psynegy Posted December 16, 2025 Posted December 16, 2025 We have a number of Paxton Net2 controllers, but are about to embark on replacing nearly 20 old standalone access controlled doors, so we want to make sure we're doing the right thing sticking with Net2. Net2 doesn't seem to have any prospect of becoming cloud hosted, the existence of Paxton10 confirms that. I fear that Net2 will become legacy once P10 reaches maturity. I know some people would prefer to keep things on-site - that's just not the direction we're heading at the moment. I also have serious reservations about the security of Net2's use of MiFare UIDs as a means of identification - we've already had ID collisions and a kid with a Flipper Zero is probably not going to need long to clone a staff card or fuzz their way through a door. Don't even get me started on how bad the PoE implementation seems to be on the Net2 controllers... I've been doing a bit of looking into the UniFi option - which whilst it relies on a "cloud gateway" - we'd have to have some sort of router on site anyway, it might as well do that too. If it means we can unify (ha-ha) our WiFi and network authentication too, that's a plus. It would also give staff the option to use other devices for opening doors, where Net2 (pre P10) does not support BLE. Cost wise, BroadbandBuyer puts a UniFi Mini Door hub at ~£85 and a reader at ~£83 (£100 for the newer model). Last I saw a Net2 PoE Controller and reader were £300 and £90 respectively... I believe the intercoms are circa 10x cheaper also, though do not look as "rugged" - as we've found with our Net2 intercoms - nothing is "vandal proof". I suspect we would find it hard to find an installer for Unifi, how necessary that is - I'm not sure. Interested to hear peoples thoughts and experiences with other products!
RobFuller Posted December 16, 2025 Posted December 16, 2025 I've certainly been questioning recently if net2 is worth continuing with new installations. I've had a couple of failures recently which has been expensive. Problem I face is we use our ID cards with multiple systems so using anything other than mifare is problematic. What's the workflow like for enrolling cards, can it pull these from other systems, sync or API?
Paxton Posted December 17, 2025 Posted December 17, 2025 Hi -psynegy very interesting points! To take each concern one at a time: - Net2 can be installed to a cloud hosted VM; I've seen this done many times successfully over the past decade. - many API integrations with ID management and MIS systems automate Net2 across MATs and independent Trusts in the UK and globally. - Net2 is not going anywhere, Paxton is investing and developing it daily. E.g.. a new version of the Net2 Plus was released in June this year which reduced faults and improved performance. - Paxton10 is not cloud hosted. Although there are deeper ties with cloud for sure. - Net2 does support BLE readers and most any technology via third party reader integration. - Mifare UID is the defacto standard for access control across the Education sector as with many sectors because of simplicity and cost. If you are worried by this there are many ways to defeat cloning from: Reader 2FA, to software features such as anti pass-back, to encrypted tokens and readers in the Net2 system e.g. HID SEOS with native dual credential support native to Net2. - the issue of cloning is not borne out by evidence at all. If anything, the database or lack of any security culture would the best way to enter a site. After all, people take the easiest route provided to them. Lot's of doors are still held open for people or by extinguishers for example. - cost is an issue if you do not see the value in the product or service provided. That would be something I'd gladly discuss to understand more. I really hope this helps and if you wish to discuss you can book a meeting with me or email me on the following: [email protected] Book time with Anthony Searle: Introduction/Catch up
johnpd Posted December 17, 2025 Posted December 17, 2025 What’s net2 plus compared to just net2? I suspect looking at alternatives to Paxton is going to only increase as schools and trust go fully cloud and don’t want to host the server in azure at their cost. Many would appreciate an OpEx cloud hosted model subscription with cheaper hardware implementation.
Paxton Posted December 17, 2025 Posted December 17, 2025 Net2 Plus Controller - https://www.paxton-access.com/products/net2-plus-1-door-controller/ There are OpEx cloud hosted solutions for Net2 via solution providers. Many still don't want to rely on cloud or have access control in the cloud due to security or lagging concerns. The recent AWS and Azure outages are a good case in point. Still the march to a useful cloud solution is undeniable and being solved by Paxton. 1
Simcfc73 Posted December 17, 2025 Posted December 17, 2025 I'm going to be looking at putting Net2 in the cloud in the summer but would like a cloud solution also that's not just an azure blob. I had Unifi at the previous place but the lack of support and installers would steer me away from them at present. Shame as the ecosystem they have produced is amazing and I miss my controller (currently on Aruba) 1
psynegy Posted December 19, 2025 Author Posted December 19, 2025 Thank you for responding Anthony, it's very much appreciated. On 17/12/2025 at 06:43, Paxton said: - Net2 can be installed to a cloud hosted VM; I've seen this done many times successfully over the past decade. Yes, we've been told this, but have also been told that it's not supported by Paxton and can cause issues with detecting new hardware. Running a Windows VM in Azure also has fairly significant overhead and therefore cost associated with it. According to your Net2 compatibility table, it looks like it's not recommended for any users to be using a higher version than 6.7 SR3? For Server 2022 you only recommended to use 6.6 SR1 (3+ years old), but Windows 8.1 should use 6.7 SR3?? No support for Server 2025 at all? It's been out for over a year now... On 17/12/2025 at 06:43, Paxton said: - many API integrations with ID management and MIS systems automate Net2 across MATs and independent Trusts in the UK and globally. Yes, that's very useful indeed, and we use the API ourselves to achieve things that are not built into the product. API access would be a key feature of any system we would look to implement. On 17/12/2025 at 06:43, Paxton said: - Net2 is not going anywhere, Paxton is investing and developing it daily. E.g.. a new version of the Net2 Plus was released in June this year which reduced faults and improved performance. Personally, I don't agree that the most recent update being 6 months ago lends any credence to the software being updated regularly... Similarly, I reported a bug in 2023 which was acknowledged, and despite multiple (ignored) follow up emails, the bug is still present today. On 17/12/2025 at 06:43, Paxton said: - Paxton10 is not cloud hosted. Although there are deeper ties with cloud for sure. To be honest, we didn't really see what the purpose of Paxton10 was as a product. I think when we started with Net2, P10 was still quite limited, I'm sure it's probably come a long way since, but it didn't make sense to us. I think it's caused a lot of people concern that all their Net2 gear is going to become obsolete, especially with no (apparent) upgrade path from one to the other. On 17/12/2025 at 06:43, Paxton said: - Net2 does support BLE readers and most any technology via third party reader integration. Honestly, if you we were going to replace each reader with a third party solution that we'd have to manage separately - replacing the access control unit at the same time (so at least it's all in one system) makes more sense to me. I also imagine the BLE device would still just be stored with an 8 digit number in the database? On 17/12/2025 at 06:43, Paxton said: - Mifare UID is the defacto standard for access control across the Education sector as with many sectors because of simplicity and cost. If you are worried by this there are many ways to defeat cloning from: Reader 2FA, to software features such as anti pass-back, to encrypted tokens and readers in the Net2 system e.g. HID SEOS with native dual credential support native to Net2. So was asbestos and RAAC - now look where we are! Reader 2FA isn't what I would call a solution at all... Slow, cumbersome, requires reader replacements, more for users to remember... Anti pass-back isn't helpful here either unless the person's card they've cloned happens to be walking in behind them, and also adds reliance on server availability. HID SEOS requires replacing all readers and cards, and even then doesn't work with your intercoms/handles without falling back to UID. What's also really concerning is that there doesn't seem to be any rate limiting on the controllers or readers for trying new cards... I was easily able to emulate 3x cards per second on a P50 reader for several minutes... Granted, that's still around 9 hours if you assume 1000 tokens in the database giving you a 1 in 10k chance per random UID, but I bet with some refinement (like UID generation based on known cards, or attacking multiple readers at once, or possibly just speeding up the rate of attempts), that could be made quicker. "but no student is going to try this" - well, I'm here to tell you they will, and they have, and we've seen it. Being able to apply a rate limit would improve the situation immensely. Net2 encrypted tokens (Hitag2) would certainly also be an improvement, but they too will likely be as easy to clone in a year or two as Mifare is today. How to copy, read and write Paxton fobs and cards with an RFIDler | Badcfe.org - Some info on Paxton RFID tags Question - when using the Hitag2 tokens - can you prevent Mifare or EM tokens from being read? If not, the system is still just as vulnerable to brute forcing. Couldn't see an option for this - only HID+Wiegand activation seems to block them, but that also blocks the Paxton Hitag2 tokens... On 17/12/2025 at 06:43, Paxton said: - the issue of cloning is not borne out by evidence at all. If anything, the database or lack of any security culture would the best way to enter a site. After all, people take the easiest route provided to them. Lot's of doors are still held open for people or by extinguishers for example. It could not be easier to clone a MiFare UID. A student with a Flipper Zero in their pocket can do this in seconds. I agree that there are other issues with security, and we take those seriously too, we have alarms that sound when a door is propped open too long for example, but just saying 'there are other holes' in a sinking ship doesn't mean we shouldn't try and block up any of the holes... Granted, no access control system is going to fix security culture - but it could fix this problem. On 17/12/2025 at 06:43, Paxton said: - cost is an issue if you do not see the value in the product or service provided. That would be something I'd gladly discuss to understand more. It's not even just that the cost is high - it's how hard is is to get hold of the equipment. Most, if not all of the official resellers won't deal with end users, and if we do manage to buy the kit from a "naughty" reseller, then Paxton says "no warranty for you!". Going through this reseller model also means the idea of any education discount tends to go out the window. I assume the free training (and therefore warranty entitlement) doesn't extend to school IT staff based on the "specifically for installation engineers" and for on-site training: "Training is offered to professional security installation companies currently, or wishing to begin, providing Paxton equipment or services as part of their portfolio." terms, but I'd be very happy to be told otherwise! 1
pipsyp Posted January 16 Posted January 16 I have a little form with this. I'm not a door access installer as such, but have had reasonable exposure to various platforms through my MSP work which might help you. Paxton - I still feel overall that Net2 Pro is the best overall solution. I think its too costly, and Paxton have rather rested on their laurels where the software side of its concerned (its literally been the same for years, warts and all), but the hardware tends to be very reliable and once its in and working (and built out right from a software perspective) it does the job, and broadly better than most other things. Paxton 10 - For years even Paxton put customers off buying this in place of Net2 Pro (i've been well informed by various Paxton accredited installers) as it simply was not as good or capable. I gather there is far more feature parity now though, however its even more costly than Net2 Pro. If you've got the funds, probably the way to go, if not....well goes without saying! UniFi Protect - Functionality wise the door access stuff is really rather amazing for the money. Ive had no real experience of it, but my long running experience of UniFi is that dependability is not its strong suit (over the years I've seen firmware upgrade break more things than they've fixed) and as much as I hate to say it, like much of their hardware its all rather form over function. They are rather the Apple of the network infrastructure world, but without the overall polish. As a company they continue to grow exponentially, and it does look as though they are finally placing a lot of energy and focus into better enterprise end user support (it used to be woeful) Hikvision Door Access with HikCentral Pro software - I've recently assisted a customer with getting this deployed (from a software and configuration standpoint), to displace a very troublesome Videx system. It is rather new to market, a bit buggy, but fundamentally does the job and at far less cost than Paxton (though probably more expensive overall than UniFi). Gives the opportunity to bring together and manage Hik CCTV systems as well, so a positive if you do have Hik CCTV. Support is a bit average (their people don't know the current release well enough to support it properly) but given how big Hik are, I am sure they'll get a handle on it. Not to offend the Paxton rep that's also posted, but play their cards right, Hik could take alot of business way from Paxton with their offering. Of the options above, I'd go Paxton 10 as the dream, Net2 Pro if Paxton 10 cant be attained, then HikCentral Pro as the "will do the job" fallback.
pipsyp Posted January 16 Posted January 16 (edited) ...and yes....I agree with the sentiment that Paxton 10 being hardware silo'd is a bit naughty, given how much investment people have made in Paxton Net2's ecosystem already. Missing a trick IMHO not building in Paxton 10 compatibility for Net2 Plus ACU's etc; particularly if they hope to retain market share against the likes of HikVision. That said, in Paxton's defence, there are possibly hardware limitations that prevent them doing this. Edited January 16 by pipsyp 1
synaesthesia Posted January 16 Posted January 16 I would be surprised if anyone is brave/daft enough to go down the Hik route. As much as I love their hardware generally, software is poor and there's still always that big question mark hanging over the company as a whole. Yeah I imagine you can annex it off like you can their CCTV, but that's still a big commitment. And if it goes wrong - what's the level of support like with the installers and partners we use? 2
pipsyp Posted January 18 Posted January 18 On 16/01/2026 at 11:50, synaesthesia said: I would be surprised if anyone is brave/daft enough to go down the Hik route. As much as I love their hardware generally, software is poor and there's still always that big question mark hanging over the company as a whole. Yeah I imagine you can annex it off like you can their CCTV, but that's still a big commitment. And if it goes wrong - what's the level of support like with the installers and partners we use? Yeah I get the connotations of using Hik products - partly state financed and being called out on some things ethically, but as a bang per buck solution, there isn't much of anything out there (that I've seen so far) that comes close. HikCentral is still relatively new, so for sure does have it's quirks and bugs, but none more so than most of its peers I would say. Leaps and bounds on from iVMS as well (from what I've seen of it). For a school needing a scalable door access solution at reasonable cost, particularly if they have Hik CCTV already (as it can integrate - and you'd hope a Hik accredited partner already supporting that) I honestly think you could do alot worse.
Homer Posted January 18 Posted January 18 We're actively pondering Unifi for one of the primaries we have who are currently on some antiquated, unsupported and possibly unusable access control system that also are in need of a new solution for their gate. CCTV is also up for refresh, so we're going to use the incoming Unifi Enterprise NVR at my site as a yard stick for that (looking very positive) and then see about how access control works with it too as their NVRs do doors and CCTV. We're going to re-use the hik cameras but begin phased replacement of the older ones with Unifi ones to get max benefit. 1
pipsyp Posted January 19 Posted January 19 13 hours ago, Homer said: We're actively pondering Unifi for one of the primaries we have who are currently on some antiquated, unsupported and possibly unusable access control system that also are in need of a new solution for their gate. CCTV is also up for refresh, so we're going to use the incoming Unifi Enterprise NVR at my site as a yard stick for that (looking very positive) and then see about how access control works with it too as their NVRs do doors and CCTV. We're going to re-use the hik cameras but begin phased replacement of the older ones with Unifi ones to get max benefit. Ubiquiti are really innovating here, but would still be a little concerned about software bugs and end user support, though I get the impression they have listened and have largely ironed out their software QA and placing significant efforts into providing better end user support. Like them or hate them, Hik have significant legs on Ubiquiti in the CCTV space.....broadly speaking if you want a CCTV service you can rely upon, and have someone responsible for installing and maintaining it, its arguably still one of the better choices. UniFi is still very much on the DIY spectrum, though horses for courses....as a school if you wanted to do it end-to-end then its ideal. I've heard that Verkada are excellent, though the cost is significant. A school I work wit were interested in their solution, but they did not want to talk cost until you've committed to buying some demo equipment and had undertaken a trial which I found a little odd in terms of sales practice. Needless to say they didn't get the business.
Paxton Posted January 23 Posted January 23 On 17/12/2025 at 08:27, Simcfc73 said: I'm going to be looking at putting Net2 in the cloud in the summer but would like a cloud solution also that's not just an azure blob. I had Unifi at the previous place but the lack of support and installers would steer me away from them at present. Shame as the ecosystem they have produced is amazing and I miss my controller (currently on Aruba) I have experience with the Net2 in the cloud as do partners of ours who offer integrations with MIS etc. Do get in touch if you want assistance.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: es, we've been told this, but have also been told that it's not supported by Paxton and can cause issues with detecting new hardware. Running a Windows VM in Azure also has fairly significant overhead and therefore cost associated with it. According to your Net2 compatibility table, it looks like it's not recommended for any users to be using a higher version than 6.7 SR3? For Server 2022 you only recommended to use 6.6 SR1 (3+ years old), but Windows 8.1 should use 6.7 SR3?? No support for Server 2025 at all? It's been out for over a year now... This is not the case. What Paxton Support say's is VMs do of course work however should there be protracted issues it may mean testing on a physical machine may be needed. In my experience this scenario rarely happens. What really matters is close alignment between all parties as to what and how. The compatibility table is a guide, specific versions of Net2 and OS is the message. Reality is keep Net2 up to date and all will be well with OS. On 2025, the next release of Net2 is due by end of Q1 2026 which includes support. It has been a busy year for Net2 dev.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: On 19/12/2025 at 17:08, psynegy said: Personally, I don't agree that the most recent update being 6 months ago lends any credence to the software being updated regularly... Similarly, I reported a bug in 2023 which was acknowledged, and despite multiple (ignored) follow up emails, the bug is still present today. Apologies for some confusion here. I gave an example. Net2 products across the board have seen updates in 2025 released including firmware, and software. More to come in 2026 and beyond.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: Honestly, if you we were going to replace each reader with a third party solution that we'd have to manage separately - replacing the access control unit at the same time (so at least it's all in one system) makes more sense to me. I also imagine the BLE device would still just be stored with an 8 digit number in the database? That's a fair point. You can update to Paxton10 very easily with your suggested method in that case. However, seamless integration with API methods between third party readers and BLE tokens make the management simple in Net2 also.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: So was asbestos and RAAC - now look where we are! Reader 2FA isn't what I would call a solution at all... Slow, cumbersome, requires reader replacements, more for users to remember... Anti pass-back isn't helpful here either unless the person's card they've cloned happens to be walking in behind them, and also adds reliance on server availability. HID SEOS requires replacing all readers and cards, and even then doesn't work with your intercoms/handles without falling back to UID. What's also really concerning is that there doesn't seem to be any rate limiting on the controllers or readers for trying new cards... I was easily able to emulate 3x cards per second on a P50 reader for several minutes... Granted, that's still around 9 hours if you assume 1000 tokens in the database giving you a 1 in 10k chance per random UID, but I bet with some refinement (like UID generation based on known cards, or attacking multiple readers at once, or possibly just speeding up the rate of attempts), that could be made quicker. "but no student is going to try this" - well, I'm here to tell you they will, and they have, and we've seen it. Being able to apply a rate limit would improve the situation immensely. Net2 encrypted tokens (Hitag2) would certainly also be an improvement, but they too will likely be as easy to clone in a year or two as Mifare is today. How to copy, read and write Paxton fobs and cards with an RFIDler | Badcfe.org - Some info on Paxton RFID tags Question - when using the Hitag2 tokens - can you prevent Mifare or EM tokens from being read? If not, the system is still just as vulnerable to brute forcing. Couldn't see an option for this - only HID+Wiegand activation seems to block them, but that also blocks the Paxton Hitag2 tokens... All very good points to raise and questions to consider. I am interested in your thinking here, happy to have a conversation about it. Stepping back. There are many ways to access a building if you really want to, these issues you raise around token and reader security are valid. However, in my experience, its a risk conversation. I would advocate a conversation specific to a site as it would be unwise for me to comment further casting all sites into the same bracket of need.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: It could not be easier to clone a MiFare UID. A student with a Flipper Zero in their pocket can do this in seconds. I agree that there are other issues with security, and we take those seriously too, we have alarms that sound when a door is propped open too long for example, but just saying 'there are other holes' in a sinking ship doesn't mean we shouldn't try and block up any of the holes... Granted, no access control system is going to fix security culture - but it could fix this problem. I understand your points and again thank you for the opinion. If card cloning is an issue or a risk then there are solutions we can deploy in current systems to combat this. All are effective. However, it takes but a second to waltz through an open door.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: It's not even just that the cost is high - it's how hard is is to get hold of the equipment. Most, if not all of the official resellers won't deal with end users, and if we do manage to buy the kit from a "naughty" reseller, then Paxton says "no warranty for you!". Going through this reseller model also means the idea of any education discount tends to go out the window. I assume the free training (and therefore warranty entitlement) doesn't extend to school IT staff based on the "specifically for installation engineers" and for on-site training: "Training is offered to professional security installation companies currently, or wishing to begin, providing Paxton equipment or services as part of their portfolio." terms, but I'd be very happy to be told otherwise! Yeah, I definitely feel it's worth a Teams call. To be clear Paxton sells only to Trade. However, training is delivered to schools directly. We always want to work with your contractors because this ensures you get the best levels of service and support. However, site meetings, health checks, user academies and more, are delivered direct with or with a contractor present. Many contractors embrace a knowledgeable client team as it helps them cut out unnecessary fault call outs and out of contract charges.
Paxton Posted January 23 Posted January 23 On 19/12/2025 at 17:08, psynegy said: To be honest, we didn't really see what the purpose of Paxton10 was as a product. I think when we started with Net2, P10 was still quite limited, I'm sure it's probably come a long way since, but it didn't make sense to us. I think it's caused a lot of people concern that all their Net2 gear is going to become obsolete, especially with no (apparent) upgrade path from one to the other. Appreciate your feedback. We can't please everyone When did you see Paxton10 last? In experience, picking the tool for the job is always best. We don't sell you anything you don't need or isn't going to solve your problems. To end, Paxton10 today is selling well and proving it's worth to a great many schools and many other sectors. https://www.paxton-access.com/install-paxton/resources/case-studies/
Paxton Posted January 23 Posted January 23 On 16/01/2026 at 10:09, pipsyp said: ...and yes....I agree with the sentiment that Paxton 10 being hardware silo'd is a bit naughty, given how much investment people have made in Paxton Net2's ecosystem already. Missing a trick IMHO not building in Paxton 10 compatibility for Net2 Plus ACU's etc; particularly if they hope to retain market share against the likes of HikVision. That said, in Paxton's defence, there are possibly hardware limitations that prevent them doing this. This is a fair point which often raised. The decision to move to Paxton10 from Net2 is based on needs and requirements. And yes, the Paxton10 hardware is very much different as is the software hence why they don't mix. However, thank you for the feedback rest assured this gets fed back to the product teams. 1
Paxton Posted January 23 Posted January 23 On 18/01/2026 at 19:23, Homer said: We're actively pondering Unifi for one of the primaries we have who are currently on some antiquated, unsupported and possibly unusable access control system that also are in need of a new solution for their gate. CCTV is also up for refresh, so we're going to use the incoming Unifi Enterprise NVR at my site as a yard stick for that (looking very positive) and then see about how access control works with it too as their NVRs do doors and CCTV. We're going to re-use the hik cameras but begin phased replacement of the older ones with Unifi ones to get max benefit. If you would like a visit to let you know how Paxton can solve your problems, please do let me know. Always nice to meet new people.
Paxton Posted January 23 Posted January 23 On 16/12/2025 at 19:03, RobFuller said: I've certainly been questioning recently if net2 is worth continuing with new installations. I've had a couple of failures recently which has been expensive. Problem I face is we use our ID cards with multiple systems so using anything other than mifare is problematic. What's the workflow like for enrolling cards, can it pull these from other systems, sync or API? Yes, API integration is possible with excellent solutions. We could have a Teams call to discuss?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now