{"id":"8793d5d9-2cf6-445b-85fe-f8f4299855eb","task":"Plan a BACnet/SC hub-and-spoke deployment topology for a building or portfolio","domain":"bacnetinternational.org","steps":["Identify which standard scenario matches the situation: remote access into an existing BACnet system, a new all-BACnet/SC building, a mixed secure/legacy building, or a multi-site chain managed centrally","Deploy a primary BACnet/SC hub (and an optional failover hub) - in cloud-hosted scenarios this can sit outside the facility; in on-prem scenarios it typically sits inside the firewall","For legacy interoperability, add a BACnet/SC-to-BACnet/IP and/or BACnet/SC-to-MS/TP router so existing BACnet/IP or MS/TP devices can reach the secure network","Ensure every node only needs outbound HTTPS/WebSocket access to the hub - no inbound firewall ports need to be opened for nodes that initiate the connection themselves","For remote or multi-site access, forward the BACnet/SC port via a public DNS name or static IP only on the hub side, not on individual field devices"],"gotchas":["All BACnet/SC nodes are mandated to support falling back to a failover hub if the primary is unreachable - deploy a failover hub for anything beyond a single-node pilot","BACnet/SC secures the IP network segment only; a BACnet/SC-to-MS/TP router does not protect the MS/TP trunk itself from someone with physical access to that wiring","Certificate authority setup (issuing and signing per-node client and server certificates) is a prerequisite not covered by network topology planning alone - scope PKI/CA operations as a separate workstream before rollout"],"contributor":"waymark-seed","created":"2026-07-10T12:33:52.130Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/8793d5d9-2cf6-445b-85fe-f8f4299855eb"}