Contact Us

If you still have questions or prefer to get help directly, please reach out to your technical contact.

  • Home
  • Home
  • Integrations
  • Presence

LenelS2 NetBox: Integration Overview and Network Requirements

Written by Jeff Burr

Updated at June 23rd, 2026

Contact Us

If you still have questions or prefer to get help directly, please reach out to your technical contact.

  • Get Started
  • FAQ
    Home Tab Organization Tab Locations Tab Occupants Tab Directory Tab Reports Tab Assignments Tab Map Editor Tab Facility Management Tab IT & Cloud Tab Visitor Management Tab Pre-screen Tab Mobile App SSO Login Room Signage Calendar Sync Other Settings
  • Integrations
    Avigilon (OpenPath) Integrations Calendar Sync Maptician Signage Microsoft Integrations Okta Integrations Opensity Integrations Presence Provisioning Single Sign-on (SSO) Webex Integrations Zoom
  • API Guide
  • Release Notes
    Newsletters Historical Releases
+ More

Table of Contents

Overview How the Integration Works Sync Behavior User Mapping Data Handling Required Network Access API Endpoint Access Firewall Allowlisting Communication Behavior Enabling API Access in NetBox

Overview

Maptician integrates with the LenelS2 NetBox access control system to automatically update user presence based on badge swipe activity. When a user badges into an office location, Maptician detects the event and sets that user's presence status to the corresponding location - no manual input required. 

This article covers how the integration works, what data is synced and how it is handled, and what your network team must configure to allow Maptician to reach your NetBox API endpoint. 


How the Integration Works

Maptician connects to the NetBox web-based API to retrieve badge access activity and user records. This data is used to populate the Presence feature in Maptician, giving authorized users a current view of who is in the office and where. 

Maptician runs two parallel synchronization processes against the NetBox API: 

  • User sync: Maps users between the S2 system and Maptician so that badge swipes can be attributed to the correct occupant.
  • Badge access history sync: Retrieves badge swipe events and converts them into Presence entries in Maptician.

Sync Behavior

Maptician pulls badge access history from the NetBox server every 5 minutes. Each sync retrieves the previous 30 minutes of badge access data. 

ℹ️ NOTE

The S2 NetBox system has an approximate 15-minute delay between the actual badge swipe and when that event becomes available via the API. The 30-minute lookback period is intentional and results in overlapping data across sync runs. This redundancy compensates for potential server outages, network disruptions, or other interruptions in data transfer. 

 

User Mapping

Before badge swipe data can be attributed to an occupant in Maptician, the system must establish a mapping between the user in S2 and the corresponding occupant in Maptician. The mapping process works as follows: 

  • Maptician first attempts to match users by email address, which is the most reliable identifier.
  • If email is unavailable or insufficient, Maptician falls back to first name, last name, and any relevant custom fields, depending on your configuration settings.
  • Once a match is confirmed, the user's unique PERSONID from the S2 system is recorded in the corresponding occupant record in Maptician. This ID is used to accurately attribute all future badge swipe events.

Data Handling

When Maptician converts a badge swipe into a Presence entry, it extracts three pieces of information: 

  • Occupant identifier: Links the badge swipe to the correct individual.
  • Time of entry: Records when the badge swipe occurred.
  • Location: Since a NetBox instance is typically associated with a single office location, Maptician automatically assigns all badge swipes from that instance to the configured location.

ℹ️ NOTE

After a badge swipe is converted to a Presence entry, the original badge swipe data is discarded. Swipe events for users who are not mapped in both systems are never stored. 

 

Required Network Access

Maptician initiates all connections outbound to your NetBox API endpoint. From your network's perspective, this requires allowing inbound TCP traffic from the Maptician source IP to the NetBox API endpoint. The table below lists the values your network team will need. 

Item Value
Source Maptician cloud server
Source IP 18.233.82.110
Source hosting region AWS US East (N. Virginia) / us-east-1
Destination Client-hosted LenelS2 NetBox API endpoint
Direction (client perspective) Inbound from Maptician
Protocol HTTPS (recommended) or HTTP
Default port TCP 443 for HTTPS, or TCP 80 for HTTP
API method HTTP POST
Payload format XML
Authentication NetBox API username and password, provided by your team during implementation

API Endpoint Access

The NetBox API endpoint must be reachable from Maptician at the URL provided during implementation. The endpoint may be served directly by NetBox or through a client-managed network layer such as a reverse proxy, firewall, VPN, or load balancer. 

Example endpoint formats:

  • https://<netbox-host-or-ip>/nbws/goforms/nbapi
  • http://<netbox-host-or-ip>/nbws/goforms/nbapi

ℹ️ NOTE

HTTPS is recommended. If HTTPS is used, SSL/TLS may be terminated either by NetBox itself (where supported) or by a client-managed device positioned in front of NetBox. 

 

Firewall Allowlisting

The Maptician source IP must be allowlisted on any firewall, VPN, reverse proxy, load balancer, or other network security appliance positioned in front of NetBox. Use the rule below as a reference for your allowlist configuration. 

Source IP Destination Port Protocol Action
18.233.82.110 Client NetBox API endpoint 443 or 80 TCP Allow

⚠️ IMPORTANT

Only the Maptician-provided source IP (18.233.82.110) should be permitted. Access from other public IP addresses should be denied unless explicitly required by your internal support or administration processes. 

 

Communication Behavior

For each sync run, Maptician follows this sequence to communicate with the NetBox API. The same pattern applies to both user synchronization and badge access history synchronization. Requests use the Connection: keep-alive HTTP header. 

  1. Sends an HTTP POST request with an XML Login command to authenticate with the configured NetBox API username and password. 
  2. Receives a NetBox session ID in the response.
  3. Issues the required API command or commands for the operation, reusing the session ID.
  4. Sends a Logout command to terminate the session.

Enabling API Access in NetBox

To enable Maptician's access to your NetBox API, you will need to configure API access and set up username and password authentication in NetBox. The exact steps depend on your specific NetBox configuration. Contact your S2 service provider for assistance with this setup. 

For detailed instructions, refer to the following sections in the NetBox Web-Based API documentation: 

  • Creating User Roles for API (page 17)
  • User Login Authentication (page 18)

💡 TIP

If you have questions during setup or need guidance on configuring the integration, contact Maptician's integration support team at support@maptician.com. 

 

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

Configuring Microsoft IP Presence Integration
Microsoft Graph API Configuration Guide
Maptician Logo
121 S. 13th St.
Suite 204
Lincoln, Nebraska 68508
Info@maptician.com
  • Platform Overview
  • Workplace Analytics
  • Space Planning
  • Visitors
  • Conference Rooms
  • Flexible Seating
  • Presence
  • Industries
  • Legal
  • Financial Services
  • Corporate
  • Pricing
  • News
  • About
  • Resources

© | All Rights Reserved | Terms of Service | Privacy Policy | Disclaimer | Cookies | Data Subject Access Request | Do Not Sell My Info

Expand