet or PoE for short can be a new and potentially confusing term to a lot of people searching for security cameras. PoE connectivity simplifies cabling needed to connect a device by allowing power and data delivery over a single network cable such as CAT5e or CAT6. It makes it easy to connect devices such as IP security cameras, or office phones; a separate power supply or electrical outlet for each device is not needed. However, it is important to know the nuances about PoE equipment to avoid damaging your equipment. There are two types of PoE connections - active and passive. While one may think active is with power and passive is without power, that's not correct.

Active Power over Ethernet (PoE) uses an automatic negotiation handshake to safely deliver dynamic power levels based on device requirements, whereas passive PoE sends a constant, fixed voltage without any communication or safety check.

Active PoE

802.3af/at Compliant PoE - Good for IP cameras

Active PoE means that a device is rated to be 802.3af or 802.3at compliant. These are regulated specifications that require a device and power supply to do a “handshake” or verification. The PoE power supply tests the connection to the device and ensures that the power is compatible. If it isn’t, then the device simply will not power up, preventing any potential damage.

Active PoE Standards (IEEE 802.3)

The IEEE defines several Active PoE standards that determine how much power can safely be delivered.

Standard

Name

Max Power

Voltage Range

802.3af

PoE

Up to 15.5W

44–57V DC

802.3at

PoE+

Up to 30W

50–57V DC

802.3bt

PoE++

60–90W

52–57V DC

Passive PoE

Raw unnegotiated power - Bad for IP cameras

Passive PoE refers to any device that does not follow the 802.3af or 802.3at specifications. Passive PoE does not do any sort of power check so it simply supplies power regardless of what it is plugged into. This can damage any equipment not rated to accept the passive PoE power input. It is extremely important to understand the requirements and specifications of your equipment before plugging anything in.

Unfortunately, we see it too often that a customer damages their newly purchased IP security cameras when using a PoE switch such as a Unifi Switch that can output Passive PoE Power. If you choose to use your own PoE switch, we recommend use of reputable manufacturers such as Cisco, Netgear, or TP-Link that manufacture 802.3af/at compliant PoE hardware.

Calculating Passive PoE Power

If a device requires 12W and supports 12–30V, and you are using a 24V Passive PoE injector, you will need at least 0.5A to meet the power requirement:

24V x 0.5A = 12W.

Practical Limits for Passive PoE

·        24V Systems: Typically limited to about 50 metres due to higher voltage drop at lower voltages.

·        48V Systems: More efficient for longer runs, as higher voltage reduces the current needed for the same power, thereby minimizing heat loss (I2R).

·        Wiring: Passive PoE often uses Mode B, sending power over the "spare" pairs: pins 4/5 (+) and pins 7/8 (-)

Now question is How to access a PoE Security Camera from a Computer

We’re often asked how to modify an IP camera’s video settings once you already have it up and running on your NVR. This process can be difficult without any knowledge of computer networking or setting up a standalone IP camera. In this article we explain the technical details of taking a camera from the back of your NVR and connecting to it with either a direct connection or through your network.

The first steps include understanding how a camera and PoE NVR work together, noting the IP address the camera is configured to and finally physically removing the camera from the NVR.

After having a grasp on the basics and noting the IP address of your camera you can then proceed to the next steps. There are two ways that you can connect to a camera’s web interface:

·       The first is through a direct connection into your Windows desktop or laptop that has an ethernet port.

·       The second involves going over your computer network by configuring the camera to communicate on the network.

Be sure to note the IP address of the camera before disconnecting it from the NVR, you will need it later.

A) Direct connection between IP camera and Computer

The easiest way to access an IP camera is by connecting to it directly from a computer. This method requires you have the following:

1.   The IP address of your camera from the NVR registration page

2.   PoE Injector or 12VDC 1A Power Adapter. It is very important to use a CCTV Camera World approved device or you risk frying the camera due to incorrect voltage

3.   Two Ethernet cables (one if using a power adapter)

4.   Windows 11 pro based PC

1. Use a PoE injector to supply power and data

A PoE injector will have two ports, one labeled for PoE or P+D/Out (power and data) and one labeled LAN or Data/In. Connect the PoE injector to a power outlet. Connect an ethernet cable from your PC's network port to the Data/In on the PoE injector. Connect a second ethernet cable from the network camera's RJ45 network jack to the port labeled PoE or P+D/Out. To check if everything is connected properly refer to the lights on the PoE injector and the port on your computer. If you do not see any indication lights you may have a bad cable or do not have the wires connected properly.

2. Use a 12VDC 1A power adapter

A correct power adapter will have a label stating it is 12VDC 1000mA. Connect an ethernet cable from the camera directly to your computer’s ethernet port. A good way to check if the camera is receiving power and communicating with your computer is to look at the lights on your computer’s port. If you have no lights it is important to test that your cable and power supply work with another device.

3. Configure your PC's network port to communicate with the camera

For your computer to "speak" to your camera, you need to set its network port to the same IP address scheme as the camera. Before we disconnected the camera from the back of the NVR, we noted what the IP address of the camera was.

Login to your Windows PC, change your computer's ethernet adapter to communicate with the camera. Use the Network & Internet settings which contains an Ethernet section. Using the change adapter settings set an IP address for your computer that matches the network for the camera. If you do not know how to do this refer to the video above for this step.

4. Test the connection with the Ping command

After powering the camera and configuring your computer to talk with it, it is good practice to test the connection using the Ping command. Simply open the Command Prompt and type Ping with the address of the camera. In our case we used the following command: ping 10.1.1.65 -t press enter key.

5. Access the camera using Internet Explorer

It is important to use Internet Explorer as it is the most compatible browser for accessing security cameras. Type the IP address of your camera into the address bar in Internet Explorer. Some cameras may require initialization and it is recommended to uncheck the Easy4IP and auto-update options when proceeding through the prompts. The password can be admin, or may be printed on the label found on the box of the camera. Note: the customer is responsible for any password change beyond the defaults. There is no master reset password.

After successfully logging into the camera you need to install a plugin to view the camera. Click the link in the center of the page to download the plugin. Make sure to Run and do not save the plugin download. Internet Explorer will prompt you to allow the plugin to run. Once the plugin is installed, you will be required to log back into the camera. You should now see video from your camera and can modify the settings of the camera in the Setting tab within your browser. Make sure when you are done modifying your camera(s) that you change your network settings back to “Obtain IP address automatically” in your network settings, this is demonstrated in the video above.

B) Accessing the camera over your network

Besides direct connection to a computer, the other method to connect to a PoE security camera is over the network. This method requires the following pre-requisites:

1.   A home or business network with router

2.   Windows PC with ConfigTool installed

3.   PoE Injector or 12VDC 1A power adapter

4.   A network cable to connect to your router

5.   The IP address of your camera

1. Power the camera

You can use a PoE injector or 12V DC 1amp power adapter to power the camera and connect to your network router or switch. The process is simple. It is very important to use a CCTV Camera World approved device or you risk frying the camera due to incorrect voltage.

2. Connect the camera to your network router

Instead of connecting the camera directly to your computer, you will connect it to your network router so the computer can communicate with the camera over the network. When following this guide, it is important to connect the camera and computer to the same router or switch. We suggest using a hardwired connection between the computer and the router to prevent a situation where your WiFi network is different from the wired network. If you are knowledgeable about your network setup, feel free to use a WiFi laptop.

3. Use the ConfigTool to find the camera and change its IP address

Using the ConfigTool to find the camera on your network is fairly easy. It is imperative that you turn off any firewall or antivirus program on your computer that may prevent the program from sniffing your network.

4. Access the camera's web interface using Internet Explorer

The steps are similar to method A because the web interface will be the same regardless of how you connect to the camera.

Method for Identifying a PoE Power Supply Failure Caused by High Network Cable Resistance

If network cables can be removed from the switch at the local site, use below method to measure the resistance.

·        Measurement tool: Multimeter

·        Measurement contents and procedure: Use the multimeter to measure the DC resistance of each cable wire and take down the measured values as R1, R2,…R8.

·        Measurement results:

Network cable resistance:

R = (R1 + R2 + R3 + R6)/4 (when the switch uses the wires 1, 2, 3, and 6 to supply power.)

Or:

R = (R4 + R5 + R7 + R8)/4 (when the switch uses the wires 4, 5, 7, and 8 to supply power.)

Usually, the AC and PoE switch use wires 1, 2, 3, and 6 for power supply, and the PoE adapter uses wires 4, 5, 7, and 8 for power supply.

Key Takeaways

The primary difference between Active and Passive Power over Ethernet (PoE) is how they deliver power: Active PoE communicates with a device to ensure it is safe to power, while Passive PoE sends electricity immediately without checking compatibility.

Active PoE (The "Smart" Choice)

Active PoE is the industry standard for most modern business networks.

·        Intelligent Handshake: The power source (PSE) sends a low-voltage signal to detect if the connected device is PoE-compatible and determines exactly how much power it needs.

·        Protection: If you plug in a laptop or a non-PoE device, the switch detects it and sends only data, preventing electrical damage.

·        Common Standards:

o   PoE (802.3af): Up to 15.4W per port.

o   PoE+ (802.3at): Up to 30W per port.

o   PoE++ (802.3bt): Up to 60W or 100W for high-power devices.

Passive PoE (The "Always-On" Choice)

Passive PoE is common in specific setups like outdoor wireless bridges or legacy equipment.

·        No Communication: It does not check the device's needs; it simply pushes a fixed voltage over specific pins in the Ethernet cable.

·        High Risk: If you plug a device into a passive port that doesn't match its required voltage (e.g., 48V into a 24V device), it can cause permanent electrical failure.

·        Manual Matching: You must manually verify that your injector or switch matches the exact voltage and pinout required by your device.

Which should you choose?

·        Choose Active PoE for almost all standard office or home office uses (IP cameras, VoIP phones, modern Access Points) to ensure safety and future-proofing.

·        Choose Passive PoE only if you have specific legacy hardware or budget-constrained outdoor installations where you are certain the power specs match perfectly

How to Find Your Model's Requirements

1.   Check the Physical Label: Look for a sticker on the back or bottom of the device. It will often list "802.3af," "802.3at," or a specific voltage like "24V DC".

2.   Consult the Datasheet: Search for your model number + "technical specs" online. Look specifically for the "Power Method" field.

3.   Check the Box: If you still have the original packaging, the required PoE standard is usually printed on the side near the serial number.

 

Wednesday, April 15, 2026

Factory Acceptance Tests for CCTV Systems

Factory Acceptance Tests for CCTV Systems

Factory Acceptance Tests (FAT) for CCTV systems are a crucial process conducted at the manufacturer's site to verify that the system meets all specified requirements and functions as intended before installation. Key aspects include checking hardware and software functionality, validating video quality and recording, ensuring network connectivity, and verifying that all components and licenses are correct, all before the system is delivered to the customer site. This comprehensive testing identifies and addresses issues early, ensuring the system's reliability, quality, and compliance with contractual specifications.

Key components of a CCTV FAT

A comprehensive FAT ensures that all parts of the CCTV system perform as expected. An effective FAT protocol will include the following elements: 

1. Documentation review

Before any physical testing, a thorough review of all project documentation is performed to ensure compliance with the contract. This includes:

·        Drawings: Confirming that all system layouts, wiring diagrams, and equipment locations match the approved "as-built" documentation.

·        Bill of Materials (BOM): Verifying that the delivered equipment, including camera models, lenses, and recorders, matches the specified list.

·        Certifications: Checking that all necessary certificates for materials, calibration, and industry standards are available.

·        Specifications: Ensuring all technical specifications and customer requirements are clearly documented. 

2. Hardware and visual inspection

This stage involves a physical examination of the equipment to check for proper assembly, damage, and labeling. 

·        Physical condition: Inspecting cameras, recorders (NVR/DVR), servers, and storage for any visible signs of damage, defects, or poor craftsmanship.

·        Mechanical integrity: For Pan-Tilt-Zoom (PTZ) cameras, testing the smooth mechanical movement of the pan, tilt, and zoom functions.

·        Labeling and nameplates: Verifying that all equipment is properly labeled according to project specifications.

·        Cabinet and console check: For rack-mounted systems, checking that cabinets, consoles, and terminals are correctly arranged, wired, and labeled. 

3. System functionality and performance testing

Functional tests verify that all hardware and software components of the CCTV system are operating correctly. 

·        Power-up test: Powering on all system components, including cameras, recorders, and workstations, and checking all status indicator lights.

·        Camera functionality: Testing all cameras individually to confirm they are online and transmitting video. For PTZ cameras, testing all control functions from the monitoring station.

·        Image quality: Evaluating video streams for clarity, resolution, color accuracy, and proper field of view as specified in the contract. This may involve checking night vision or infrared (IR) capabilities under low-light conditions.

·        Recording and playback: Testing that the system records video continuously or based on specified triggers (e.g., motion detection). Verifying that recorded footage can be played back correctly.

·        Storage check: Confirming that the storage capacity (Hard Disk Drives) and redundant storage options function as intended.

·        Redundancy testing: If the system is configured for redundancy (e.g., dual Network Video Recorders or power supplies), testing the failover process to ensure it works seamlessly. 

4. Software and network configuration

This step focuses on the software setup and network communication of the CCTV system. 

·        Software version: Verifying that the correct software and firmware versions are installed on all components, as per specifications.

·        Network connectivity: Testing all network connections to ensure reliable communication between cameras, recorders, and monitoring stations.

·        User interfaces: Checking that all graphical user interfaces (GUIs) on operator workstations are functioning and allow for proper system control and monitoring.

·        Alarm and event logging: Verifying that the system correctly logs events and triggers alarms for specified incidents.

·        Access control and user permissions: Testing different access levels and user permissions to ensure that only authorized personnel can access certain functions or cameras. 

5. Integration and security testing

If the CCTV system is part of a larger security network, it must be tested for proper integration. 

·        System integration: Verifying seamless communication and data exchange with other systems, such as access control, fire alarms, or building management systems.

·        Cybersecurity check: Depending on project requirements, conducting basic security tests to ensure all necessary security controls and encryption protocols are properly implemented. 

6. Improved Installation and Commissioning:

·        Smooth transition: A successfully passed FAT paves the way for a smoother and less error-prone installation and commissioning process. You can expect fewer surprises and disruptions at your site, leading to faster operational readiness.

·        Reduce installation costs: By minimizing the need for post-installation troubleshooting and adjustments, the FAT can help lower your installation costs.

The FAT report

Upon completing the FAT, a formal report is created to document the test results and obtain sign-off from all stakeholders. The report typically includes: 

·        Checklist: The completed checklist from the test procedure, with clear pass/fail criteria.

·        Test data and results: A summary of all tests performed, including any observations or deviations.

·        Corrective actions: A log of any identified non-conformities and the corrective actions taken by the manufacturer.

·        Signatures: Formal approval and sign-off by the manufacturer, customer, and any third-party inspectors involved. 

Factory Acceptance Test Checklist?

A good factory acceptance test checklist should enable quality managers to make sure that no aspects are overlooked when it comes to performing factory acceptance tests. A comprehensive FAT checklist should include the following:

1. Documentation Review

·        Verify technical specifications, design drawings, and manuals.

·        Ensure calibration certificates and material certificates are available.

·        Confirm compliance with regulatory standards and customer requirements.

·        Check the bill of materials against delivered components.

2. Pre-Test Preparation

·        Ensure test procedures and acceptance criteria are clearly defined.

·        Confirm availability of required tools, instruments, and test rigs.

·        Assign responsibilities to test personnel.

·        Review risk assessments and safety protocols before starting.

3. Mechanical & Structural Inspection

·        Verify equipment dimensions and physical condition.

·        Check welding, joints, and finishes for defects.

·        Ensure proper installation of moving parts, bearings, and fasteners.

·        Confirm correct labeling, tags, and nameplates.

4. Electrical & Control Systems

·        Inspect wiring, grounding, and connections.

·        Test protective devices (fuses, circuit breakers, relays).

·        Verify control panels and interfaces are functional.

·        Confirm software/firmware versions match the specification.

5. Functional Testing

·        Operate equipment under different modes (manual, automatic).

·        Test alarms, interlocks, and emergency stops.

·        Verify startup, shutdown, and restart sequences.

·        Simulate fault conditions where feasible.

6. Safety & Compliance

·        Check compliance with OSHA, CE, ISO, or other relevant standards.

·        Inspect safety guards, light curtains, and lockout/tagout devices.

·        Verify safety signage is visible and accurate.

·        Review hazardous material handling protocols (if applicable).

7. Performance & Reliability Testing

·        Run performance tests against agreed KPIs.

·        Measure vibration, noise levels, and thermal behavior.

·        Test endurance and repeatability under simulated load.

·        Confirm energy efficiency or environmental compliance metrics.

8. System Integration & Connectivity

·        Verify interfaces with upstream/downstream systems.

·        Test communication protocols

·        Check integration with MES, ERP, or SCADA systems.

·        Confirm data logging and reporting functions work correctly.

9. Documentation & Reporting

·        Record all test results and deviations.

·        Ensure calibration records and certificates are attached.

·        Include photos/videos of critical test steps where useful.

·        Compile the FAT report in the agreed template.

10. Post-Test Review

·        Conduct a debrief session with stakeholders.

·        Document corrective actions and retest results if needed.

·        Prepare recommendations for commissioning and site acceptance test (SAT).

·        Store all records in a traceable, accessible system.

Cybersecurity Factory Acceptance Test (CFAT)

Together with one of the largest providers of industrial automation, a representative for the Canadian end-user, ASaP, successfully passed a Cybersecurity Factory Acceptance Test (CFAT). The CFAT was used to structurally prove the security and functionality of all IT assets. Amongst these critical assets were the PLC, HMI, switch, and maintenance laptops.

Secure your process critical assets!

A big part of the CFAT is the LNG Sampler system hardening. System hardening is a collection of techniques and best practices to reduce vulnerability in applications, systems, infrastructure and firmware. The goal of system hardening is to reduce security risk by eliminating potential attack vectors and reducing the LNG Sampler’s attack surface. By removing unused functionalities, user accounts, applications, ports and permissions, potential attackers and viruses have fewer opportunities to enter your process domain.  

The scope of the CFAT

·        System, application, and operating system hardening

·        Network management

·        Switch configuration

·        Verifying application functionality while the antivirus software is performing a full system scan

·        Modbus mapping verification

·        Back-up and restore of all devices and applications

Factory Acceptance Test Standards

While not a single, universal standard governs Factory Acceptance Tests (FATs), several industry-recognized standards and guidelines shape best practices and ensure quality, safety, and compliance. Here’s a closer look at three crucial standards:

ISO 9001 – Quality Management Systems:

·        Foundation for Quality: This comprehensive standard establishes a framework for quality management across all aspects of an organization’s operations, including FATs

Key Requirements for FATs: 

·        Clear documentation of FAT procedures and expectations.

·        Controlled testing environment with calibrated equipment.

·        Traceability of test results for thorough documentation.

·        Corrective actions for identified defects.

·        Continuous improvement of FAT processes.

IEC6oo68 – Environmental Testing

·        Ensuring Environmental Resilience: This standard specifies test methods for assessing equipment’s ability to withstand various environmental conditions, often included in FATs.

·        Common Tests Covered:

a)   Temperature and humidity extremes

b)   Vibration and shock resistance

c)   Corrosive atmospheres

d)   Sand and dust exposure

e)   Other relevant environmental factors

IEC 61010 – Safety Requirements for Electrical Equipment:

·        Protecting Personnel and Property: This standard focuses on electrical safety requirements for equipment, ensuring protection against electrical hazards during FATs and subsequent operation.

·        Key Safety Aspects Addressed:

A.   Grounding and insulation

B.   Protection against electrical shocks

C.   Fire and explosion prevention

D.   Electromagnetic compatibility

Additional Considerations:

·        Industry-Specific Standards: Alongside these general standards, certain industries often have additional standards or guidelines for FATs, tailored to their specific equipment and risks.

·        Contractual Requirements: Specific FAT requirements and standards might be stipulated in contracts between manufacturers and buyers, ensuring alignment with their quality and safety expectations.

The STQC (Standardisation Testing and Quality Certification) test process for CCTV systems is a mandatory regulatory framework in India, governed by the Ministry of Electronics and Information Technology (MeitY). From 1 April 2026, only CCTV cameras that are STQC-certified and comply with the Essential Requirements (ER) can be sold in the Indian market.

Local content (LC) for CCTV systems is calculated based on the Public Procurement (Preference to Make in India) Order (PPP-MII), which measures the value added in India as a percentage of the total product value.

The DPIIT's formula for calculating local content is:

·        Total Value: The sale price of the item, excluding net domestic indirect taxes.

·        Imported Content: The landed cost at the factory, including all customs duties and clearing charges.

·        Exclusions: Services like transportation, insurance, installation, and after-sales support (AMC/CMC) cannot be claimed as local value addition if the product itself is imported

Specific CCTV Weightage Caps

For CCTV cameras (specifically analog), MeitY's gazette notification defines maximum weightage limits for certain local components within the Bill of Materials (BOM): 

Component Category 

Requirement for Local Content

Max Weightage in BOM

Housing & Mount

Domestically manufactured inputs

Up to 15%

Cables & Connectors

Domestically manufactured inputs

Up to 5%

Final Assembly & Testing

Domestically assembled in India

Up to 10%

PCBA

Mandatory SMT process in India

Required for compliance

Supplier Classification

Your calculated percentage determines your eligibility for government tenders: 

·        Class-I Local Supplier: Local content 50%. Eligible for purchase preference.

·        Class-II Local Supplier: Local content 20% to 49%. Eligible to bid but generally without price preference.

·        Non-Local Supplier: Local content 20%. Generally ineligible for local-preference tenders.

Core Phases of the STQC Test Process

The process follows a structured path from technical preparation to final certification issuance: 

1.   Preparation of Technical Construction File (TCF):

A.   The manufacturer prepares a TCF documenting the product's architecture, Bill of Materials (BOM), and compliance with ER.

B.   This must include a detailed entity relationship diagram of the supply chain for critical chips and components.

2.   Application & Initial Review:

A.   A formal application is submitted to the STQC Directorate along with the TCF.

B.   The Certification Body (CB) evaluates the documents for a prima facie review and may schedule a technical presentation by the manufacturer.

3.   Laboratory Testing:

A.   Product samples are sent to one of the 21 STQC labs across India.

B.   Cybersecurity Testing: Verifying "secure-boot" code, unique cryptographic keys per device, and ensuring debugging ports (like UART, JTAG) are disabled.

C.   Functional & Environmental Testing: Checking image resolution, power consumption, and endurance against temperature/humidity.

4.   Manufacturing Facility Audit:

STQC officials conduct a process audit at the manufacturing unit to verify that security controls are properly implemented during production.

5.   Final Validation & Issuance:

A.   A Certification Committee reviews the lab reports and audit findings.

B.   Successful products receive an STQC Certificate, typically valid for 3 years (subject to surveillance audits). 

Key Technical Requirements (ER:01)

CCTV cameras must meet specific security benchmarks to pass the STQC evaluation: 

·        No Hardcoded Credentials: Every device must have unique passwords/keys.

·        Secure Boot & Updates: Only digitally signed firmware can be loaded or updated.

·        Data Encryption: Use of modern protocols like TLS 1.2+ for video streams and management data.

·        Local Content: For government procurement, cameras must meet a minimum "domestic value addition," currently set at 35% for FY 2025-26

Critical Deadlines

·        1 April 2026: Final deadline for all CCTV cameras sold in India to have STQC and BIS certification.

·        Existing License Holders: Must have submitted their ER:01 test reports via the BIS Portal to avoid license cancellation

Government-Operated Laboratories

These primary labs are divided by region and are the main hubs for electrical and electronics testing. 

  • North Region:
    • ERTL (North): New Delhi (Okhla Industrial Estate).
    • ETDC Ajmer: Ajmer, Rajasthan.
    • ETDC Jaipur: Jaipur, Rajasthan.
    • ETDC Mohali: Mohali, Punjab.
    • ETDC Solan: Solan, Himachal Pradesh.
  • East & North-East Region:
    • ERTL (East): Kolkata, West Bengal (Salt Lake City).
    • ETDC Agartala: Agartala, Tripura.
    • ETDC Guwahati: Guwahati, Assam.
  • West Region:
    • ERTL (West): Mumbai, Maharashtra (Andheri East).
    • ETDC Goa: Bambolim, Goa.
    • ETDC Pune: Pune, Maharashtra.
  • South Region:
    • ERTL (South): Thiruvananthapuram, Kerala.
    • ETDC Bengaluru: Bengaluru, Karnataka (Peenya Industrial Estate).
    • ETDC Chennai: Chennai, Tamil Nadu.
    • ETDC Hyderabad: Hyderabad, Telangana.