Jump to content

Recommended Posts

Posted

Hi all

 

Investigating the world of Paxton Net2. Is the system worth it? When I search for it there seems to be a lot of unhappiness and workarounds for it. Are there any decent competitors?

 

What's the cheapest way to do the cards/fobs? We would need 150. They seem to cost £3-£4 a card? is that correct?

 

We currently don't have any sort of card based entry system. All we have close to it is Inventry.

Posted

We use Mifare Classic 1k cards which are about 50p each, and wristbands which are closer to £1.50.

 

It's alright. Locally hosted. The controllers bug out sometimes and need a restart, the main software has bugs which cause it to crash, and some settings (like IPv4 on the intercom units, and DHCP on the controllers) will cause chaos.

 

I like the Salamander integration (our new users just appear!)

  • Like 2
Posted (edited)

£3-4 a card is extortionate, depending on what you are getting.  We pay less than 50p generally, for MiFare 1k cards, which are then generally compatible with other systems.

Paxton is OK, makes sense.  Generally the issues I've had are VLANs or the hardware just having a bit of a fit.  The issue I've found is that the system just hasn't moved on in 10 years and their new Paxton10 apparently is still getting needed features added.  The interface is a bit clunky, but you can get it to do what you want and do some smart things.

 

EDIT:  Also be sure that any installer is following the latest standards.  I can't remember what it is that was updated, but throwing a mag lock and a break glass on a door isn't compliant anymore especially if the door is an escape route.

 

Net-Ctrl did a good video with Abloy - https://www.youtube.com/watch?v=7gpLiplEz1M or if you really like the details there is a longer one that goes into everything - https://www.youtube.com/watch?v=cE3iOsNKnXo

Edited by TechMonkey
  • Like 2
Posted

Be aware of the security weakness of MiFare 1k cards. The encryption on these has been broken and they are vulnerable.

DESFire is considered secure, but the cards are more expensive.

  • Like 2
  • Thanks 1
Posted

There are different readers available, make sure you get the more universal ones that let you use the cheap mifare ID cards.
They work with Net2 software just the same, you just don't have to buy the paxton-own fobs.

 

Wrong: Paxton Fob 695-644 Net2 Proximity keyfobs Box, one Color, 10 Count (Pack of 1) : Amazon.co.uk: DIY & Tools

 

Right: HERNAS 100pcs Rewritable UID Smart Cards, Mi-Fare 1K S50 RFID Cards, White, 13.56MHz PVC Blank Cards for Access Control System, Block 0 Sector, Comply ISO 14443A : Amazon.co.uk: DIY & Tools

 

It's pretty reliable, I don't have to mess with it often, a couple of doors might have a wobble and need restarting after a power cut but generally solid.

 

We also have a Paxton entry which video calls reception through 3CX, and then unlocks a gate when reception press 1.

 

  • Like 1
  • 1 month later...
Posted

Paxton if installed correctly just works.

NB: Although i work for a school i own my own company doing Security/AV/IT and Paxton is all we install for schools.

 

as mentioned above, you will also need to think about getting fire relays for your escape routes as relying on the software alone is not regs.

  • Like 1
Posted

Obviously the hardware is terrible and overpriced, crashes if it gets a malformed packet, and the software is just as bad (had to rollback the VM the other day, and afaik there's no way to move a fob from one user to another), but it's building management stuff, it's all like that

Posted (edited)

Its generally pretty solid and their support team are pretty good.

Works well with our cashless catering system that manages the cards and imports them into net2 via the net2 API. We also have Live Register integration for AM roll call.

 

It has its quirks but usually during upgrades. I have 14 years experience with Net2 and its only really had issues during upgrades or the odd power cut on the odd door here or there.

My advice if you go with it manage your IP addresses through DHCP and assigned them before your turn them on for the 1st time. 

 

Installers also like to cut corners make sure they install the backup battery on critical doors.

Also Mav only found out about the issue he was having with malformed packets due to him doing a security scan on them so just exclude the doors from any such system.

 

Edited by gaz350b
  • Like 1
Posted

If your starting from scratch, I'd probably go with the Paxton 10 as that seems to get the new features.

 

Unifi have a solution that looks good, but I don't know of anyone who has gone with it.

 

Its worth looking at other systems like copiers or cashless catering to see if you can share the cards with that system.

 

Blank mifare cards should be under £1, but if you outsource the printing then it could get more expensive. Its worth it if you have the time and are doing a load of them.

 

Mifare cards can be cloned, so if you require higher levels of security, I'd probably go for one of the more expensive options. Even then, there are ways to get the card ID and replay it. I'd make sure all the doors and readers are covered by a good camera, and be on top of checking out of hours access.

 

The issue with malformed packets and the door controllers should be fixed in a recent release. I think they called it a 'COP reset', but there's not much about the bug online other than a couple of videos. It can potentially be used to unlock doors.

 

The ACUs should be on an isolated VLAN to protect against that and other issues.

  • Like 1
Posted

Also every controller in the world has the same hard coded password, the hash is available in the linux image in the firmware upgrade file

  • Haha 1
Posted (edited)

Worth remembering that these are not designed to foil serious attempts at entry, just like manual key pads, combination locks, padlocks etc. Deterrent, basic access controls only and shouldn't be used for main security access such as front doors, access gates etc :D

 

Likewise, have used them for years, installed a few myself, they just work. Not sure about the expensive side of things, generally they always appear vastly cheaper than most other systems and importantly are well supported - important if you need someone else to come look at them! Never had any issues, install batteries on all of ours (for the sake of an extra tenner per door, no brainer). One of the few things that despite being old fashioned, just works.

Edited by synaesthesia
  • Like 1
  • 4 weeks later...
  • 2 weeks later...
Posted

look at your use case.  We use .NET2 as a simple entry system and as a control to the lifts.  It is NOT used as a primary security feature in our school.  The classrooms and doors are closed at certain times, lifts are only used by those with passes, year groups can open certain doors and other year groups cannot.  This is purely as an operational setup (obviously person with card A can open and wedge a door etc).  The fire alarm is built in to the system too.   We use MIFARE cheap cards, these double up with papercut and inventry.  All syncd from 365.  Issues?  None really, other than the cost of the .NET2 hardware it pretty much works.  Reboot the controller occasionally, but im talking once or twice a year - we only figure this out when a new issue card hasnt propagated fully.  We find the lanyards and card holders to be the weak link in the system rather than the cards themselves.

  • Like 2
Posted
On 24/09/2025 at 11:38, FN-GM said:

Be aware of the security weakness of MiFare 1k cards. The encryption on these has been broken and they are vulnerable.

Maybe I'm being dense, but what does this actually mean? When I've used Mifare with either Vanderbilt ACT or paxton, the only data on the card is the default 10 (I think) digit number which any reader would always have been able to pick up, and association with people is server-side.

  • Like 1
Posted (edited)
On 15/12/2025 at 20:25, Rob_D said:

Maybe I'm being dense, but what does this actually mean? When I've used Mifare with either Vanderbilt ACT or paxton, the only data on the card is the default 10 (I think) digit number which any reader would always have been able to pick up, and association with people is server-side.

 

It means if someone has the card, they can read the data on this and write it to another or use a repeater device (like a flipper zero) to replay the data to open doors. If you use a secure card that is encrypted they can't do that so they can't just clone the card. 

 

EDIT: This is a good demonstration: 

 

Edited by FN-GM
  • Thanks 1
Posted

Geovison is an alternative to Paxton both have differing cons and pros. While I do prefer using Geovison its far from perfect and has just as many cons as Paxton. One of which is the card designer for Geovision is useless to the point I do not even bother with it. I wouldn't say Paxtons card designer is great but it functions and does the job.

  • Like 1
  • 1 month later...
Posted

We loved net2 and found the paxton support team to be great.

A word of caution though, we did have one disastrous day where the door controller for the site team's office decided to stop letting anyone in at all. Unfortunately the breakers for distribution to each floor, and each area (including the one powering the door controller & maglock) were inside that office. The only PC on the management network was also inside that office (not that it would have helped, it stopped responding even to pings). We ended up having to kill the main incoming supply to the entire building, and then wait four and a bit hours (with no power) for the units battery backup to die. This was, of course, the day the DfE came to see the shiny new school they had built.

 

We VERY quickly moved the controller to a VM, put the system on our own network, reconfigured the IP addressing and wired up keyed external override to that office... And sacked the contractors off.

 

Since taking control over and doing it properly we had no issues at all, and we loved the system!

  • Like 1
Posted

We use Paxton Net2 ACU with Suprema Biometric readers (30+ doors). 
1600+ users with biometric

We also have some users with cards.

This setup has been working fine for last 10+ years.

  • Like 1
Posted
10 hours ago, cwade said:

We loved net2 and found the paxton support team to be great.

A word of caution though, we did have one disastrous day where the door controller for the site team's office decided to stop letting anyone in at all. Unfortunately the breakers for distribution to each floor, and each area (including the one powering the door controller & maglock) were inside that office. The only PC on the management network was also inside that office (not that it would have helped, it stopped responding even to pings). We ended up having to kill the main incoming supply to the entire building, and then wait four and a bit hours (with no power) for the units battery backup to die. This was, of course, the day the DfE came to see the shiny new school they had built.

 

We VERY quickly moved the controller to a VM, put the system on our own network, reconfigured the IP addressing and wired up keyed external override to that office... And sacked the contractors off.

 

Since taking control over and doing it properly we had no issues at all, and we loved the system!

Thanks for the feedback. If there's something you need from me please get in touch.

Posted
On 16/12/2025 at 10:51, Pottsey said:

Geovison is an alternative to Paxton both have differing cons and pros. While I do prefer using Geovison its far from perfect and has just as many cons as Paxton. One of which is the card designer for Geovision is useless to the point I do not even bother with it. I wouldn't say Paxtons card designer is great but it functions and does the job.

Thanks for the feedback. There are plenty of third party ID card management systems that API into Net2 also.

Posted
On 15/12/2025 at 09:55, Rob_D said:

Maybe I'm being dense, but what does this actually mean? When I've used Mifare with either Vanderbilt ACT or paxton, the only data on the card is the default 10 (I think) digit number which any reader would always have been able to pick up, and association with people is server-side.

There are two token numbers on a Mifare credential; encrypted sectors and unique ID serial. In the main 99% of access control uses the serial number.  This is the number which can of course be copied.  It is also possible to crack Mifare encryptions to access the sector information.
Depending on the site, needs, risks etc it is up to the system owner which approach to take with credentials. My experience of 25 yrs shows that the serial number approach is flexible enough to cater to most needs.  

Combatting any mischief such as cloning is also simple and straightforward.  I can explain on a quick Teams should you wish to understand more.

  • Like 1
Posted
On 24/09/2025 at 11:31, TechMonkey said:

£3-4 a card is extortionate, depending on what you are getting.  We pay less than 50p generally, for MiFare 1k cards, which are then generally compatible with other systems.

Paxton is OK, makes sense.  Generally the issues I've had are VLANs or the hardware just having a bit of a fit.  The issue I've found is that the system just hasn't moved on in 10 years and their new Paxton10 apparently is still getting needed features added.  The interface is a bit clunky, but you can get it to do what you want and do some smart things.

 

EDIT:  Also be sure that any installer is following the latest standards.  I can't remember what it is that was updated, but throwing a mag lock and a break glass on a door isn't compliant anymore especially if the door is an escape route.

 

Net-Ctrl did a good video with Abloy - https://www.youtube.com/watch?v=7gpLiplEz1M or if you really like the details there is a longer one that goes into everything - https://www.youtube.com/watch?v=cE3iOsNKnXo

What would you like to see from Paxton in terms of the system moving forward?

Posted
11 hours ago, cwade said:

We loved net2 and found the paxton support team to be great.

A word of caution though, we did have one disastrous day where the door controller for the site team's office decided to stop letting anyone in at all. Unfortunately the breakers for distribution to each floor, and each area (including the one powering the door controller & maglock) were inside that office. The only PC on the management network was also inside that office (not that it would have helped, it stopped responding even to pings). We ended up having to kill the main incoming supply to the entire building, and then wait four and a bit hours (with no power) for the units battery backup to die. This was, of course, the day the DfE came to see the shiny new school they had built.

 

We VERY quickly moved the controller to a VM, put the system on our own network, reconfigured the IP addressing and wired up keyed external override to that office... And sacked the contractors off.

 

Since taking control over and doing it properly we had no issues at all, and we loved the system!

 

 

 

I tell site staff they could set the fire alarm off briefly if there is ever a controller failure to release the doors if they can't get access (although never happened yet touch wood).

 

Are your controllers not wired through relays to release them?

 

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...