DSC PowerSeries Neo (IT-2 / TL280)
GEM integrates with a DSC PowerSeries Neo alarm panel through the panel's ITv2 integration protocol — the same protocol DSC's TL280 / TL280E network communicators speak. One GEM device represents the whole panel. From there GEM can arm and disarm partitions, watch every panel zone go open/closed/in-alarm, follow exit/entry-delay countdowns, surface panel trouble and alarm conditions, and bypass zones — all over the building LAN with no cloud account involved.
This is a local, encrypted integration. The session is secured with AES-128 keying that the panel and GEM negotiate automatically.
GEM lists this driver as DSC IT-100 / IT-2, but it speaks the ITv2 integration protocol used by the TL280 / TL280E communicator on DSC PowerSeries Neo panels (HS2016 / HS2032 / HS2064 / HS2128). It is not the legacy IT-100 RS-232 serial module, which uses a different text protocol — pair this driver with a Neo panel that has a TL280/TL280E (or the equivalent built-in integration communicator), not an IT-100 serial board. For older PowerSeries panels reached through an Eyez-On module, see Envisalink EVL-4; for cloud-monitored systems, see Alarm.com.
Unlike most network devices, GEM does not dial out to the panel. GEM opens a listening port and the panel/communicator connects inward to it (a "panel-initiated" session). That means two things during commissioning: you program GEM's server IP into the communicator, and you make sure the communicator can reach GEM on the integration port (default TCP 3072, plus UDP 3073). There is nothing for GEM to "find" — it waits for the panel to call in.
What you get
- Arm / Disarm per partition: arm away, arm home (stay), arm night, arm with no entry delay, and disarm — issued from GEM as device commands you can put on a UI button, a macro, or a trigger.
- Live zone state, auto-created. GEM creates a zone for each panel zone the first time the panel reports on it, under the Security subsystem, and tracks its real-time condition (open/closed, plus tamper, fault, low-battery, and alarm flags).
- Partition feedback. Each partition's armed/disarmed/exit-delay/entry-delay/alarm state is published back onto the device, so the homeowner Security control and your automations can react to it, including a live exit/entry-delay countdown.
- Trouble and alarm reporting. Partition troubles, alarms, and per-device trouble detail are published as device attributes as the panel raises and clears them.
- Zone bypass. Bypass and un-bypass individual zones — and because the panel reports each zone's bypass state, the homeowner Security control's on-screen Bypass buttons work and show bypassed zones with a badge.
Prerequisites
- A DSC PowerSeries Neo panel with a TL280 / TL280E communicator installed, powered, and on the network, with healthy panel programming.
- Integration enabled in the communicator's installer programming (section 851 — see below).
- The panel's Integration ID (section [851][422]) and Access Code (section [851][423], 8 digits — or the 32-hex value in [851][700]).
- A valid DSC user code for arm/disarm.
- A static IP or DHCP reservation for the GEM server, programmed into the communicator (section [851][428]), and network reachability from the panel to the GEM server on TCP 3072 and UDP 3073.
- The Security subsystem (it ships by default, labeled Security). Auto-created panel zones land under it, and the built-in homeowner Security control looks here for the panel device.
The Integration ID ([851][422]) identifies the session, the Access Code ([851][423]) encrypts/authenticates it, and a user code is what actually arms/disarms the panel. The Integration ID and Access Code come from the communicator's installer programming; the user code is an ordinary keypad code. Don't confuse the Access Code (an integration secret) with a user code (a keypad PIN) — they are not interchangeable.
Setup
1. Program the communicator for integration
In the communicator's installer programming (typically *8 + installer code), enable the
integration session and point it at the GEM server. The exact keystrokes vary slightly by
firmware; the essentials are:
- [851][428] — enter the GEM server's IP address (the machine running GEM). This is who the panel calls in to.
- [851][425] / [851][426] — enable integration and real-time notifications (so zone and partition events are pushed, not just polled).
- [851][422] — read the 12-digit Integration ID (you'll enter this in GEM).
- [851][423] — read the 8-digit Access Code (you'll enter this in GEM).
- [851][999] — reboot the communicator after changes (a brief keypad trouble during reboot is normal).
Typical TL280 / TL280E programming walkthrough
This mirrors DSC's TL280 configuration guide. Use it as a reference; your installer should follow the documentation for your exact panel/firmware.
- Section 382 — enable option 5 (Alternate Communicator).
- Section 300 — set Receiver 1 to Alternate Com Receiver 1.
- Section 380 — confirm communications are enabled.
- Section 310 — set a system account code (and the matching partition account code).
- [851] > 005 — enable option 3 (DHCP), or program a static IP in sections 001/002/003/007/008.
- [851] > 100 — turn on option 2.
- [851] > 425 — enable options 3 and 5.
- [851] > 426 — turn on option 3 (required for real-time notifications).
- [851] > 428 — enter the GEM server IP.
- [851] > 422 — read the Integration ID (12 digits).
- [851] > 423 — read the Access Code (8 digits).
- [851] > 999 — enter 55 to reboot the communicator.
2. Add the device
- Open Devices and add a new device with the driver set to DSC IT-100 / IT-2.
- Fill in the fields:
- Integration ID — the 12-digit value from section [851][422].
- Access Code — the value from section [851][423] (or [851][700]). Stored encrypted.
- Master Code — a valid DSC user code used for arm/disarm when a command doesn't supply its own code (for example, the homeowner keypad always sends a code, but a macro might rely on this default). Stored encrypted.
- TCP Port — the integration port GEM listens on. Leave at the default 3072 unless you have a reason to change it; whatever you set here, the communicator must reach.
- Save and enable the device. GEM starts listening and logs "waiting for panel connection". When the panel calls in, the log shows "session established" and the device goes Connected.
- Module IP Address (
ip) is informational only — because the panel initiates the connection, GEM does not use it to dial out. Record it if you like for documentation. udp_portdefaults to 3073; add it only if you moved the UDP side off the default.log_leveldefaults tominimal. Set it toverbosetemporarily to log every panel event while troubleshooting, then set it back.
3. Point the Security subsystem at the panel
So the homeowner Security control and the standard security workflow find the panel:
- Open Subsystems and edit Security.
- Set its Device to the DSC panel you just added.
- Save.
The subsystem's Device is how GEM resolves "the security panel" for the homeowner control.
4. Let the zones auto-populate
You do not create panel zones by hand. The first time the panel reports on a zone (on connect, or when the zone opens/closes), GEM auto-creates a zone under the Security subsystem:
- the zone address is the panel zone number,
- the zone label is "<device> Zone <n>" — rename it to something friendly (for example Front Door, Kitchen Motion),
- the zone state then tracks the panel in real time.
Open Zones and filter to the Security subsystem to confirm they appeared. Naming a zone with words like "door", "window", or "motion" helps — the homeowner Security control groups zones into Doors, Windows, Motion, Smoke, and Water by matching keywords in the label. If a zone never appears, confirm the Security subsystem exists (auto-create is skipped without it).
5. Enable arming from the touch panel (optional)
The built-in homeowner Security control hides its arm/disarm buttons until arming is turned on for the subsystem:
- On the Security subsystem, add the attribute
arm_enabled(type boolean) and set it to true. (Add it from the subsystem's attribute editor — it is offered in the name picker.) - Reopen the homeowner Security control; the Arm/Disarm buttons are now active. With
arm_enabledoff, the control shows "System arming is DISABLED."
Arming and disarming
Arming is done with device commands. The driver exposes:
| Command | What it does |
|---|---|
arm_away | Arms the partition in Away mode (perimeter + interior). |
arm_home | Arms in Stay / Home mode (perimeter only). |
arm_stay | Same as arm_home — an alias for stay arming. |
arm_night | Arms in Night mode (stay arming with the panel's night settings). |
arm_no_entry_delay | Arms away with the entry delay suppressed (instant). |
disarm | Disarms the partition. |
Each arm/disarm command takes two arguments:
code— the DSC user code sent to the panel. The panel validates it, so it must be a real user code. If a command omitscode, the driver falls back to the device's Master Code.partition— the partition number. If omitted it defaults to partition 1, which is the only partition the homeowner Security control targets.
You can fire these three ways:
- For testing — run the command from the device's command list or the
Commands screen with
code(andpartitionif needed) and watch the result. - From a UI — the homeowner Security control's Arm Home, Disarm, and Arm Away
buttons map to
arm_home,disarm, andarm_away. Each prompts for a code on an on-screen keypad (minimum 4 digits) and sends it to the panel as the user code. - From automation — call the command in a macro or trigger (for example, "arm Night when the
house goes to Sleep mode"). See Macros and
Triggers. Put the user code in the step's
codeargument, or rely on the device's Master Code.
Reading the panel's state
The partition's current state is published to the device's arm_state attribute as one of
disarmed, armed_home, armed_away, armed_night, exit_delay, entry_delay, or alarm.
Per-partition state is also published as partition_<n>_state (partition_1_state,
partition_2_state, …). A macro condition or trigger can read these — for example to avoid
re-arming an already-armed system, or to flash a light during entry delay.
The homeowner Security control reads arm_state for its big status banner and to highlight the
active arm button, and it shows a live exit/entry-delay countdown driven by the panel's
reported delay duration.
The homeowner Security control only ever targets partition 1. To arm or disarm a second
partition, call the command from a macro or the Commands screen with the
partition argument set to that partition number.
Zones and live state
Each auto-created GEM security zone mirrors its panel zone. As the panel reports events, the driver updates these attributes on the zone:
| Attribute | Meaning |
|---|---|
state | open or closed — the zone's open/closed condition. |
alarm | true while the zone is in alarm. |
tamper | true while the zone reports tamper. |
fault | true while the zone reports a fault. |
low_battery | true for a wireless zone with a low battery. |
delinquency | true while the zone reports a supervision/delinquency fault. |
alarm_in_memory | true if the zone was in alarm since the last disarm (alarm memory). |
bypassed | true while the zone is bypassed. |
In the homeowner Security control a zone shows red when it is open or faulted, orange when bypassed, and green otherwise; faulted zones float to the top of their group. You can search zones by name and toggle between Show Faults, Show All, and Show Bypass.
Zone bypass
The driver provides bypass_zone and unbypass_zone. Both take the panel zone
number in the address argument (and accept an optional code/partition):
- From a macro or the Commands screen:
bypass_zonewithaddress=5. - From the homeowner Security control: tap a zone to bypass/un-bypass it, or use Bypass
Faulted to bypass every open zone at once. The control passes the zone's address, which is
exactly what these commands expect, and the panel-reported
bypassedflag drives the on-screen BYPASS badge.
Attribute reference
Device attributes — configuration
| Attribute | Required | Type | Notes |
|---|---|---|---|
integration_id | yes | string | Integration ID, section [851][422]. Shown as Integration ID. |
access_code | yes | string (secure) | Access Code, section [851][423] (or 32-hex [851][700]). Shown as Access Code. |
master_code | yes | string (secure) | Default DSC user code used for arm/disarm when a command omits code. Shown as Master Code. |
port | yes | integer | TCP port GEM listens on for the panel. Default 3072. Shown as TCP Port. |
ip | no | string | Module IP — informational only; not used to connect (the panel initiates). Shown as Module IP Address. |
udp_port | no | integer | UDP port for the ITv2 session. Default 3073. |
log_level | no | string | minimal (default), verbose (logs every panel event for debugging), or silent. |
Device attributes — published by the driver
These appear automatically as the panel reports state; you don't set them.
| Attribute | Type | Notes |
|---|---|---|
arm_state | string | Current panel state: disarmed / armed_home / armed_away / armed_night / exit_delay / entry_delay / alarm. |
partition_<n>_state | string | Per-partition state, same values as arm_state. |
partition_<n>_ready | boolean | true when the partition is ready to arm. |
partition_<n>_alarm | boolean | true while the partition is in alarm; clears on restore. |
partition_<n>_trouble | boolean | true while the partition reports a trouble; clears on restore. |
partition_<n>_trouble_flags | integer | Raw trouble bit-flags for the partition. |
partition_<n>_exit_delay | boolean | true during the partition's exit delay. |
partition_<n>_exit_delay_duration | integer | Exit-delay length in seconds, used for the on-screen countdown. |
max_zones | integer | Panel capability — maximum zones, learned on connect. |
max_partitions | integer | Panel capability — maximum partitions, learned on connect. |
trouble_<type>_<number> | string | Detailed per-device trouble (e.g. a specific sensor's trouble state) when the panel reports it. |
connected | boolean | Online flag — true while a panel session is established. |
Zone attributes
| Attribute | Required | Type | Notes |
|---|---|---|---|
address | yes | string | The panel zone number. Filled in automatically when the zone is auto-created. |
state | auto | string | open / closed. |
alarm, tamper, fault, low_battery, delinquency, alarm_in_memory, bypassed | auto | boolean | Zone condition flags (see Zones and live state). |
Diagnostic commands
These query the panel on demand and are mainly useful for commissioning and support. They don't change the panel's armed state.
| Command | Args | What it does |
|---|---|---|
get_zones | — | Returns the driver's cached zone states. |
get_partitions | — | Returns the driver's cached partition states. |
get_system_state | — | Returns cached partitions plus zones in one call. |
query_capabilities | — | Asks the panel for its capabilities (max zones/partitions). |
query_global_status | — | Requests a full global status refresh. |
query_zone_status | address | Queries zone status starting at a zone number. |
query_partition_status | partition | Queries a partition's status. |
query_zone_bypass_status | address | Queries a zone's bypass state. |
query_trouble_status | — | Requests the current system trouble list. |
How it works
Listening for the panel. When the device is enabled, GEM opens a TCP listener on the configured port and waits — the log reads "waiting for panel connection." The panel (via its TL280/TL280E communicator) connects inward to GEM's IP and port. GEM never dials the panel, so a device that stays Disconnected almost always means the communicator can't reach GEM (wrong server IP in [851][428], or a firewall blocking the inbound port).
Encrypted session. Once the panel connects, GEM and the panel negotiate AES-128 keying (Type 1 or Type 2, auto-detected) using the Integration ID and Access Code. The log reports the encryption type on "session established."
Initial pull, then events. On connect GEM queries capabilities and an initial status pull ("status ready"), so partitions and known zones populate right away. After that, updates are event-driven — the panel pushes zone open/close, partition arm/disarm, exit/entry delay, alarms, and troubles as they happen, and the driver maps each onto the matching attribute. A heartbeat keeps the session alive.
Auto-reconnect. If the listener can't start (for example the port is in use) the driver retries with an increasing backoff. If the panel drops the session, the log reads "session closed, waiting for panel to reconnect" and GEM accepts the next inbound connection automatically.
Known limitations and notes
- Panel-initiated only. There is no outbound "connect to the panel" path; GEM listens and the communicator must be programmed with GEM's IP. A NAT or firewall between them must allow the inbound integration ports.
- Single partition from the touch panel. The homeowner Security control targets partition 1.
Multi-partition arming has to be driven from macros/commands with an explicit
partition. - Master Code is the arm/disarm fallback. Commands that don't pass a
codeuse the device's Master Code; keep it set to a valid DSC user code. The homeowner keypad always supplies its own code. - Trouble flags are raw.
partition_<n>_trouble_flagsis a numeric bit-field straight from the panel;trouble_<type>_<number>carries the human-readable per-device detail when the panel sends it.
Troubleshooting
| Symptom | Check |
|---|---|
| Device stays Disconnected; log shows "waiting for panel connection" | The communicator isn't reaching GEM. Confirm GEM's server IP in section [851][428], and that the panel can reach GEM on the integration port (default TCP 3072 / UDP 3073) through any firewall/NAT. |
| Connects then drops, or never establishes a session | Integration ID or Access Code mismatch. Re-read sections [851][422] and [851][423] and re-enter them. Set log_level to verbose to see the negotiation. |
| Arm/disarm rejected with a command error | The user code is wrong, or the panel locked out the integration after repeated bad codes. Verify the code on a physical keypad and wait out any lockout before retrying. |
| Arm "succeeds" but the panel doesn't arm | A zone is faulted (open door/window) or the panel has a trouble; clear or bypass it, then re-arm. |
| Zones never appear | Confirm the Security subsystem exists (auto-create is skipped without it). Zones are created on the first event GEM receives for each zone number. |
| Homeowner control shows "System arming is DISABLED" | Set the arm_enabled attribute on the Security subsystem to true. |
| Homeowner control shows "Missing security device" | Set the Security subsystem's Device to the DSC panel under Subsystems. |
Related documentation
- Devices — where the DSC panel device is added and its connection fields are set.
- Subsystems — assign the panel as the Security subsystem's
device and add the
arm_enabledattribute. - Zones — auto-created panel zones live under the Security subsystem.
- Commands — where
arm_away,arm_home,arm_night,disarm, andbypass_zoneare dispatched and wired into automation. - Macros and Triggers — arm/disarm on a
schedule or in response to events, and react to
arm_stateand zone state. - Envisalink EVL-4 — the alternative for older DSC PowerSeries panels reached through an Eyez-On keybus module.
- Alarm.com — cloud-monitored DSC/other panels without a local integration path.