Showing posts with label Cyber security. Show all posts
Showing posts with label Cyber security. Show all posts

Tuesday, September 15, 2026

Difference Between Active vs. Passive PoE

Difference Between Active vs. Passive PoE 

Power over Ethernet or PoE for short can be a new and potentially confusing term to a lot of people searching for security cameras. PoE connectivity simplifies cabling needed to connect a device by allowing power and data delivery over a single network cable such as CAT5e or CAT6. It makes it easy to connect devices such as IP security cameras, or office phones; a separate power supply or electrical outlet for each device is not needed. However, it is important to know the nuances about PoE equipment to avoid damaging your equipment. There are two types of PoE connections - active and passive. While one may think active is with power and passive is without power, that's not correct.

Active Power over Ethernet (PoE) uses an automatic negotiation handshake to safely deliver dynamic power levels based on device requirements, whereas passive PoE sends a constant, fixed voltage without any communication or safety check.

Active PoE

802.3af/at Compliant PoE - Good for IP cameras

Active PoE means that a device is rated to be 802.3af or 802.3at compliant. These are regulated specifications that require a device and power supply to do a “handshake” or verification. The PoE power supply tests the connection to the device and ensures that the power is compatible. If it isn’t, then the device simply will not power up, preventing any potential damage.

Active PoE Standards (IEEE 802.3)

The IEEE defines several Active PoE standards that determine how much power can safely be delivered.

Standard

Name

Max Power

Voltage Range

802.3af

PoE

Up to 15.5W

44–57V DC

802.3at

PoE+

Up to 30W

50–57V DC

802.3bt

PoE++

60–90W

52–57V DC

Passive PoE

Raw unnegotiated power - Bad for IP cameras

Passive PoE refers to any device that does not follow the 802.3af or 802.3at specifications. Passive PoE does not do any sort of power check so it simply supplies power regardless of what it is plugged into. This can damage any equipment not rated to accept the passive PoE power input. It is extremely important to understand the requirements and specifications of your equipment before plugging anything in.

Unfortunately, we see it too often that a customer damages their newly purchased IP security cameras when using a PoE switch such as a Unifi Switch that can output Passive PoE Power. If you choose to use your own PoE switch, we recommend use of reputable manufacturers such as Cisco, Netgear, or TP-Link that manufacture 802.3af/at compliant PoE hardware.

Calculating Passive PoE Power

If a device requires 12W and supports 12–30V, and you are using a 24V Passive PoE injector, you will need at least 0.5A to meet the power requirement:

24V x 0.5A = 12W.

Practical Limits for Passive PoE

·        24V Systems: Typically limited to about 50 metres due to higher voltage drop at lower voltages.

·        48V Systems: More efficient for longer runs, as higher voltage reduces the current needed for the same power, thereby minimizing heat loss (I2R).

·        Wiring: Passive PoE often uses Mode B, sending power over the "spare" pairs: pins 4/5 (+) and pins 7/8 (-)

Now question is How to access a PoE Security Camera from a Computer

We’re often asked how to modify an IP camera’s video settings once you already have it up and running on your NVR. This process can be difficult without any knowledge of computer networking or setting up a standalone IP camera. In this article we explain the technical details of taking a camera from the back of your NVR and connecting to it with either a direct connection or through your network.

The first steps include understanding how a camera and PoE NVR work together, noting the IP address the camera is configured to and finally physically removing the camera from the NVR.

After having a grasp on the basics and noting the IP address of your camera you can then proceed to the next steps. There are two ways that you can connect to a camera’s web interface:

·       The first is through a direct connection into your Windows desktop or laptop that has an ethernet port.

·       The second involves going over your computer network by configuring the camera to communicate on the network.

Be sure to note the IP address of the camera before disconnecting it from the NVR, you will need it later.

A) Direct connection between IP camera and Computer

The easiest way to access an IP camera is by connecting to it directly from a computer. This method requires you have the following:

1.   The IP address of your camera from the NVR registration page

2.   PoE Injector or 12VDC 1A Power Adapter. It is very important to use a CCTV Camera World approved device or you risk frying the camera due to incorrect voltage

3.   Two Ethernet cables (one if using a power adapter)

4.   Windows 11 pro based PC

1. Use a PoE injector to supply power and data

A PoE injector will have two ports, one labeled for PoE or P+D/Out (power and data) and one labeled LAN or Data/In. Connect the PoE injector to a power outlet. Connect an ethernet cable from your PC's network port to the Data/In on the PoE injector. Connect a second ethernet cable from the network camera's RJ45 network jack to the port labeled PoE or P+D/Out. To check if everything is connected properly refer to the lights on the PoE injector and the port on your computer. If you do not see any indication lights you may have a bad cable or do not have the wires connected properly.

2. Use a 12VDC 1A power adapter

A correct power adapter will have a label stating it is 12VDC 1000mA. Connect an ethernet cable from the camera directly to your computer’s ethernet port. A good way to check if the camera is receiving power and communicating with your computer is to look at the lights on your computer’s port. If you have no lights it is important to test that your cable and power supply work with another device.

3. Configure your PC's network port to communicate with the camera

For your computer to "speak" to your camera, you need to set its network port to the same IP address scheme as the camera. Before we disconnected the camera from the back of the NVR, we noted what the IP address of the camera was.

Login to your Windows PC, change your computer's ethernet adapter to communicate with the camera. Use the Network & Internet settings which contains an Ethernet section. Using the change adapter settings set an IP address for your computer that matches the network for the camera. If you do not know how to do this refer to the video above for this step.

4. Test the connection with the Ping command

After powering the camera and configuring your computer to talk with it, it is good practice to test the connection using the Ping command. Simply open the Command Prompt and type Ping with the address of the camera. In our case we used the following command: ping 10.1.1.65 -t press enter key.

5. Access the camera using Internet Explorer

It is important to use Internet Explorer as it is the most compatible browser for accessing security cameras. Type the IP address of your camera into the address bar in Internet Explorer. Some cameras may require initialization and it is recommended to uncheck the Easy4IP and auto-update options when proceeding through the prompts. The password can be admin, or may be printed on the label found on the box of the camera. Note: the customer is responsible for any password change beyond the defaults. There is no master reset password.

After successfully logging into the camera you need to install a plugin to view the camera. Click the link in the center of the page to download the plugin. Make sure to Run and do not save the plugin download. Internet Explorer will prompt you to allow the plugin to run. Once the plugin is installed, you will be required to log back into the camera. You should now see video from your camera and can modify the settings of the camera in the Setting tab within your browser. Make sure when you are done modifying your camera(s) that you change your network settings back to “Obtain IP address automatically” in your network settings, this is demonstrated in the video above.

B) Accessing the camera over your network

Besides direct connection to a computer, the other method to connect to a PoE security camera is over the network. This method requires the following pre-requisites:

1.   A home or business network with router

2.   Windows PC with ConfigTool installed

3.   PoE Injector or 12VDC 1A power adapter

4.   A network cable to connect to your router

5.   The IP address of your camera

1. Power the camera

You can use a PoE injector or 12V DC 1amp power adapter to power the camera and connect to your network router or switch. The process is simple. It is very important to use a CCTV Camera World approved device or you risk frying the camera due to incorrect voltage.

2. Connect the camera to your network router

Instead of connecting the camera directly to your computer, you will connect it to your network router so the computer can communicate with the camera over the network. When following this guide, it is important to connect the camera and computer to the same router or switch. We suggest using a hardwired connection between the computer and the router to prevent a situation where your WiFi network is different from the wired network. If you are knowledgeable about your network setup, feel free to use a WiFi laptop.

3. Use the ConfigTool to find the camera and change its IP address

Using the ConfigTool to find the camera on your network is fairly easy. It is imperative that you turn off any firewall or antivirus program on your computer that may prevent the program from sniffing your network.

4. Access the camera's web interface using Internet Explorer

The steps are similar to method A because the web interface will be the same regardless of how you connect to the camera.

Method for Identifying a PoE Power Supply Failure Caused by High Network Cable Resistance

If network cables can be removed from the switch at the local site, use below method to measure the resistance.

·        Measurement tool: Multimeter

·        Measurement contents and procedure: Use the multimeter to measure the DC resistance of each cable wire and take down the measured values as R1, R2,…R8.

·        Measurement results:

Network cable resistance:

R = (R1 + R2 + R3 + R6)/4 (when the switch uses the wires 1, 2, 3, and 6 to supply power.)

Or:

R = (R4 + R5 + R7 + R8)/4 (when the switch uses the wires 4, 5, 7, and 8 to supply power.)

Usually, the AC and PoE switch use wires 1, 2, 3, and 6 for power supply, and the PoE adapter uses wires 4, 5, 7, and 8 for power supply.

Key Takeaways

The primary difference between Active and Passive Power over Ethernet (PoE) is how they deliver power: Active PoE communicates with a device to ensure it is safe to power, while Passive PoE sends electricity immediately without checking compatibility.

Active PoE (The "Smart" Choice)

Active PoE is the industry standard for most modern business networks.

·        Intelligent Handshake: The power source (PSE) sends a low-voltage signal to detect if the connected device is PoE-compatible and determines exactly how much power it needs.

·        Protection: If you plug in a laptop or a non-PoE device, the switch detects it and sends only data, preventing electrical damage.

·        Common Standards:

o   PoE (802.3af): Up to 15.4W per port.

o   PoE+ (802.3at): Up to 30W per port.

o   PoE++ (802.3bt): Up to 60W or 100W for high-power devices.

Passive PoE (The "Always-On" Choice)

Passive PoE is common in specific setups like outdoor wireless bridges or legacy equipment.

·        No Communication: It does not check the device's needs; it simply pushes a fixed voltage over specific pins in the Ethernet cable.

·        High Risk: If you plug a device into a passive port that doesn't match its required voltage (e.g., 48V into a 24V device), it can cause permanent electrical failure.

·        Manual Matching: You must manually verify that your injector or switch matches the exact voltage and pinout required by your device.

Which should you choose?

·        Choose Active PoE for almost all standard office or home office uses (IP cameras, VoIP phones, modern Access Points) to ensure safety and future-proofing.

·        Choose Passive PoE only if you have specific legacy hardware or budget-constrained outdoor installations where you are certain the power specs match perfectly

How to Find Your Model's Requirements

1.   Check the Physical Label: Look for a sticker on the back or bottom of the device. It will often list "802.3af," "802.3at," or a specific voltage like "24V DC".

2.   Consult the Datasheet: Search for your model number + "technical specs" online. Look specifically for the "Power Method" field.

3.   Check the Box: If you still have the original packaging, the required PoE standard is usually printed on the side near the serial number.

 

Wednesday, March 1, 2023

Fenced for Perimeter Protection

Fenced for Perimeter Protection 

Securing a private or public building is a complex issue, right from any perimeter and entrance point to internal asset management. Instead, optimal security solutions can only be achieved by going back to basics, understanding individual environments and integrating security systems to achieve unique requirements.

The 2022 Crime Report from the Association of Convenience Stores (ACS) shows that, in the past year, 89% of store staff faced abuse in their job, with 35,000 incidents of violence, 9% those resulting in personal injury.

The perimeter is the first line of defence. It inhibits and delays intruders. Unfortunately, history has taught us that even the most impenetrable perimeter can still be breached.

Therefore, sensitive sites should not be on the fence when it comes to investing in the right security technology for the right application. A genuinely intelligent system is key to a successful security solution.

Delaying the intruder is essential. If it takes a security team five minutes to deploy intervention, but the time to target is three minutes, then a security solution needs to create a delay of at least two minutes. If there are layers in place that take three minutes to penetrate, then the response team will have time to apprehend the perpetrators before they reach their target.

In terms of physical perimeter security, layers of technology should be applied starting with the outer perimeter, such as the fence line; the inner zone perimeter, such as specific buildings or key infrastructure; the building face perimeter, such as the external building shell; and finally, the internal perimeter, such as internal space where restricted access is necessary. Solutions within each layer should help delay, deter, and detect intrusion.

There are a wide range of technologies that make up an intelligent outer perimeter. To deter people from attempting to gain unauthorised access, a site can use signage or physical barriers. Sites requiring a more secure perimeter typically “harden” the physical barrier using high security palisade or welded mesh products. These barriers are designed to delay intruders and serve as a physical deterrent by preventing unauthorised access. Additionally, perimeter fences ensure the safety of the public – protecting people from entering sites where they may unwittingly expose themselves to risk, injury or even death.

However, while many businesses use gates, fencing, and other structures to keep intruders out, these only delay an intrusion. That is why highly secure sites should look to include elevated detection technologies such as monitored pulse, energised fences. A monitored pulse fence both deters and detects criminals or trespassers. A grid of energised wires is often enough to prevent someone from attempting to climb or break through the fence. Monitored pulse fences comply with international safety standards and are designed to deliver a short but safe shock and acts as a highly effective deterrent.

Additional technologies such as full integration with video management systems provides a visual record of events that can be viewed as a live stream and later used as evidence if required. Designing an effective perimeter security solution is a significantly more complex process than it appears at first glance. The consultant, architect, or engineer has many factors they need to consider in the process, including understanding the site requirements and environment, and selecting which technology or combination of technologies will have a direct impact on the success of the system.

For example, a highly secure yet discrete site, where the customer doesn’t want to “advertise” what they do by way of a visually intimidating perimeter, may use discrete technologies such as buried sensors, laser curtains and microwave. The possible intrusion risks balanced against the requirements of the site will determine the type of sensors used – these risks can range from vandalism or protests by activists to criminal theft, espionage, and terrorism.

One of the main requirements from customers when it comes to an intelligent perimeter solution is a high probability of detection and low false alarm rate. For sites requiring higher levels of perimeter protection, like prisons, it is crucial that perimeter security is as sensitive to tampering on the fence line as possible to prevent and detect perimeter breaches. However, a highly sensitive fence line can be subject to false alarms due to factors such as disturbances from wildlife and environmental extremes.

In recent years, there has been a shift to intelligent, integrated perimeter solutions where detailed reporting and configuration can be carried out on the performance of the perimeter technology. While perimeter security is an organisation’s first and arguably best, line of defence, integration with other technologies is key in effectively securing a site. Essentially, a security management system that brings everything together can provide a truly intelligent multi-layered perimeter solution.

An integrated approach provides the control room operator with all the information associated with an attempted attack to their fence line, ultimately assisting with faster response times. On top of that, cyber security threats are becoming a very real risk to perimeter protection and are forcing a rethink in how and what technologies are installed, with a shift towards more intelligent and integrated solutions. An end-to-end approach is vital. A cyber security vulnerability can occur along any of the communication channels, from the fence detector to the device that displays the alarm to the security guard.

Gallagher considers each communication link and device to assure the complete security of a perimeter protection system. Their security solutions are engineered to meet stringent standards that define how high security sites around the world should be protected and are backed by the implementation of government standards to validate their effectiveness. Gallagher undertakes internal and external penetration testing of their products to ensure they are hardened and secured to mitigate the risk of cyber-attacks.

During pandemic, Gallagher supplied perimeter security solutions to ensure protection. Gallagher’s intelligent deterrent and detection technologies continue to be utilised across small to medium commercial and industrial facilities, right through to larger correctional, utility, and high-profile government sites.


Sunday, January 1, 2023

Security Trends in 2023

Security Trends in 2023 

Wishing you a very Happy New Year – 2023. Although some of the worst disruption caused by the global Covid-19 pandemic is hopefully behind us, 2023 is shaping up to be another challenging year for business and society. But this year few states going through partial lockdown case to case basis.

Cyber security in physical security:

Adoption of digital technology and internet have also led to increase in cybercrime incidents. It can be controlled or minimized with care, precaution, awareness and with the use of appropriate tools to secure the information. Indian Cyber Crime Coordination Centre (I4C) under Cyber & Information Security (CIS) Division of the Ministry of Home Affairs, has prepared one manual to disseminate Cyber Hygiene Best Practices for the benefit of Industrial Bodies/General Public/Government Officials.

Many large buyers now provide a cybersecurity questionnaire that integrators and solution vendors must complete, leading to creation of new roles in some companies just to respond to such questionnaires that are required in bid processes. Vendors, integrators and the practitioners themselves are simultaneously chasing cybersecurity talent to add to their employee teams, a challenging proposition given the overall difficulty to hire technically skilled workers of any type. Cybersecurity has to be managed on multiple levels, requiring constantly expanding investments in:

·        Device-level cybersecurity (e.g., cameras, readers, panels)

·        Infrastructure cybersecurity (wiring, networks, switches, etc.)

·        Software and Server cybersecurity

·        Configuration cybersecurity (correct implementation of cybersecurity features)

·        Cloud cybersecurity

·        Mobile device cybersecurity (particularly as security and employee bases become more mobile or remote)

·        User cybersecurity (e.g., social engineering attacks, insider threats, etc.)

Security practitioners today seem to have three general choices when it comes to convergence:-

1. Ignore: Disregard the need to converge—a wholly unwise choice, by most accounts.

2. Strongly Interrelated Teams: Continue to manage security in two, separate but equal channels, but strongly define team relationships such that constant open dialogue and cross-investigation exist between the two specialized teams.

2. Fully Converged: Fully merge security leadership and tactical security management to link cybersecurity protections and physical security protections, given converged threat vectors that impact information, data, people and assets.

Artificial Intelligence (AI):

In 2018, a NITI Aayog report stated that India will hold a late-mover advantage in real world application of artificial intelligence (AI). Worldwide, spending by governments and business on AI technology will top $500 billion in 2023, according to IDC research. Moreover AI applications on top of security solutions helps break the boundaries of our industry’s value to practitioners, by embedding non-security applications that take data from the proliferation of sensors of all types to correlate data points or find trends that can save businesses money or enable them to act more swiftly.

In a pre-event discussion with panel lists from an AI panel held at SNG 2022, the expert panel lists (reflecting integrators, vendors and practitioners) indicated they see sweeping AI frameworks coming, but admitted the industry is not yet prepared to define a framework for AI, noting that the technology’s rate of change is likely outpacing our ability to construct implementation frameworks, particularly ethical frameworks.

 

“IN 2023, ARTIFICIAL INTELLIGENCE WILL BECOME REAL IN ORGANIZATIONS. NO-CODE AI, WITH ITS EASY DRAG-AND-DROP INTERFACES, WILL ENABLE ANY BUSINESS TO LEVERAGE ITS POWER TO CREATE MORE INTELLIGENT PRODUCTS AND SERVICES.”

—TRENDS FUTURIST BERNARD MARR, WRITING FOR FORBES IN NOVEMBER 2022

 

Autonomous Devices:

Autonomous devices are a physical form of autonomous technology. Robots, both functional and humanoids, drones and vehicles are a few examples of autonomous devices. Autonomous devices learn from their surroundings and complete tasks without continued human input.

Automation of repetitive security tasks in lower-risk environments (think robots doing automated patrols in unstaffed facilities) and partly about highly responsive situational awareness (flying a drone to a remote or dangerous location for visual input back to the command post), but the real opportunity being seen for 2023 is connecting improved robotics with AI-embedded intelligence to finally put more “autonomous” in “autonomous devices,” some of which required an operator to previously drive the robot. Notably the International Standards Organization narrowly defines robots to not include remote-controlled solutions such as remote-controlled drones and ground vehicles.

Over half a million industrial robots were installed in 2021 according to the International Federation of Robotics (IFR), and that doesn’t even include robots for security applications, which are outside of the scope of the IFR’s annual World Robotics research.

Workforce development:

Workforce development from the societal centric perspective is defined as initiatives that educate and train individuals to meet the needs of current and future business and industry in order to maintain a sustainable competitive economic environment.

In a survey they found attracting skilled labor is a top concern, and there’s only one solution in today’s hyper-competitive labor market: “We must train our own.” Long established as a factor limiting companies’ growth (especially that of the systems integrators), expanding the workforce has become a key focus of organizations like SIA, which partnered with the Electronic Security Association to cofound the Foundation for Advancing Security Talent (FAST) to drive awareness of security industry employment opportunities.

Smart practitioners, particularly larger corporations with extensive security teams, are also hiring talent from their integrators and vendors in some cases, recognizing that they need internal personnel with the skillsets that they once could wholly outsource. Others are instead outsourcing or embedding integrator talent into their organization.

70% of employees work through mobile devices, with 200 million worldwide using mobile business apps. What’s more, 84% of decision makers plan to increase spending on mobile applications that drive employee productivity, reduce costs and enhance customer satisfaction.

The mobile workplace is a place that offers a host of benefits. Its core objective is to make employees as productive as possible, whether they are at their desks, in the field or working remotely. It’s all about equipping staff with the tools they need to do their jobs more efficiently, putting those tools conveniently at their fingertips, and connecting processes so that everything within a business works more cohesively.
 
Smartphone applications will increasingly be employed in 2023 to control physical security systems. Managers will have fingertip control over who has access to certain zones and facilities, and will be able to set those controls from wherever they happen to be working.
 
Security analytics will collate rich data insights from a suite of IoT connected devices, delivering them into the hands of decision makers via their smart devices, helping to inform security and operational strategies.

Data privacy:

Data privacy is the right of a citizen to have control over how their personal information is collected and used. Data protection is a subset of privacy. This is because protecting user data and sensitive information is a first step to keeping user data private. US data privacy laws are regulated at the federal level. Data privacy is typically applied to personal health information (PHI) and personally identifiable information (PII). This includes financial information, medical records, video footage security, social security or ID numbers, names, birthdates, and contact information. You might be surprised to learn that CCTV footage is subject to the GDPR (General Data Protection Regulation).

By 2024, 75% of the Global Population Will Have Its Personal Data Covered Under Privacy Regulations. Ultimately, the practitioner is responsible for ensuring that their data is protected and that systems are used ethically. This had led to pullback from many practitioners on their pace of adoption for some technologies like facial recognition to ensure that they have not only justifiable use cases but the procedures in place to ensure that advanced systems are used responsibly, and that data is only collected when it is needed.

Contactless security:

Contactless technology has become hugely important post-Covid, due to the strong reaction against physical contact. It’s also about the user experience, with people increasingly wanting things to be instant and simple.


Contactless security is therefore, unsurprisingly, becoming more commonplace. Biometric access, using the likes of fingerprints, iris scans and facial recognition to identify authorised personnel for physical access into a building or specific part of it, is already becoming the norm, whilst other contactless entry technologies that are set to be even more widely adopted during 2023 and beyond include Bluetooth Low Energy (BLE), and smartphone NFC (Near Field Communication) keyless entry, as well as QR code entry for temporary access.


For added security, multi-factor authentication (MFA), the use of more than one method of identification, is likely to become more widely adopted, as organisations batten down the hatches, making it harder for would-be unauthorised entrants to gain access.