Protocols and data

BACnet routing, BBMDs and foreign devices

How BACnet messages cross networks: routers and network numbers, BBMDs and broadcast distribution tables, foreign device registration, and how to design discovery across IP subnets.

A Who-Is from the BMS that finds only the devices on its own subnet, or finds some of them twice, is almost always a routing problem. BACnet messages cross network boundaries in two ways. A BACnet router sits between an MS/TP trunk and BACnet/IP, and a BBMD (BACnet broadcast management device) carries broadcasts between the IP subnets of one BACnet/IP network, because IP routers drop them. A device outside those subnets can register with a BBMD as a foreign device.

This guide is part of the BACnet and building protocols series. Read the discovery guide first for device instances and network numbers.

BACnet routers

A BACnet router has one port on each network it joins, for example one BACnet/IP port and two MS/TP ports. Clause 6 of ASHRAE 135 defines the network layer it uses. Each port has a network number from 1 to 65,534. Network number 65,535 means "all networks" and is used for global broadcasts.

An MS/TP device's full address is its network number and its one-octet MAC address. Masters use MAC 0 to 127, slaves can use up to 254, and 255 is the MS/TP broadcast. A BACnet/IP client sends a request for that device to the router's IP address, with the trunk's network number and the MAC in the destination fields of the NPDU (DNET and DADR). The router passes it on to the trunk. The BACnet/IP vs MS/TP guide explains token passing and why a routed read to a slow trunk takes longer.

A client learns which router serves a network in two ways. It can send Who-Is-Router-To-Network, and the router answers with I-Am-Router-To-Network, which lists the networks behind it. Or it can read the source network and address (SNET and SADR) in a routed reply, such as an I-Am, and note the router's IP address as the path. A router also broadcasts I-Am-Router-To-Network on each port when it starts. If the client's subnet never receives these broadcasts, the client cannot find the trunks behind the router.

The standard allows only one active path between any two devices. Every MS/TP trunk needs its own network number, and that number must differ from the BACnet/IP network's number. Two routers that claim the same network split or loop its traffic. The NPDU hop count starts at 255 and each router reduces it by one, so a looped message is discarded in the end, but only after many passes over the network. To a BMS, a duplicate network number looks like devices moving between trunks. To find one, send Who-Is-Router-To-Network with no network number and capture the replies. Two I-Am-Router-To-Network replies that list the same number identify the two routers. A Reject-Message-To-Network with reason 1 (the router has no path to that network) also points to a numbering fault.

On many sites the router is a port on the BMS supervisory controller, so the controller's network number settings are the router's settings. Read them before you add a second router.

Why broadcasts stop at IP routers

BACnet uses broadcasts for dynamic binding (Who-Is, I-Am, Who-Has, I-Have), for TimeSynchronization and UTCTimeSynchronization, and for unconfirmed notifications sent to a broadcast address, such as UnconfirmedCOVNotification and UnconfirmedEventNotification. Newman's account of the Cornell campus adds two site uses: an emergency load-shedding command, and a value that many control processes share.

On BACnet/IP, each broadcast is a UDP datagram to the subnet broadcast address, for example 10.1.10.255, on port 47808 (0xBAC0). IP routers do not forward it. Since RFC 2644 (1999), routers also drop directed broadcasts to a remote subnet by default. So a client on one subnet cannot discover devices on another, even when unicast traffic between the two subnets works.

BBMDs

Annex J of ASHRAE 135 defines the BBMD. On most sites it is a function inside a supervisory controller or router, not a separate device. Each BBMD holds a broadcast distribution table (BDT). The BDT has one entry for the local BBMD and one for each remote BBMD that must receive this subnet's broadcasts. Each entry holds the BBMD's IP address and UDP port and a 4-octet broadcast distribution mask.

When a device on its subnet broadcasts, the BBMD wraps the message in a Forwarded-NPDU. This carries the IP address and port of the device that sent the broadcast. The mask on each BDT entry sets how the message reaches the remote subnet. With a mask of 255.255.255.255 (two-hop), the BBMD sends the Forwarded-NPDU by unicast to the remote BBMD. The remote BBMD then broadcasts it on its own subnet and sends it to each foreign device registered with it. With the subnet mask, for example 255.255.255.0 (one-hop), the BBMD sends a directed broadcast straight to the remote subnet. One-hop fails wherever IP routers drop directed broadcasts, which is their default, and it cannot pass NAT. Use two-hop unless site IT has agreed to forward directed broadcasts.

Addendum 135-2008o (2009) changed some of the original Annex J rules. The current rules are:

ItemRule
BBMDs per subnetAt least one on each subnet that takes part. Two on one subnet only if their BDTs share no entry; otherwise broadcasts loop between them
MasksThe mask for a given subnet is the same in every BDT that lists it
Traffic between BBMDsUnicast UDP, usually on port 47808. Firewalls between subnets must pass it in both directions
Reads after discoveryUnicast from the client to the device, not through the BBMDs. Firewalls must pass this traffic too

The original Annex J required every BDT on a BACnet/IP network to be identical, so that every device received every global broadcast. Newman explains why Cornell did not follow that rule: most broadcasts matter only inside one building. Each Cornell BDT lists only the local BBMD and the BBMD at the operations centre. Newman calls this a split horizon, because the other networks are "below the horizon". Operators at the centre see all broadcast traffic. A misconfigured controller affects only its own building, for example one that sends alarms to a recipient that does not exist, or sends a flood of COV notifications because its COV increment is too small. Addendum 135-2008o removed the identical-BDT rule, and a BDT may now forward broadcasts only to the subnets that need them.

A split horizon has a cost. A workstation outside the operations centre cannot find devices in other buildings with a global Who-Is. It needs a static binding from device instance to IP address, or it must register as a foreign device with the BBMD of the building it needs.

A two-building example

A site has one BACnet/IP network, network number 10, across two buildings. Each building has its own IP subnet and a supervisory controller that is both the BBMD and the router to the building's MS/TP trunks.

Building 1Building 2
IP subnet10.1.10.0/2410.2.10.0/24
BBMD and router10.1.10.2:4780810.2.10.2:47808
MS/TP trunksNetworks 101 and 102Network 201
BMS workstation10.1.10.50None

Both BBMDs hold the same BDT:

Broadcast distribution table
10.1.10.2:47808   mask 255.255.255.255
10.2.10.2:47808   mask 255.255.255.255

A discovery from the BMS then runs like this:

  1. The BMS broadcasts a global Who-Is to 10.1.10.255 as an Original-Broadcast-NPDU.
  2. BBMD 10.1.10.2 sends a Forwarded-NPDU with origin 10.1.10.50:47808 by unicast to 10.2.10.2.
  3. BBMD 10.2.10.2 broadcasts the Forwarded-NPDU on 10.2.10.255. Its router function also sends the Who-Is out on trunk 201.
  4. Controller 10.2.10.37 broadcasts its I-Am, and the I-Am returns to 10.1.10.0/24 the same way through both BBMDs.
  5. The BMS takes 10.2.10.37:47808 from the originating address in the Forwarded-NPDU and sends ReadProperty requests to that address by unicast. The BBMDs take no part in the read.
  6. MS/TP device 5 on trunk 201 answers through the router. Its I-Am carries SNET 201 and SADR 5, so the BMS sends later reads to 10.2.10.2 with DNET 201 and DADR 5.

A commissioning laptop on the site VPN at 10.50.0.23 registers with 10.1.10.2 as a foreign device, with a time-to-live of 300 s. The BBMD keeps the entry for 330 s. Set the laptop to re-register every 150 s, so that one lost registration does not drop it.

Foreign devices

A foreign device is a BACnet/IP device whose IP subnet is not part of the BACnet/IP network it wants to join. Typical examples are a commissioning laptop and a remote workstation. It needs IP reachability to one BBMD, and it uses these Annex J BVLC messages:

  1. The device sends Register-Foreign-Device to the BBMD, with a time-to-live (TTL) in seconds. The field is two octets, so the maximum is 65,535 s.
  2. The BBMD answers with BVLC-Result. Code 0x0000 means success. Code 0x0030 is a Register-Foreign-Device NAK: the BBMD does not accept registrations, its table is full, or a vendor allow-list rejects the address.
  3. The BBMD adds the device to its foreign device table (FDT). It keeps the entry for the TTL plus a fixed grace period of 30 seconds (clause J.5.2.1).
  4. The BBMD sends the broadcasts from its subnet and from its BDT peers to the device as Forwarded-NPDUs.
  5. The device sends its own broadcasts to the BBMD as Distribute-Broadcast-To-Network. The BBMD broadcasts them locally, forwards them to its BDT peers and sends them to its other foreign devices. If the device is not registered, the BBMD answers with code 0x0060.
  6. The device re-registers before the entry expires. If it does not, the BBMD deletes the entry. The device then stops receiving broadcasts, and it gets no error.

The FDT size is set by the BBMD's manufacturer. Check it in the manual when several tools must register at the same time. Accept registrations only from the address ranges that need them: a registered device receives every broadcast on the network.

Network address translation (NAT) between a foreign device and the BBMD causes two faults. The first is on the device side. The BBMD records the UDP source address of the registration, which is the NAT router's public address and port. Forwarded broadcasts reach the device only while the NAT router keeps that mapping open. Addendum 135-2008o says that a foreign device behind NAT should re-register often, and that the interval depends on the NAT router and may be 30 seconds or less.

The second fault is on the BBMD side. A Forwarded-NPDU carries the private address of the device that sent the broadcast, and a client on the far side of the NAT router cannot reach that address. A BBMD that supports NAT puts the NAT router's global address and port in that field instead, and each BDT entry holds the global address of the peer BBMD. NAT support is optional and is declared in the BBMD's PICS. Behind one NAT router, only one device on a BACnet/IP network can be reached from the global side. That device routes to the others, which must be on other BACnet network numbers. One-hop distribution cannot pass NAT, so these networks use two-hop.

Design discovery for a site

Agree a written plan with the BMS owner and site IT before installation:

  1. Assign one network-number and device-instance scheme for the whole site. Record it before installation.
  2. List the IP subnets that carry BACnet, and the UDP port on each.
  3. Name the BBMD on each subnet that takes part, its address and its BDT, with the mask for each entry.
  4. Open UDP 47808 between the BBMDs, and between each client and the devices or routers it reads.
  5. Name the BBMD that accepts foreign devices, and the address ranges it accepts.
  6. Decide which broadcasts each subnet needs, and write the BDTs to match.

Newman's Cornell scheme shows how to make numbers readable. A network number is the building's four-digit facility code followed by one digit for the network in that building, so the networks in the building with code 2000 are 20000 to 20009. A device instance adds two more digits, FFFFNDD, so each network holds up to 100 devices. A technician can read the building from any address in a capture. Device instances stop at 4,194,303, so the scheme does not work for facility codes above 4194. On a smaller site, use a network number of 100 × building + trunk and a device instance of 1000 × network number + MAC address. MS/TP device 12 on trunk 2 of building 1 is then device 102012. Choose the scheme first. A renumber after handover breaks every BMS point binding, trend log and graphic that stores the old instance.

Count the broadcast load before you choose the BDTs. A global Who-Is with no instance range gets one I-Am from every device. With two-hop distribution across n BBMDs, each I-Am crosses between subnets n − 1 times and is broadcast on n subnets. On a site with 2,000 devices and 10 BBMDs, one global Who-Is causes 18,000 Forwarded-NPDUs between BBMDs and 20,000 local broadcasts, plus copies to each foreign device. A Who-Is with an instance range still goes to every subnet; only the replies are fewer. A Who-Is sent to one network number (a remote broadcast) reaches only that network. Use it when you know where the device is.

If site IT will not forward BACnet broadcasts across subnets or a WAN, use BACnet Secure Connect (BACnet/SC). Addendum 135-2016bj added it in 2019. Each node connects to a hub over a TLS-secured WebSocket, and the hub distributes broadcasts, so the network needs no BBMDs. Every device, or a router in front of it, must support BACnet/SC.

Faults and how to find them

Read the BDT and FDT of every BBMD with a BACnet tool (Read-BDT and Read-FDT), and compare them. Then capture UDP 47808 on each side of the firewall. In Wireshark, bvlc.function == 0x04 shows Forwarded-NPDUs, bvlc.result shows NAK codes, and bvlc.reg_ttl shows the TTL in each registration.

SymptomLikely causeCheck
Devices on the local subnet appear, others do notNo BBMD on one subnet, a missing BDT entry, or a firewall that blocks UDP 47808 between BBMDsRead-BDT on each BBMD. Capture on the remote subnet for Forwarded-NPDUs
Remote devices appear, but reads time outThe firewall passes BBMD traffic but blocks unicast from client to deviceCapture the ReadProperty request and look for the reply on both sides
Every I-Am arrives twiceTwo BBMDs on one subnet with a shared BDT entry, or different masks for one subnet in different BDTsRead-BDT on every BBMD on the subnet and compare them
A foreign device finds devices, then goes quietThe registration expired, or a NAT mapping closedRead-FDT for the entry and its remaining time. Compare the re-registration interval with the TTL
A foreign device's Who-Is gets code 0x0060The device is not registered with that BBMDLook for a Register-Foreign-Device and its BVLC-Result
Registration gets code 0x0030Registration is disabled, the FDT is full, or the address is not allowedThe BBMD's foreign device settings
Devices on a trunk seem to change identityTwo routers use the same network numberWho-Is-Router-To-Network, then look for two routers that list the same network

Routing with Edge

Edge on the ZGW-20 Gateway is a BACnet/IP client. It discovers devices with a global Who-Is sent to the broadcast address in its BACnet settings, 255.255.255.255 by default, on UDP port 47808 by default. It records devices behind a BACnet router by their network number and MAC address, and reads them through that router. It does not connect to an MS/TP trunk directly.

Edge does not register as a foreign device and does not act as a BBMD. It finds devices on another subnet only when the site's BBMDs bring their broadcasts to the Gateway's subnet. Put the Gateway on the controllers' subnet, or on a subnet whose BBMD is in the site's BDTs. With a split horizon, the BBMD on the Gateway's subnet and the BBMD of each building it reads must list each other. After discovery, Edge reads each controller by unicast, so the firewall must pass UDP 47808 between the Gateway and each controller or router.

The Test Connection button in Edge's BACnet settings pings the configured local address. It sends no BACnet request and proves nothing about UDP 47808 or the BBMDs. Confirm each controller by its device instance in the discovery results, then by a sensor test that reads one point, before you rely on its data.

Common questions

What is a BBMD in BACnet?

A BACnet broadcast management device, defined in Annex J of ASHRAE 135. It is usually a function inside a supervisory controller or router. It receives BACnet broadcasts on its IP subnet and sends them as Forwarded-NPDU messages to the BBMDs listed in its broadcast distribution table, which broadcast them again on their own subnets.

Do I need a BBMD?

Only when BACnet/IP devices that must discover each other are on different IP subnets. Devices on one subnet see each other's broadcasts without one. Each subnet that takes part needs a BBMD. Two BBMDs on one subnet are allowed only if their tables share no entry, because shared entries make broadcasts loop.

What is BACnet foreign device registration?

A way for a device outside the subnets of a BACnet/IP network to take part in its broadcasts. The device sends Register-Foreign-Device to a BBMD with a time-to-live in seconds. The BBMD forwards broadcasts to it and accepts its broadcasts as Distribute-Broadcast-To-Network messages. The entry expires 30 seconds after the time-to-live unless the device re-registers.

What is the difference between a BACnet router and a BBMD?

A router connects two different BACnet networks, each with its own network number, such as MS/TP and BACnet/IP. A BBMD connects IP subnets that belong to one BACnet/IP network, and so share one network number, by forwarding broadcasts between them.

Can the ZGW-20 Gateway register as a foreign device?

No. Edge is a BACnet/IP client. It does not register as a foreign device and does not act as a BBMD. Put the Gateway on the controllers' subnet, or on a subnet whose BBMD is in the site's broadcast distribution tables.