CONNECTIVITY AND TECHNOLOGY
Security for connected scales and their data
Align access, network connections and device protection with your IT and OT environment. The standard architecture uses encrypted communication and device-initiated connections.
- Encrypted cloud connections
- Permissions matched to user responsibilities
- Controlled access to scales and data
Devices establish outbound connections
Browsers and APIs use HTTPS/TLS on TCP 443. CloudScaleLink and Neutron use outbound MQTTS/TLS on TCP 443 for cloud connections. In the standard architecture, the cloud does not initiate unsolicited inbound connections to the customer's network.
- A public device IP or port forwarding to the scale is generally unnecessary.
- A project-specific static destination IP configuration is possible for strict policies.
- Align DNS, time synchronisation and local connections with network rules.
Give each user appropriate access
Roles separate operation, review, service and administration. Configuration, calibration, outputs, updates and user management receive specific restrictions.
- Named accounts and least-privilege permissions.
- Two-factor authentication options.
- Restrictions by IP address, country or region.
- Logical separation of organisations, devices, users and data.
- Restricted external service access.
Control devices and access
Include device access and updates in your company's management procedures. Administrators control configuration and service permissions; operators use the functions needed for their work.
- Ethernet is generally recommended for fixed industrial stations.
- Include updates in a controlled company procedure.
- For critical systems, plan testing and rollback.
Implementation with your specialists
We suggest a separate OT/IoT segment, necessary outbound traffic, protected physical access, regular permission reviews and MFA for privileged accounts. Final rules depend on your security environment.
GOOD TO KNOW
Answers to your questions
Do we need to open inbound ports to the device?
Not in the standard architecture. The device establishes an outbound encrypted connection. We review network rules for the complete configuration.
Can we restrict access to our corporate VPN?
An allowed public-IP list can include your corporate VPN's outbound addresses. User permissions and MFA provide additional protection.
Where is data stored?
Online workflows store data in Scale Monitor Cloud. Neutron NT also keeps local operational data at the scale and synchronises it with the cloud.
START WITH ONE WEIGHING STATION
From your workflow to a proposed solution.
Send the scale model, a photograph of its connections and a brief workflow description. We will check connectivity options and propose the next step.