Hardware

Recommended hardware and virtualization requirements for production environments.

Minimum requirements

  • Processor: Intel Xeon E5 or newer / AMD Ryzen 5 or newer

  • CPU: At least 4 cores; 8 cores or more recommended

  • RAM: At least 4 GB; 8 GB or more recommended

  • Disk space: At least 80 GB; 260 GB or more (SSD) recommended

  • Network card: Gigabit Ethernet

  • Operating system: Debian 12 (Bookworm) or newer

Software & Operating System

Requirements for the installed operating system.

Installation:

  • NDPro is a Node.js project designed to run on the Debian Linux distribution.

  • Operating system: Debian 12 (Bookworm, "No-Desktop" default setup) on a single partition

  • Configuration of an IPv4 adapter (static or DHCP) via 1GbE or 10GbE Ethernet

  • SSH access for administration; provision of a user named "ndpro"

  • Configuration of hostname and hosts file according to project requirements

  • Installation of the NDPro environment via the included *.sh script; this script automates the installation of the following additional modules: curl, openvpn, openssl, htop, zip, unzip, ufw, samba, sqlite3, ca-certificates, gnupg, and apache2

  • The script installs the latest Node.js LTS version (22.11 or newer) for NDPro operation, along with PM2 as a watchdog process and npm/ncu as package managers

  • The installation process includes an option to configure SMB/Samba for directory sharing

  • Automatic setup of the UFW firewall, allowing traffic for SSH, (SMB), HTTP, and HTTPS

  • Download of the current NDPro package from update.ndpro.app

  • Extraction and installation of the NDPro environment within the "ndpro" user's home directory

User Context:

NDPro runs under the "ndpro" user context without root privileges; services are managed via PM2/systemd.

  • Generation of a self-signed certificate as a default solution (to be replaced later by a user-provided certificate)

  • Setup and configuration of the Apache2 VirtualHost environment for HTTPS forwarding/proxying

  • Setup of the OpenVPN client on the NDPro update bridge (AES-256-GCM, ECDSA secp521r1 + TLS)

  • Finalization, including provision of the system key for documentation purposes

  • Further system configuration is performed via the NDPro web interface

Network & Firewall

NDPro is designed as a central platform for local operation. Communication with AV and building technology systems takes place locally via IP-based device interfaces. All core functions—such as control, automation, user interfaces, backups, and scheduling—are fully available offline. An internet connection is required for the following services: operating system/service updates, NDPro Updater (software updates & patches), and NDC Monitoring (status reports, notifications).

DNS routing for visualizations:

Touch panels, web browsers, and mobile devices always connect to the NDPro server using a domain name. The configured DNS server must resolve this domain to the IP address of the NDPro controller.

Example: projectdomain.ndpro.app → 192.168.100.5

Production environments require valid, publicly trusted TLS certificates. These can be provided either by the operating organization or the integration partner. Automatic renewal, for example via Let’s Encrypt, is recommended. Wildcard certificates are fully supported. For initial setup, NDPro generates a self-signed certificate.

The configuration files generated by NDPro contain the configured domain. Touch panels and web browsers expect a valid TLS connection by default. Servers using self-signed certificates are rejected by many devices and browsers unless explicitly allowed.

For test environments, many manufacturers provide an option to temporarily bypass certificate validation. This option should only be used for development and testing purposes.

To ensure reliable TLS communication, the device’s date, time, time zone, and NTP synchronization must also be configured correctly. DNS resolution should be verified directly on the target device. The configured domain must resolve to the IP address of the NDPro server.

Firewall rules for online access:

  • HTTPS (TCP Port 443): The controllers require HTTPS access for the secure transmission of status, operational, and error reports.

  • DNS (TCP/UDP Port 53 + 853): The controllers require access to an internal or external DNS server for domain name resolution.

  • NTP/SNTP (UDP Port 123): The controllers require access to an internal or external time server (NTP) to ensure accurate timestamping of system events.

  • VPN (UDP Port 1201): The controllers require access to the NDPro update server to continuously receive software updates and security patches.

  • General: For operating system updates, TCP ports 80 and 443 should be enabled (either selectively or permanently) to allow the download of update packages from Debian repositories.

Firewall rules for local communication:

  • Access to NDPro – The following protocols/ports must be accessible for administration, visualization, and file access: SSH (22), HTTP (80), HTTPS (443), SMB (445).

  • Access from NDPro to end devices – Control operations require flexible communication paths depending on the manufacturer and protocol. Therefore, traffic originating from the NDPro controller to end devices should be permitted as ANY TCP/UDP + ICMP to ensure full functionality for all manufacturer-specific APIs, status updates, and protocol-based communication.

Limited Online-Access as an Option

Minimum requirements for updates, monitoring, and external services. Depending on the individual system configuration, outbound Internet connections may be required for the operation of NDPro. The following destinations represent the recommended minimum requirements. Services that are not required can be excluded from the customer’s firewall rules.

NDPro Services

  • update.ndpro.app
    Provision of NDPro software and system updates.

  • service.(provider).com
    Central NDPro services for monitoring, licensing, and certificate management.

NDPro Operating System and Software Updates

  • *.debian.org
    Debian package repositories and security updates, including security.debian.org.

  • *.nodesource.com
    Provision and updates of the Node.js runtime environment.

  • *.npmjs.org
    Node.js package management and updates of required npm components.

Remote Service

  • *.teamviewer.com
    Remote service via TeamViewer. Access should only be permitted through approved and appropriately secured company accounts.

DNS and Time Synchronization

  • 8.8.8.8 / 1.1.1.1
    External DNS resolution if no customer-provided DNS servers are available.

  • *.ntp.org
    NTP servers for system time synchronization if no customer-provided NTP servers are available.

Windows and Google Chrome

  • *.windowsupdate.com / *.microsoft.com
    Microsoft services for Windows operating system and security updates.

  • *.google.com / *.googleapis.com / *.gvt1.com
    Google services required for the operation and updating of Google Chrome.

Microsoft 365 / Graph API

  • login.microsoftonline.com
    Microsoft OAuth 2.0 authentication and token provisioning.

  • graph.microsoft.com
    Microsoft Graph API, for example for room calendars, room booking, email, and Microsoft 365 integrations.

Network Access

If DNS, NTP, or other infrastructure services are provided by the customer’s network, the corresponding external access permissions are not required.

Ports & Protocols

NDPro communicates directly with connected devices and systems using standard network protocols and manufacturer-specific interfaces. The following overview lists the outbound ports used by NDPro for device communication.

TCP/UDP Ports

Port

Protocol

Manufacturers

22

TCP/SSH

Various

23

TCP/Telnet

Various

45

TCP

Sennheiser

80

TCP/HTTP/WS

Various

100

TCP

Exsys

443

TCP/HTTPS/WSS

Various

445

TCP/HTTPS

Cisco

502

TCP/Modbus TCP

NDPro

587

TCP/SMTP

NDPro

1400

TCP/UPnP

Sonos

1515

TCP/MDC

Samsung

1710

TCP

Q-SYS

1986

TCP

Vestel, Toshiba

2202

TCP

Shure

3535

TCP/HTTP

ProDVX

3629

TCP/ESC/VP.net

Epson

4001

TCP

NDPro

4003

TCP

Barco

4352

TCP/PJLink

Panasonic, Sony

4660

TCP

BenQ

4664

TCP

Clevertouch

5000

TCP

Crestron, iiyama, Philips

5200

TCP

NovaStar

6107

TCP

Lightware

6688

TCP

i3

7078

TCP

P5 Automation

7142

TCP

NEC, Sharp

8001

TCP

NovaStar

8002

TCP/HTTPS/WSS

Samsung

8003

TCP

Cisco

8006

TCP/HTTPS

Proxmox

8080

TCP/HTTP

ZeeVee

8374

TCP

Fohhn

8890

TCP

Televic

9006 / 49160

TCP

Humax

9090

TCP

Barco

9990

TCP

Blackmagic Design

10008

TCP

Sharp

10600 / 10606

TCP

Analog Way

11000

TCP

Bluesound

27182

TCP

Sedna

49280

TCP

Yamaha

50000

TCP

Yamaha

50915

TCP

WolfVision

9

UDP/Wake-on-LAN

Various

161

UDP/SNMP

Various

3671

UDP/KNXnet/IP

Various

5000

UDP

BrightSign

6000

UDP

NovaStar

6454

UDP/Art-Net

Various

8600

UDP

Expromo

8711

UDP

Audac

9910

UDP

Blackmagic Design

47808

UDP/BACnet/IP

Various

52381

UDP/VISCA over IP

Aver