Skip to main content

ConfigGuardian

Self-Healing MQTT Configuration Protection

ConfigGuardian is an enterprise security feature that continuously monitors and protects the MQTT configuration on Axis cameras running the Anava ACAP. It automatically detects unauthorized or accidental changes to critical MQTT settings and restores them to the known-good state.

Why ConfigGuardian Exists

Anava cameras connect to the cloud via MQTT. The MQTT configuration—broker address, TLS settings, subscriptions, and identity—is accessible through the camera's web UI. If anyone modifies these settings, whether accidentally, maliciously, or through firmware updates, the camera could:

RiskImpact
Complete DisconnectCamera loses all cloud connectivity
Rogue Broker ConnectionSecurity breach - data sent to unauthorized server
Lost FunctionalityCannot receive commands or configuration updates
Silent FailureNo indication of the problem until manual inspection

ConfigGuardian eliminates these risks through continuous monitoring and automatic remediation.

Key Capabilities

Automatic Healing

Unlike traditional monitoring that only alerts, ConfigGuardian automatically restores correct configuration within seconds of detecting drift. No manual intervention required.

Intelligent Detection

ConfigGuardian compares live configuration against a "golden" reference captured after successful setup. It classifies changes by severity and responds appropriately.

Anti-Thrashing Protection

Smart backoff logic prevents configuration wars. If someone is actively fighting the guardian, it escalates to an alert rather than entering an infinite loop.

Full Visibility

Every configuration change is detected, logged, and reported to your dashboard for complete audit trails.

How It Works

ConfigGuardian architecture overview

  1. Capture: Golden configuration saved after successful MQTT setup
  2. Monitor: Every 30 seconds, compare actual vs expected configuration
  3. Detect: Identify any drift with severity classification
  4. Heal: Automatically restore critical settings
  5. Report: Send alerts to cloud for visibility

Quick Reference

ComponentDescription
How It WorksArchitecture overview and monitoring flow
Protected SettingsComplete list of monitored configuration
AlertsAlert codes and response guidance
TroubleshootingFAQ and common issues

Requirements

  • Anava ACAP version 2.0+
  • AXIS OS 11.0 or later
  • Active cloud connection for alert reporting

Last updated: December 2025