beroNet Cloud — manage devices remotely
The device opens the connection, not the cloud. A beroNet gateway sends an HTTPS request outward roughly once a minute, reports its current state, picks up any task waiting for it and reports back. Nothing from the outside has to reach into the customer network, and NAT is not a problem.
Each of those requests carries the network settings, the SIP registration, the state of the ISDN ports and the CPU and memory load. That is what the dashboard and the alerts are built from, and it is the first thing to look at when a device misbehaves.
What it is used for
- Remote monitoring of many devices at once, with connection and status changes
- Configuration and firmware updates across a whole fleet, scheduled if needed
- A dashboard with every device on a map, organised by site
- Notification when a device drops out
- Backup and restore of device configuration
- Activating a configuration and rebooting a device remotely
- Installing apps from the beroNet Market on one device or a whole fleet
- CRC error counters, SIP and LTE registration state
- Client management and provisioning on first boot (partner and professional accounts)
How a device joins the cloud
An account is organised by locations, typically one per customer site, and each device is assigned to one of them. There are two ways to register a device:
- From the device. In the gateway’s web interface, enter the beroCloud account credentials under Remote Management and enable cloud monitoring. The device needs internet access and a correct name server setting.
- Automatically at boot. With a Professional account, a redirect entry tells a device what to do the moment it starts: join a given account, load an XML configuration from a provisioning URL, or both — the connection to the provisioning server then runs over TLS with a certificate signed by beroCloud. Creating the entry requires the complete serial number and the MAC address of the device; both are on the label of the device or its box.
Security
- Device and cloud communicate over HTTPS only, and the beroCloud web interface is served over HTTPS as well.
- Besides its serial number, every device identifies itself with its own cloud key. The key can be changed if it may have been exposed.
- Configuration backups are uploaded only when the backup function is enabled, and are then stored on the beroCloud server. Projects whose configuration must not leave their own network provision their devices locally instead.
Getting started
Sign up at berocloud.beronet.com — a 30-day trial is free. The sign-up asks for a user name, the organisation name, an email address and a first location; the account is active once the email address has been confirmed. Registration, the dashboard and the redirect service are described step by step in the beroNet Wiki: beroCloud and Device Redirect Service.
Frequently asked questions
Does a beroNet device need beroCloud to work?
No. beroCloud is an addition, not a requirement. Every device is configured through its own web interface, and configurations can also be rolled out without the cloud: as an XML file from a provisioning server over HTTP, HTTPS or TFTP, through DHCP options, or through the device API.
Which firewall ports have to be opened for beroCloud?
No inbound port. The device opens an outgoing HTTPS connection to berocloud.beronet.com about once a minute. It needs internet access and a working name server setting; port forwarding and NAT rules are not required.
Can a device be removed from beroCloud again?
Yes. A device can be deregistered from beroCloud in its web interface at any time. The redirect service, which asks beroCloud for tasks when the device starts, can be switched off on the device as well.