Card works at one door, not another
very common
“My badge works at the front door but not the back one. New cards won't read at all, old ones are fine.”
Likely causes
-
Reader's output format doesn't match what the panel's reader port expects
~30%The invalid-card event logs a raw bit count or a nonsense card number. Write down the bit count: that number names the format. A 35- or 37-bit stream into a port templated for 26-bit does exactly this.
-
Facility or site code mismatch
~20%Card number in the log matches the badge but the facility code doesn't, or the reader is filtering to one code. Standard 26-bit carries an 8-bit facility code and a 16-bit card number; other formats split differently and some carry no facility code at all.
-
Multi-tech reader with the needed technology or keys not enabled
~15%Prox reads, smart card doesn't, and the failing tech produces no event whatsoever. No event means the reader never generated bits. That's the reader, not the host. For phone credentials go to Phone credential won't open the door.
-
Credential not enrolled, enrolled in another partition, or a typo on the number
~15%Log shows unknown card with a number that looks correct. That's enrollment, not format. Stop looking at the wire and go to Denied at certain times or certain doors.
-
Card number collision inside a 26-bit system
~10%Badge card A and cardholder B's name comes up in the log. Two facility codes, same 16-bit number, and the system only kept one.
-
Reader config lost or defaulted on a swap
~7%Reader was replaced recently. A spare off the shelf is at factory defaults: it will read the card happily and send a format this panel doesn't take.
-
Site keys or secure element mismatch on keyed smart credentials
~3%Reader gives an error flash or beep pattern on presentation and no card data reaches the panel. Keys, not wiring.
What to bring
- Known-good card of each format in use on site
- Wiegand decoder or reader-to-USB tool
- Laptop with head-end and the reader config app
- OEM config cards
- DMM
Steps
-
Step 1: Badge the failing card at the failing reader and capture the raw event
Write down bit count, facility code and card number exactly as logged. A bit count that doesn't match your system's format is the whole answer. No event at all means the reader never decoded the card.
If that doesn’t do it
Cross-test.
-
Step 2: Cross-test three ways
Same card at a working door, known-good card at the failing door. Fails everywhere = credential, enrollment or technology. Nothing works at this door = reader config or port template. Only this card fails = that credential. Costs nothing.
If that doesn’t do it
Read the card's part number.
-
Step 3: Read the card's printed part number and pull the original order
Format and facility code live in the part number and the purchase record. Never assume a reorder matched. This is where most 'new cards don't work' calls end.
If that doesn’t do it
Compare reader config against the port template.
-
Step 4: Compare the reader's config to the panel's reader format
Pull the reader config via OEM config card, app, or OSDP, and set it against the panel's format template. They have to agree bit for bit, including parity and how the facility code is handled.
If that doesn’t do it
Put a decoder on the line.
-
Step 5: Put a Wiegand decoder or the reader's diagnostic output on the data lines
A decoder shows the actual bit stream and ends the argument. Pulse train with the wrong bit count = reader config. No pulse train = reader, technology, or keys.
If that doesn’t do it
Chase keys and credential programming.
-
Step 6: Verify keys and applications for smart credentials
Site keys, the secure element, or the card application must be loaded in the reader. A default reader will not read keyed credentials, ever. Get the OEM to reissue the config card or key file. This does not get fixed in the panel.
If that doesn’t do it
Escalate to the credential issuer or OEM with your logged bit count.
References
- SIA AC-01: the de facto description of the Wiegand reader interface; verify its current standards status before citing it as a live standard
- IEC 60839-11-5 (OSDP)
- FIPS 201 (PIV credentials, where federal cards are in play)
- NIST SP 800-116 (PIV in physical access systems)