Protocols About 2 min read

BACnet/IP

BACnet/IP carries BACnet traffic over an IP network. Check discovery, broadcasts and routing alongside the objects, services and access rules your integration needs.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

The licensed BACnet standard is required for normative BVLL and NPDU/APDU encoding and conformance work.

Verification and testing

Overview#

BACnet/IP, defined by Annex J of the BACnet standard, carries BACnet network and application messages in a BACnet Virtual Link Layer (BVLL) over UDP/IP. Deployments commonly use UDP port 47808 (0xBAC0), but port, BACnet network number, subnet, and routing design must come from the project configuration.1

Broadcast domains and BBMDs#

BACnet discovery and some service patterns use broadcasts. IP routers don't normally forward subnet broadcasts. A BACnet Broadcast Management Device (BBMD) distributes BACnet broadcasts between configured IP subnets, while a Foreign Device can register with a BBMD for a bounded lifetime.

Treat the Broadcast Distribution Table and Foreign Device Table as controlled routing/security configuration:

  • allow only expected peers and registration sources;
  • avoid duplicate or circular BBMD meshes;
  • monitor table changes, registration churn, and broadcast rate anomalies;
  • never solve reachability by exposing BACnet UDP to the public Internet;
  • document NAT explicitly, addresses carried in BVLL control information and topology assumptions can make casual translation fail.

Client state#

BACnet confirmed services use invoke identifiers to correlate responses. Keep a bounded per peer transaction table and distinguish SimpleACK, ComplexACK, Error, Reject, Abort, timeout, and transport loss. Segment handling, maximum APDU, windowing, retries, and concurrent invoke IDs must follow the peer's declared and observed limits.

Discovery results are untrusted input. Enforce maximum message and collection sizes; normalise neither object names nor vendor strings into identifiers; and detect a device instance appearing at an unexpected address. Don't let repeated I Am traffic overwrite a trusted inventory binding without review.

Security posture#

Classic BACnet/IP doesn't give every message modern cryptographic peer authentication or confidentiality. Network isolation, strict routing, source/destination allowlists, BBMD governance, write authorisation, and monitoring remain necessary. Where products support it, BACnet Secure Connect provides a TLS based data link; migration still requires object/service authorisation and secure management planes.

Packet capture or active Who Is can expose building topology and may load controllers. Validate discovery rate limits, routing boundaries, write controls, and recovery behaviour in an authorised environment before enabling them at a site.

Primary sources#

Section overview · Wiki home

  1. ASHRAE BACnet Committee, BACnet FAQ ↩