BACnet finds devices by broadcasting a question and listening for the answers. A client sends Who-Is, and every device that matches replies with I-Am, which gives its device instance and its address. To make this work, each device needs a unique device instance, each network a unique network number, and the broadcast must reach the network where the device is. Most discovery problems break one of those three conditions.
This guide is part of the BACnet and building protocols series.
Three identities
| Identity | What it is | Scope | Example |
|---|---|---|---|
| Device instance | The instance number of the Device object, 0 to 4,194,302 | Unique across the whole site | 20102 |
| Network number | The number of one BACnet network, 1 to 65,534 | Unique across the whole site | 12 |
| Address on the network | An IP address and UDP port on BACnet/IP, or a MAC address from 0 to 254 on MS/TP | Unique on that network | 10.20.4.31:47808, or MAC 7 |
The device instance is the stable name. Clients discover a device by its instance and then remember its address. If the device moves to a new IP address, rediscovery finds it again under the same instance.
The BACnet Committee's primer states the rule: the instance number of the Device object must be unique across the entire BACnet internetwork. Object identifiers inside the device (analog-input 3, for example) need to be unique only within that device.
How Who-Is and I-Am work
- The client broadcasts Who-Is. It can ask all devices, or only devices with instances in a range.
- Each device that matches broadcasts I-Am. The reply carries the device instance, the largest message the device accepts, whether it supports segmentation, and its vendor identifier.
- The client records the source address of the I-Am, and binds the device instance to that address.
- The client then reads the Device object, usually its Object_List, to find the other objects.
A related pair, Who-Has and I-Have, finds a device by the name or identifier of an object it contains.
Some devices cannot take part. Karg's article on MS/TP explains that MS/TP slave devices never hold the token, so they cannot answer Who-Is by themselves. A router or a slave proxy answers for them, or the client binds to them statically with a configured address. The BACnet/IP vs MS/TP guide explains token passing and slave devices.
Why a device does not appear
| Symptom | Likely cause |
|---|---|
| Devices on the local subnet appear, others do not | Broadcasts stop at IP routers; the site needs BBMDs or foreign-device registration |
| No devices appear at all | A firewall blocks UDP 47808, the client listens on the wrong network interface, or uses another UDP port |
| One device is missing | Its instance is outside the Who-Is range, it is on an MS/TP bus behind a router with a wrong network number, or it is an MS/TP slave |
| A device appears and disappears, or values jump between two plants | Two devices share one device instance |
| Devices behind two routers are confused | Two networks share one network number |
| Discovery works, reads time out | The device answers broadcasts but not direct messages: NAT, a firewall rule, or a message size larger than the device accepts |
The routing and BBMD guide explains how broadcasts cross subnets.
Ping, discovery and a read prove different things
Test in this order, and record each result:
| Test | What success proves |
|---|---|
| Ping the IP address | The device's network interface is reachable. ICMP may be blocked, so failure proves little |
| Who-Is and I-Am | The device runs BACnet on this network and has the expected instance |
| Read Present_Value of one object | The client can address the device directly and the object exists |
| Values update over time | Polling or COV continues, with a recent timestamp on each point |
A green light at one step is not proof of the next. A device that answers ping may have BACnet disabled. A device that replies to Who-Is may reject a ReadPropertyMultiple request that it does not support.
Before you connect a new client
Agree these points with the BMS owner:
- the UDP port and the IP subnet of each BACnet/IP network;
- the network numbers already in use, and the device instance plan;
- whether BBMDs exist, where they are, and whether the new client may register with one;
- the time of day for discovery on a large site, because a global Who-Is causes a burst of I-Am replies.
Discovery with Edge
Edge on the ZGW-20 Gateway is a BACnet/IP client on UDP port 47808 by default. It discovers devices with a broadcast on its local network, and it identifies each device by its device instance. Its connection test is a ping. Discovery, a point read and a steadily advancing timestamp are the later steps of the ladder above. For controllers on other subnets, the site's BACnet network must provide broadcast management or routing.
Common questions
What is a BACnet device instance?
The number in the device's Device object identifier, from 0 to 4,194,302. It must be unique across the whole BACnet internetwork of a site, because clients find and bind to devices by this number.
What do Who-Is and I-Am do in BACnet?
Who-Is is a broadcast that asks devices to identify themselves, optionally only those in a range of device instances. Each device that matches replies with I-Am, which carries its device instance, its maximum message size, whether it supports segmentation and its vendor identifier. The client learns the device's address from the reply.
Why can't I discover a BACnet device?
Common causes are a device on another IP subnet with no BBMD, a firewall blocking UDP 47808, a device instance outside the Who-Is range, a duplicate device instance, an MS/TP slave that cannot answer broadcasts, or a client bound to the wrong network interface.
What is a BACnet network number?
A number from 1 to 65,534 that identifies one BACnet network (an IP subnet used for BACnet, or an MS/TP bus) on a site. Routers use it to forward messages. Every network on a site must have a different number.