Background:
Because there are many components in motion, we've compiled a list outlining requirements, clarifications, and areas of responsibility to ensure the seamless integration between Inlet and the lock system.
Read more about the security principals for Inlet and the connections to locks here.
Practical and Technical Requirements:
- Locksmith installs the locks.
- The IT supplier provides a server capable of running the Hedsam software and ensures the server's security with a firewall and access control measures.
- The server needs to be connected to a static IP or a URL.
- IT supplier configures HTTPS certificates or a proxy to enable proper HTTPS communication over the internet.
- Installer makes sure Hedsam version 24.2.2 or newer is installed on the server and configures the locks and access groups.
- Installer must create an API user for Inlet to use, it should be able to read status and work with devices, and send commands.
- IT supplier ensures IP whitelisting and sets up port forwarding on port 5443(https) from an external port to an internal port on the server, enabling access to the API.
- Locksmith or IT supplier needs to verify that the windows firewall allows traffic on port 5443, and that the web service is able to communicate out.
- Inlet needs to receive the following information by mail to support@inlet.tech:
- Customer Name
- Information on what locks and lock groups Inlet should set up.
- Hedsam API username
- Hedsam API password
- Public URL or static IP address of the server.
- Inlet retrieves IDs for the locks to configure Inlet with the locking system.
- Inlet provides information to the main system/booking system for testing.
- Inlet requires a minimum of 2 weeks of testing with the main system/booking system after the installer has completed all the steps above.
IP addresses that need to be whitelisted:
Required: 52.164.185.179
Required: 77.110.204.178
Ports that need to be mapped:
External TCP port 443 to internal TCP port 443 on the Server.
Access System Server IP Address Configuration:
A static IP address should be assigned to prevent it from being changed during a restart, and causing downtime due to the mapping in the previous point