GCXONE · Platform
NXG Connect
Networking, VPN, TimeSync and Voice
Signal In. Signal Out.
NXG Connect is everything that gets signal into and out of a site: managed VPN connectivity between customer networks and the platform, the alarm transport that carries events to a monitoring centre, device clock synchronisation so every record sits on one timeline, and the SIP voice services that let an operator speak on site. It is a single component because these are one problem wearing four names.

Key capabilities
- Fully managed VPN — NXGEN designs, operates and monitors it; no customer system is exposed to the internet
- Four protocol options so the tunnel fits the customer infrastructure rather than the other way round
- Alarm transport to monitoring centres over SIA DC-09, plus a REST path for Evalink Talos
- Per-device timezone and clock synchronisation, with NTP handoff so devices stay aligned on their own
- SIP voice: operator talk-down, announcements, speaker zones and conference mode
Primary use cases
- Reaching recorders and cameras inside customer networks without opening them to the internet
- Remote troubleshooting, where an engineer needs the device rather than a screenshot of it
- Investigations and audits, where a few seconds of clock drift turns a review into a day of work
- Sites that need a voice response as well as a video one
Performance at a glance
99.95%
Uptime SLA
Under 70 ms
Typical tunnel latency
1 Gbps+
Throughput per tunnel
AES-256
Encryption standard
Primary protocol
OpenVPN
- SSL/TLS based, split tunnel to cut unnecessary backhaul
- Operator PC client access
- Flexible TCP or UDP port configuration
- Best for: remote access and multi-site connectivity
Primary protocol
IPsec
- High-performance site-to-site tunnelling
- Route-based and cloud site-to-site support, BGP or static
- Hardware-accelerated AES-256
- Best for: branch and on-premise integration
Also supported
WireGuard and Meraki
WireGuard is lightweight enough for performance-constrained edge devices; Meraki VPN integrates natively where the customer already runs Meraki.
- Best for: fitting the customer existing infrastructure
Architecture

Technical specifications
- Protocols
- OpenVPN and IPsec as the primary pair; WireGuard for constrained edge devices; Meraki VPN for Meraki-based deployments
- Encryption
- AES-256 across every supported technology, hardware-accelerated
- Uptime SLA
- 99.95% monthly
- Typical Latency
- Under 70 ms per tunnel, varying with site geography
- Throughput
- 1 Gbps and above per tunnel, protocol and infrastructure dependent
- Routing
- Static and BGP dynamic routing, split or full tunnel, with NAT for overlapping customer addressing
- Operator Access
- OpenVPN client accounts for authorised personnel, centrally controlled, with full access logs
- Onboarding
- Typically 2 to 5 business days; multi-site rollouts scoped individually
- DC-09
- SIA DC-09 over TCP to Amwin, Lisa, Immix or any compatible receiver, mapped per device by Account Number with an optional encryption key
- Evalink Talos
- REST integration authenticated with an API Key and Company ID, with no firewall configuration and no per-site mapping
- Event Link
- Each DC-09 signal carries a secure link opening pre-event footage, the live feed and the alarm context
- Model
- Timezone and synchronisation set per device, from that device own configuration panel, not as one tenant-wide switch
- NTP Handoff
- Dahua and Hikvision devices can hand off to NTP and keep their own clocks aligned afterwards with no further intervention
- Why It Matters
- Mismatched timestamps turn a straightforward multi-camera review into hours of reconciliation, and weaken the record when it is challenged
- Scale
- Operates across thousands of devices without performance impact
- SIP Audio
- Genesis Audio devices registered per site, providing two-way audio and announcements to SIP-enabled speakers from the video viewer
- Credentials
- Username, password and SIP domain issued per device and entered into the speaker own web client, transport TCP
- Capabilities
- Talk-down during alarms, speaker-zone configuration, alarm-triggered broadcast, pre-recorded messages, conference mode
- Prerequisites
- The Genesis Audio permission on the user role, and browser microphone permission. Local Mode is not required
- Ports
- 443 HTTPS client to cloud for the interface and API; 554 RTSP or 443 bidirectional for streams and WebRTC; 8000 or 80 device to cloud for HTTP event paths; DC-09 outbound to the alarm receiver
- IP Whitelisting
- CIDR ranges provided for secured corporate networks, which must be whitelisted before go-live for edge-bridge hardware
- Automatic Time Sync Coverage
- Automatic synchronisation is supported for Hikvision and Dahua devices only. Every other device carries a timezone set per device without the NTP handoff
- Managed, Not Self-Service
- The VPN is designed and operated by NXGEN. That is the value and also the boundary: changes go through the operations team rather than a customer console
- Reachability
- Everything here depends on the site having a working path out. A device behind a network that blocks the required ports will not reach the platform however it is configured
Managed VPN
Alarm transport
TimeSync
Voice and messaging
Network requirements
Governance & Limitations
Getting started
The VPN is deployed and operated by NXGEN end to end; TimeSync and audio are configured per device once the site is connected.
- 01Scope the networkTopology, site count and device requirements reviewed with the NXGEN team
- 02Open the pathWhitelist the provided CIDR ranges and confirm the required ports before go-live
- 03Build and test the tunnelsProtocols, routing, NAT and authentication configured, then latency, throughput and failover confirmed end to end
- 04Align and speakSet each device timezone and NTP handoff, and register the site speakers against their Genesis Audio credentials