Guide · Setup

How to connect an eSSL biometric machine to cloud attendance software

Most eSSL terminals sold in India since about 2016 can send every punch to a server on the internet by themselves. The setting is on the device, it takes a few minutes, and no PC is involved afterwards. This guide walks through it screen by screen, including the two places people get stuck: a serial number that does not match, and a machine that was quietly pointed at somebody else's cloud when it was installed.

To connect an eSSL machine to cloud attendance software, register the terminal's serial number in the cloud software, then on the device open Menu, Comm, and the ADMS or Cloud Server Setting screen, enter the server address and port your vendor gives you, save, and let the terminal restart. Within a minute it registers itself and shows online; a test punch then appears in the browser. The employee IDs already on the machine keep working if the cloud records use the same numbers. Old eTimeTrackLite installations can keep reading the device over the LAN during a parallel run, because the ADMS push and the desktop software's LAN read do not conflict.

~30 minutes

for one terminal, including the test punch, if the model has an ADMS screen

0 software

installed at your site afterwards; the device talks to the cloud itself

1 setting

a terminal pushes to one server; know what it points at today before you change it

10 minutes

of silence before AionHRMS marks a terminal offline, so you know the wait is real

01

Before you touch the machine: three things to collect

The connection itself is quick. The half-hour is mostly in knowing what you have, and a photo taken now saves a site visit later.

  • The exact model and firmware. On the device, Menu, System Info or Device Info, then Device or Firmware. The sticker on the back gives the model and serial; the firmware is only on screen. "eSSL X990" is not enough on its own; two X990s a year apart can run different firmware with different menus.
  • The serial number, character for character. It appears on the Device Info screen and on the sticker. Copy it from the screen, not the box: the sticker is sometimes for the housing, not the board.
  • What the terminal points at today. Open Menu, Comm, and look at ADMS or Cloud Server Setting. If a server address is already filled in, the machine is pushing somewhere: eSSL Cloud, a dealer's hosted eTimeTrackLite, or a previous vendor. Photograph that screen before changing anything, because you will want to know who has been receiving your punches.
  • Whether the office network lets the terminal out. It needs ordinary outbound internet on the port the cloud software gives you, the same way a laptop reaches a website. No inbound port, no static IP, no port forwarding. A guest Wi-Fi with a captive portal will not do; a wired LAN port or a Wi-Fi network with a plain password will.
02

Step 1: register the terminal in the cloud software first

Do this before the device is repointed, not after. A terminal that connects with a serial number the server has never seen is answered politely and ignored: it shows connected on its own screen while nothing arrives in your account. In AionHRMS, the Devices page takes the serial number, a name for the terminal, the site it belongs to and the protocol, which for eSSL and ZKTeco is iClock / ADMS. Save; support then gives you the server address and port to type into the device.

  • Type the serial exactly as the device shows it, including letters. A single transposed character is the most common reason a freshly repointed terminal never comes online.
  • Give the terminal the name people will use when reading the register, such as "Main gate" or "Plant B, shop floor". Every punch is stored against the terminal that took it, so the name appears in reports for years.
  • If you are moving several terminals, register all of them now. The device-side change is the same for each and goes faster in one pass.
03

Step 2: set the server address on the device

Menu paths differ by model and firmware. On most eSSL and ZKTeco terminals the screen you want is under Menu, then Comm. (sometimes Comm Settings), then one of ADMS, Cloud Server Setting or Server Settings. Older monochrome models show it as ADMS; newer colour touch models show Cloud Server Setting. The fields are the same.

  • Enable Domain Name: turn it on if the address you were given is a name such as a hostname, off if it is a bare IP address. Getting this wrong is the second most common cause of a terminal that will not connect.
  • Server Address: the hostname or IP from the cloud software. No http:// prefix, no trailing slash, no path. The device adds the path itself.
  • Server Port: the number you were given. Type it in the port field, not after the address.
  • Enable Proxy Server: leave it off unless your IT team has told you the LAN needs one. A proxy that is set but unreachable looks exactly like a dead internet connection from the device's side.
  • Save. Many models ask to restart; let them. Some show a small cloud or link icon on the home screen once connected; the icon changing from a struck-through symbol to a plain one is your first sign of life.
04

Step 3: watch it register, then punch

The terminal now contacts the server on its own. The first message it sends is a handshake carrying its serial number; the server answers with its options and the device begins polling for commands every few seconds. In AionHRMS the Devices page flips the terminal to online at that moment, usually within a minute of the restart.

  • Still offline after two minutes: recheck the serial number in the cloud software against the Device Info screen, then the domain-name toggle, then whether the device has an IP address at all (Menu, Comm, Ethernet or Wi-Fi). The troubleshooting guide on this site goes through the remaining causes in order.
  • Once online, have someone punch. Their record should appear in the register within seconds, with the terminal name and the verification method (fingerprint, face, card or PIN) on the row.
  • If the punch appears with an unknown person, the employee ID on the device and the employee record in the cloud do not match. See the next section.
05

Employee IDs: keep the numbers the machine already knows

Every fingerprint or face on the terminal is stored against a user ID, sometimes called the enrol ID or PIN. The terminal sends that number with each punch. As long as the employee's cloud record carries the same number, the punch lands on the right person and nobody has to re-enrol. This is the part that makes a cutover painless, and the part a rushed setup breaks.

  • Before the cutover, export the user list from the old software or read it off the terminal (Menu, User Mgt or User Management). Match each ID to a person.
  • In the cloud software, give each employee the same device ID. If you are creating employees fresh, tell the vendor the IDs are already assigned; AionHRMS can carry an existing terminal ID on the employee record.
  • Do not renumber people to make the list tidy. A renumbered ID means a fresh enrolment at the terminal for that person, which for a 200-person plant is a day of queueing.
  • New joiners after the cutover are created in the browser and pushed to the terminal with their ID. They enrol their fingerprint or face at the machine once; the template stays on that device, and compatible iClock templates can be pushed to other compatible iClock terminals on the same account.
06

Running the old software in parallel, and when to stop

A terminal has one push-server setting. If it was pushing to eSSL Cloud or another hosted server, that stops the moment you repoint it, and the old hosted register freezes at that hour. Desktop eTimeTrackLite is different: it reads the terminal over the LAN using the device's SDK port, which is a separate mechanism from the push. Both can run at once, which is exactly what you want for the first payroll cycle.

  • Leave the desktop software reading the terminal for one full pay period. Compare its monthly report with the cloud register for the same people. They should agree to the punch.
  • Export history from the old system before you decommission it: at minimum the monthly attendance reports for the periods you must retain, and the user list. The cloud register starts on the day of the cutover; it does not inherit the old database.
  • When the parallel month reconciles, uninstall the old software or simply stop the PC. The terminal keeps working; the PC was only ever a reader.
  • If the terminal was on a hosted cloud, ask that vendor for a full export before you repoint. Once the device points elsewhere, you may lose the login.
07

ZKTeco, CP Plus and other ADMS terminals

eSSL terminals are built on ZKTeco hardware, and the ADMS push is a ZKTeco protocol, so the steps above apply to ZKTeco-branded terminals and to many badge-engineered ones. The menu wording on a ZKTeco unit is usually Menu, Comm., Cloud Server Setting. CP Plus and other resellers ship a mix: some units expose the full ADMS screen, some expose only an IP and port with no domain-name toggle, and some older ones have no push setting at all.

  • If the Comm menu has no ADMS or Cloud Server entry, the firmware cannot push. Some models accept a firmware update from the dealer that adds it; others need replacing. Send the exact model, the serial number, the firmware version and a photo of the Comm or ADMS settings screen and we will say which.
  • If the screen offers only an IP and port with no domain-name toggle, the terminal still works: ask support for the numeric server address instead of the hostname, and enter it with the port as given. Nothing else about the setup changes.
  • Realtime terminals are a different case entirely: they use Realtime's own push protocol, not ADMS. The Realtime integration page covers them.
  • Matrix, Mantra, Secureye and BioMax are not implemented on AionHRMS today. We would rather say so than list every brand in the market and disappoint you at the gate.

Frequently asked questions

Do I need a static IP or port forwarding to connect an eSSL machine to the cloud?

No. With the ADMS push the terminal dials out to the server, the way a phone app reaches a website. It works behind an ordinary router on a dynamic connection. A static IP is only needed by the older model where software outside your network reads the device, which is not how push works.

The device shows connected but nothing appears in the cloud. Why?

Almost always the serial number. The terminal contacts the server with its serial in every message; if that serial is not registered to any account, the server still answers the device, so it shows connected, but the punches have nowhere to land. Compare the registered serial with the Device Info screen character by character. The second cause is the domain-name toggle set the wrong way for the type of address you entered.

Will my employees have to re-enrol their fingerprints?

Not if their cloud records use the same user IDs the terminal already holds. The templates stay on the device; only the punches move. People re-enrol only when their ID changes or when they are added to a terminal they were never enrolled on.

Can I keep eTimeTrackLite running while I test the cloud?

Desktop eTimeTrackLite reads the terminal over the LAN and can keep doing so while the terminal also pushes to the cloud, so a parallel month is straightforward. Hosted eSSL Cloud is different: it receives the same push you are about to redirect, so it stops receiving the moment you repoint the device.

How long does it take for the machine to show online?

Usually under a minute after the restart. AionHRMS marks a terminal online on its first handshake and marks it offline again only after ten minutes without contact, so if it has been silent for two minutes something is wrong with the setting, not the wait.

What if my eSSL model has no ADMS or Cloud Server option?

Then that firmware cannot push and the device cannot be repointed as it stands. Some models can be updated by the dealer; others cannot. Send the model, serial, firmware and a photo of the Comm menu and we will tell you which, before you spend anything.

Send us the model and serial before you start

We confirm the terminal, give you the server setting, and stay on the phone for the test punch. Invoiced only after the devices are live.