With the release of Access It! v7.3, support has been added for communication between the LP-4502 and BEST Wi-Q gateway. Communication between the devices is done via the CIA (Controller Interface API) protocol.
- Maximum 62 Wi-Q Locks per Wi-Q Gateway
- Maximum 62 locks per Mercury Panel
- When determining how many LP4502 panels will be needed to support a Wi-Q system, please consider the total credentials associated with locks downstream of the LP4502 panel
Maximum Credential Count Per LP4502 200 400 1000 4000 8000 16000 Maximum Supported Gateways Per LP-4502 12 10 6 4 3 2
The following licensing option must be enabled within the Access It! License and is a per lock count license.
- BEST Wi-Q Lock Count - 1/x
The following components are required to complete the integration.
- Access It! min s/w v7.3
- LP-4502 with Over-Watch add-on min f/w v1.292
- BEST Wi-Q Gateway pre-programmed with an IP address min f/w v4.1.0.7
Consult BEST documentation for IP address programming.
Over-Watch Software
The Panel Utility is required to download the necessary firmware file. To obtain the firmware required for the Over-Watch service contact Access It! Technical Support.
- On the LP-4502 set S1 - Configuration DIP Switch DIP 2 ON
- Apply power to the LP-4502 controller
- Manually configure a computer to 192.168.0.100
- Using a crossover cable, connect computer to the on-board NIC of the LP-4502
- Open the Panel Utility (Start | Programs | Access It! | Client Utilities)
- Click the Attach button
- Select model LP-4502 96Mb
- Select Comm Type TCP/IP
- Select Address 0
- Enter IP Address 192.168.0.251
- Select TCP Port 3001
- Click OK
Once connected, the lower right icon will report Online - Select Download SCP Firmware
- Navigate to the Over-Watch firmware
- Click Open
- Wait 90 seconds for firmware download to complete
- Click Detach
- On the LP-4502 set S1 - Configuration DIP Switch DIP 2 ON
- On the LP-4502 set S1 - Configuration DIP Switch DIPs 1, 3 & 4 OFF
- Apply power to the LP-4502 controller
- Manually configure a computer to 192.168.0.100
- Using a crossover cable, connect computer to the on-board NIC of the LP-4502
- Open a web browser and navigate to 192.168.0.251
- On the LP-4502 set S1 - Configuration DIP Switch DIP 1 ON
- Click Click Here to Login
- Click Continue to this website (not recommended).
- Enter a Username of admin
- Enter a Password of password
- Click Network from the left hand menu
- Under the section Interface 1, select Use Static IP configuration:
- IP Address:
- Subnet Mask:
- Default Gateway:
- Click Apply
- Click Security Options from the left hand menu
- Select (check) Enable Encrypted Partition
- Click Save Configuration
- Click Auto-Save from the left hand menu
- Set the Card Database Size accordingly
- Click Over-Watch from the left hand menu
- Enter a valid Listening port and click Save Configuration
Default port used is 1883. - Enter a username/password to be used by the Over-Watch service
- Click Add User
- Click Load Certificate from the left hand menu
- Confirm the Issued To field begins with "MAC", if not then proceed with these steps and then follow the Loading Certificate Section
- Confirm the Issued By field is "Mercury Security Certificate Signer Root CA", if not then proceed with these steps and then follow the Loading Certificate Section
- Confirm the Valid Time field ends in a year greater than 2040, if not then proceed with these steps and then follow the Loading Certificate Section
- Click Apply Setting from the left hand menu
- Click Apply, Reboot button
- Wait 60 seconds for LP controller to reboot
- Remove power from the LP controller
- Set all S1 - Configuration DIP Switch DIPs OFF
- Apply power to the LP controller
Loading Certificate
The following steps are only required when variables in steps 25, 26, or 27 with the LP-Web Browser settings indicate a non-standard certificate.
A customer generated certificate/key pair must be used. A valid certificate/key pair is available from ACRE or by dormakaba upon request. The certificate can be loaded to the LP-4502 via the Panel Utility which is located off of the start menu of every Access It! installation. The Panel Utility is also available as a standalone executable within the RS2 Technologies dealer portal.
- Open the Panel Utility
- Select Attach
- Set Panel Type to LP-4502
Specific memory selections are irrelevant for this task. - Set Comm Type to TCP/IP
- Set Address to 0
- Enter the IP address of the LP-4502
- Set port to 3001
- Set SIO port speed to 38400
- Click OK
Panel will report Online in lower right hand corner when connected. - Select Download Custom Certificate from the toolbar
- Navigate to the folder containing the PEM and CRT files
- Select the CRT file
- Click Open
The certificate will install without any confirmation. - Click Detach
- Close Panel Utility
- Power cycle the LP-4502
- Install and configure the LP-4502 controller to communicate with Access It!
- Navigate to the Hardware menu
- Select SCPs
- Edit the LP-4502 controller
- Set Protocol to Controller Integration API for either port 4 or 5
- Select the Web Logins tab
- Click New
- Select the next valid Login number
- Select Login type Over-Watch login
- Enter the username and password for the Over-Watch service configured within this LP-4502's web configuration
- Enter the IP address of this LP-4502
- Enter the listening port of the Over-Watch service configured within this LP-4502's web configuration
- Select (check) the Enable controller integration API messages option
- Click OK
- Click Save
- Click Save
- Within the hardware tree, expand the LP-4502
- Select SIOs
- Edit the first available uninstalled SIO
- Assign SIO name as needed
- Set model to BEST Wi-Q Gateway
- Within the Unique ID field enter the MAC address of the Wi-Q gateway
This can be found within the Wi-Q web interface. - Select the Options tab
- Set number of readers as needed
- Click Save
BEST Wi-Q Gateway Configuration
- Login to the Wi-Q Gateway's web interface
- Select the Inerface tab
- Select (check) Enable Mercury Mode
- Enter the IP address of the LP-4502
- Enter the Over-Watch port
- Enter the username and password for the Over-Watch service configured within the LP-4502's web configuration
- Select (check) Enable SSL
- Click Use Mercury Certificate
- Click Update
- Click Update
Sign On/Pairing Lock to Gateway
Lock With Keypad
- Login to the Wi-Q Gateway's web interface
- Under Status note the current Sign On Key
- For each lock to sign on/pair, perform the following sequence
- Enter 5678#
- Within 3 seconds enter the 6 digit sign on key followed by a pound (#) sign
- Sign-on is confirmed with a three tone increasing frequency beep1-beep2-beep3 and will then display in the Status page of the web interface.
If sign-on fails it will be a three tone with decreasing frequency.
Lock Without Keypad
- Login to the Wi-Q Gateway's web interface
- Create a sign-on card
The raw card number should be entered. For magstripe this is the full decimal number and for prox cards enter the complete octal card representation. - Using the temporary card that came with the lock, present it followed by the sign-on card to begin the sign-on process
If sign-on fails it will be a three tone with decreasing frequency.
Assigning Reader Numbers to Locks
- Within Access It!, navigate to the hardware tree and select Installed Readers
- If the column ACR Number is not displayed, add it by right clicking in the readers grid and selecting Column Chooser
Columns are added by double clicking or drag-and-drop. - For each BEST Wi-Q reader/lock, note the ACR number
- Login to the BEST Wi-Q gateway
- Select the Controllers tab
- For each lock, select edit within the ACR ID column and select the readers ACR number
- Click the green check mark to save settings
- Select Confirm
For more on configuring the BEST Wi-Q gateway, please refer to the WI-Q™ Mercury Setup And User Guide.
WQXM-PG Interface page shows no communication status message/color
- Validate the Over-Watch configuration
- Ensure matching certificate is used between LP-4502 and Wi-Q gateway
- Press UPDATE after making any configuration changes on the Interface page
WQXM-PG Interface page reports Connection Missing
This indicates that the gateway cannot communicate with Over-Watch on the LP4502 panel. Things to check during this state include:
- Panel power and network connectivity
- Gateway network connectivity
- Ensure that Over-Watch is installed and configured on the LP4502 panel
- Validate that the Over-Watch configuration in the WQXM-PG Interface page matches exactly what is configured in the LP4502
- Validate the IP address configured for Over-Watch in the WQXM-PG Interface page matches the IP address of the LP4502 panel
- Ensure that both the WQXM-PG and the LP4502 panel are configured with the same certificate – either the default or the customer/dormakaba provided.
- Ensure port 1883 (or the configured port) is open on the customer network
- Ensure the IP addresses for the WQXM-PG and the LP4502 panel are either on the same subnet or the customer network allows routing between the subnets.
With WQXM-PG firmware version 4.1.0.9 or later, the TEST CONNECTION button can be used to assist with basic connectivity. When the button is pressed, the gateway will validate that the IP address and the port of the LP4502 panel are reachable. One of three responses will be shown:
- Action Successful – Connection is available: This indicates that the IP address and port are good. The communication status should change to Yellow – Connection In Progress when this configuration is used.
- Action Error – Ping Failure. Check IP Address.: This indicates that the specified IP address of the LP4502 panel could not be reached. Check that the LP4502 panel is powered on, connected to the network, configured with the correct IP address, and ensure the IP addresses for the WQXM-PG and the LP4502 panel are either on the same subnet or the customer network allows routing between the subnets
- Action Error – Bad or Blocked Port. Check Port Number.: This indicates that the specified port number could not be accessed. Check that the port number entered matches the port number configured in the LP4502 panel Over-Watch page. Ensure that the customer network is not blocking this port. Ensure that the specified IP address is for the LP4502 panel and not for some other device on the customer network.