Installation guide

D6600 | System Guide | 3.0 Operation
12 Bosch Security Systems, Inc. | 4/10 | 4998122712-04
3.4 Networking and Encryption
2. Check the firmware versions of the NIMs that will
be used in the system. For NIST approved AES
support, the version must be 5.16 or later. The
latest version is available on the D6600CD (v1.10
or higher) and the web site. To upgrade the
firmware in the CoBox, refer to the DeviceInstaller
Operation and Installation Guide
(P/N: 4998138688). DeviceInstaller version 2.01
(or later) is required to upgrade the firmware in
the NIMs.
If you are considering using or are
currently using networking and
encryption, read the following information
carefully.
In all cases, encryption is performed in the NIM
(Network Interface Module) that is used in the
D6680/D6682, D9133TTL-E, C900V2/C900TTL-E,
and DX4020. When encryption is used, the
encryption key coming to the D6600 must be the
same key used on all field devices that are reporting
to that IP address. Because you can use up to two
NIMs on the D6600, several combinations can be
used:
Both NIMs using encryption – two NIMs can use
different keys or the same key
One NIM using encryption, the other not using
encryption
Neither NIM using encryption
If encryption is On in the NIM at the D6600, then it
must be On in the field devices. If it is Off in the NIM
at the D6600, then it must be Off in the field devices.
If you are not currently using encryption, refer to
Section
3.4.1 Using Encryption for the First Time
on page
12.
If you are currently using encryption, refer to
Section
3.4.2 Upgrading Encryption on page 12.
3.4.1 Using Encryption for the First Time
When deciding to use encryption for the first time:
1. Check the hardware versions of the NIMs that will
be used in the system. If all of the hardware
versions used in a system do not match the
versions listed below, encryption cannot be used
on that system when they all report to one
D6680/D6682. Any device that is not at the
required hardware version must be replaced with
a current version before it supports encryption.
The D6680 must be a COBOX-FL-01 version.
This is the only hardware version that
supports encryption. The COBOX-E2-01
cannot be used.
The D9133TTL-E and C900TTL-E NIMs must
be CM-E2-RAD versions. This is the only
hardware that supports encryption. The
CBXM-ERAD cannot be used.
For more information on how to obtain a
new D6200CD or how to obtain access to
the Web site, refer to Section 3.4.4
Obtaining Latest D6200CD Software on
page 16.
3. When enabling encryption on any NIM, it
communicates only with a NIM that also has
encryption enabled and has the same encryption
key programmed in it. This means that when you
enable encryption, all devices must be
programmed in order for them to communicate
with the D6680/D6682. During the time that it
takes to program the encryption key into the
NIMs, the devices will not communicate with the
D6680/D6682.
4. You can have two D6680s/D6682s on one
D6600, one having encryption On and the other
having it Off. This would allow for field devices to
communicate with the D6680/D6682 with
encryption Off and begin the programming of the
field devices to send with encryption On to the
second D6680/D6682. This would allow devices
to be programmed for encryption without the loss
of any signals or data to the D6600. For more
information on how to use two D6680s/D6682s in
a system as described, refer to Section
3.4.3
Using Two D6680s or D6682s in a System on
page
13.
3.4.2 Upgrading Encryption
If encryption is currently being used at a site that was
set up before to the release of D6600CD v1.10 or NIM
firmware versions before to v5.16 on the TTL-E
devices, there are some items to consider before
using other releases.
To ensure that NIST approved encryption is being
used and communication between the NIMs
continues, upgrade all TTL-E NIMs to v5.16 or later,
D6200 v1.10 or later, and D6202 v2.3 or later. All
versions of NIMs, D6200 software, and D6202
software are shipped with the latest software and
firmware installed.