GCXONEDocumentation
All datasheets

GCXONE · Platform

NXG Connect

Networking, VPN, TimeSync and Voice

Signal In. Signal Out.

NXG Connect is everything that gets signal into and out of a site: managed VPN connectivity between customer networks and the platform, the alarm transport that carries events to a monitoring centre, device clock synchronisation so every record sits on one timeline, and the SIP voice services that let an operator speak on site. It is a single component because these are one problem wearing four names.

Datasheet · v1.0 · verified 15 September 2026

DatasheetSecure connectivity, time synchronisation and voice services for GCX One

How NXG Connect works. Step 1, Tunnel: Managed VPN — OpenVPN, IPsec, WireGuard or Meraki. Step 2, Align: Timezone per device; NTP handoff on Dahua and Hikvision. Step 3, Transmit: SIA DC-09 or Talos REST to the monitoring centre. Step 4, Speak: SIP talk-down, zones, broadcast, conference mode.

Key capabilities

  • Fully managed VPN — NXGEN designs, operates and monitors it; no customer system is exposed to the internet
  • Four protocol options so the tunnel fits the customer infrastructure rather than the other way round
  • Alarm transport to monitoring centres over SIA DC-09, plus a REST path for Evalink Talos
  • Per-device timezone and clock synchronisation, with NTP handoff so devices stay aligned on their own
  • SIP voice: operator talk-down, announcements, speaker zones and conference mode

Primary use cases

  • Reaching recorders and cameras inside customer networks without opening them to the internet
  • Remote troubleshooting, where an engineer needs the device rather than a screenshot of it
  • Investigations and audits, where a few seconds of clock drift turns a review into a day of work
  • Sites that need a voice response as well as a video one

Performance at a glance

99.95%

Uptime SLA

Under 70 ms

Typical tunnel latency

1 Gbps+

Throughput per tunnel

AES-256

Encryption standard

Primary protocol

OpenVPN

  • SSL/TLS based, split tunnel to cut unnecessary backhaul
  • Operator PC client access
  • Flexible TCP or UDP port configuration
  • Best for: remote access and multi-site connectivity

Primary protocol

IPsec

  • High-performance site-to-site tunnelling
  • Route-based and cloud site-to-site support, BGP or static
  • Hardware-accelerated AES-256
  • Best for: branch and on-premise integration

Also supported

WireGuard and Meraki

WireGuard is lightweight enough for performance-constrained edge devices; Meraki VPN integrates natively where the customer already runs Meraki.

  • Best for: fitting the customer existing infrastructure

Architecture

Signal in, signal out. NXG Connect connects Customer network, Site routers, SIP speakers to GCX One, Monitoring centre, Authorised operators.

Technical specifications

Managed VPN

Protocols
OpenVPN and IPsec as the primary pair; WireGuard for constrained edge devices; Meraki VPN for Meraki-based deployments
Encryption
AES-256 across every supported technology, hardware-accelerated
Uptime SLA
99.95% monthly
Typical Latency
Under 70 ms per tunnel, varying with site geography
Throughput
1 Gbps and above per tunnel, protocol and infrastructure dependent
Routing
Static and BGP dynamic routing, split or full tunnel, with NAT for overlapping customer addressing
Operator Access
OpenVPN client accounts for authorised personnel, centrally controlled, with full access logs
Onboarding
Typically 2 to 5 business days; multi-site rollouts scoped individually

Alarm transport

DC-09
SIA DC-09 over TCP to Amwin, Lisa, Immix or any compatible receiver, mapped per device by Account Number with an optional encryption key
Evalink Talos
REST integration authenticated with an API Key and Company ID, with no firewall configuration and no per-site mapping
Event Link
Each DC-09 signal carries a secure link opening pre-event footage, the live feed and the alarm context

TimeSync

Model
Timezone and synchronisation set per device, from that device own configuration panel, not as one tenant-wide switch
NTP Handoff
Dahua and Hikvision devices can hand off to NTP and keep their own clocks aligned afterwards with no further intervention
Why It Matters
Mismatched timestamps turn a straightforward multi-camera review into hours of reconciliation, and weaken the record when it is challenged
Scale
Operates across thousands of devices without performance impact

Voice and messaging

SIP Audio
Genesis Audio devices registered per site, providing two-way audio and announcements to SIP-enabled speakers from the video viewer
Credentials
Username, password and SIP domain issued per device and entered into the speaker own web client, transport TCP
Capabilities
Talk-down during alarms, speaker-zone configuration, alarm-triggered broadcast, pre-recorded messages, conference mode
Prerequisites
The Genesis Audio permission on the user role, and browser microphone permission. Local Mode is not required

Network requirements

Ports
443 HTTPS client to cloud for the interface and API; 554 RTSP or 443 bidirectional for streams and WebRTC; 8000 or 80 device to cloud for HTTP event paths; DC-09 outbound to the alarm receiver
IP Whitelisting
CIDR ranges provided for secured corporate networks, which must be whitelisted before go-live for edge-bridge hardware

Governance & Limitations

Automatic Time Sync Coverage
Automatic synchronisation is supported for Hikvision and Dahua devices only. Every other device carries a timezone set per device without the NTP handoff
Managed, Not Self-Service
The VPN is designed and operated by NXGEN. That is the value and also the boundary: changes go through the operations team rather than a customer console
Reachability
Everything here depends on the site having a working path out. A device behind a network that blocks the required ports will not reach the platform however it is configured

Getting started

The VPN is deployed and operated by NXGEN end to end; TimeSync and audio are configured per device once the site is connected.

  1. 01Scope the networkTopology, site count and device requirements reviewed with the NXGEN team
  2. 02Open the pathWhitelist the provided CIDR ranges and confirm the required ports before go-live
  3. 03Build and test the tunnelsProtocols, routing, NAT and authentication configured, then latency, throughput and failover confirmed end to end
  4. 04Align and speakSet each device timezone and NTP handoff, and register the site speakers against their Genesis Audio credentials
Read the full guide
Release notes

Know when something ships

New features, fixes and integration updates for GCXONE, delivered to your inbox as they are released.

We send a confirmation link first. Every message has an unsubscribe link.