All posts

What Dante Security Actually Covers

av-over-ipdantemspnetwork-securitynetflow

Someone on the AV VLAN opens Dante Controller. Every encoder shows up. They can subscribe anything they see. IT says the site already has Dante security. They mean Director is licensed, or the devices are enrolled, or they heard about AES-256.

Those are real controls. They are also distinctly separate from security visibility on the network.

Unmanaged Dante is open by design

On a default Dante network, control lives in Dante Controller. Anyone who can reach the segment can open it and change routes.[1] That is how a lot of rooms still run. It is convenient. It is also why "we run Dante" is not an access-control statement.

Audinate's own comparison page is blunt about the next step. Once you enroll devices in Dante Director or Dante Domain Manager, control goes through the manager. Media still flows device to device, the same way it did when the network was unmanaged.[1] The stream path does not start going through a security appliance. The subscription desk does.

What Director and Domain Manager actually lock

Dante Domain Manager (on-prem) and Dante Director (cloud) are the membership and control plane.

They let you put devices into domains or sites so a classroom tech does not see the stadium. They require a login before the Controller will show enrolled devices. They assign roles. Domain Manager can talk to LDAP or Active Directory. Control traffic between devices and the manager is encrypted. Administrators get a dashboard, alerts, and an audit log of user actions, device events, and system events.[2][3]

If you are not a DDM user, and you fire up Controller on that same network, you do not get to view or steer enrolled devices. You only see whatever is still sitting in the unmanaged domain.[3]

That is real. It stops the intern from rerouting the ballroom. It does not tell you whether an enrolled encoder opened SMB to a file server, or whether a laptop that is not a Dante device started talking to the DSP.

Encryption hides the media, not the conversation

Dante Media Encryption uses AES-256 on the media itself so someone on the wire cannot reconstruct the audio or video.[4][7] Keys are handed out over the already-encrypted control channel. You do not type a passphrase onto each box. Director can rotate them on a schedule.[7][9]

Two catches, both from Audinate, not from us.

It only encrypts a subscription when both ends support it and both ends are enrolled in a managed network. On an unmanaged network, every media subscription is unencrypted.[6] Firmware has to be new enough. Audinate shipped that firmware for Dante Embedded Platform and Brooklyn 3 in 2025; manufacturers still have to push it.[5][9]

Policy is either compatible or strict. Compatible is the default. It will try to encrypt, then fall back to cleartext if the receiver cannot decrypt. Strict refuses the subscription instead.[5][6] A site that "has media encryption" can still be sending a lot of rooms in the clear if half the fleet never got the update.

Even when the payload is encrypted, the flow still exists. A switch still sees who talked to whom. Encryption answers whether a tap could reconstruct the meeting. It does not answer whether this encoder should be talking to that subnet.

Dante monitors Dante

Audinate has been saying for years that AV networks should be monitored. Their 2022 note is about connectivity, bandwidth, latency, packet loss, clock sync, subscriptions, and whether audio is actually arriving. Dante Controller can show some of that, but it was not built to stay open all day. Domain Manager is the always-on version: dashboard, email alerts, audit log of Dante activity.[8]

That is AV operations, and it is the right tool for a missing subscription, a device that dropped, or a clock that lost lock. Those are the tickets that kill a room.

It is not a picture of the rest of the LAN. Domain Manager is not a NetFlow collector. A guest address appearing as a peer of an encoder is not a Dante subscription change. A codec opening RDP or hitting the public internet is not a Controller event. A second DHCP server is not a domain enrollment.

The VLAN isolation post covered the drawing-versus-traffic version of this. Dante security is the same split, one layer up. Membership and media confidentiality are solved in the Dante plane. Lateral movement, unexpected egress, and "this box should never talk to that one" live on the switch.

Flow data is the other half

NetFlow, IPFIX, and sFlow already describe who talked to whom, on which ports, and how much moved. You do not need the media. You do not need an agent on the encoder. You need the exporter that the switch or firewall is already running.

That is enough to see a non-Dante peer on an AV address, a new talker that never enrolled, internet egress from a codec, or a discovery storm after a change window. Dante Director will not raise those, because they are not Dante events. Keep Director for the Dante plane. Use flow data for the rest.

What to do this week

Pick one live Dante site. Not the lab.

  1. Is it unmanaged? If yes, anyone on that VLAN with Controller is an admin. Decide if that is still acceptable.
  2. If it is managed, who is still in the unmanaged domain, and why?
  3. How many enrolled devices actually support media encryption, and is the policy compatible or strict?
  4. Export flows for a few days. Compare Dante peers to everything else those same addresses talked to.

If the Dante map and the flow map agree, you have a baseline. If they do not, you have the conversation before the incident.

FAQ

Is this a knock on Dante Director or Domain Manager? No. Enroll the devices. Turn on roles. Turn on encryption where the firmware exists. Those are the right Dante controls. This post is about the job they do not claim.

Does "Dante security" mean the stream is encrypted? Only on a managed network, and only when both ends support it. Unmanaged subscriptions are unencrypted. Compatible policy will still fall back to cleartext.[6]

Will flow monitoring decrypt or inspect Dante media? No. AVoIP Guard takes NetFlow, IPFIX, and sFlow metadata from the switch or firewall. No agents on the endpoints. No look at the payload. Encrypted or not, the metadata is the same job.

We already have Dante Director. Why add anything? Director tells you what enrolled Dante devices did in the Dante plane. It does not tell you what those same IPs did on the rest of the network, or what non-Dante boxes on the AV VLAN did at all.

Are you talking about Dante Security Inc.? No. That is a different company. This is Audinate's Dante AV-over-IP platform.


Sources

[1] https://www.getdante.com/products/network-management/compare-solutions — Audinate: Comparing Dante Director and Dante Domain Manager [2] https://www.getdante.com/products/network-management/dante-domain-manager — Audinate: Dante Domain Manager [3] https://dev.audinate.com/GA/ddm/userguide/1.8/webhelp/content/overview.htm — Audinate: Dante Domain Manager user guide, overview [4] https://www.getdante.com/products/network-management/dante-media-encryption — Audinate: Dante Media Encryption [5] https://www.getdante.com/support/faq/how-do-i-enable-encryption-on-my-dante-network — Audinate FAQ: How do I enable encryption on my Dante network? [6] https://www.getdante.com/support/faq/72394 — Audinate FAQ: Are all subscriptions encrypted with Dante media encryption? [7] https://dev.audinate.com/GA/dante-controller/userguide/webhelp/content/media_encryption.htm — Audinate: Dante Controller user guide, Media Encryption [8] https://www.getdante.com/blog/why-you-should-be-monitoring-your-av-network — Audinate: Why You Should Be Monitoring Your AV Network (April 22, 2022) [9] https://www.audinate.com/press/audinate-announces-availability-of-built-in-aes-256-media-encryption-in-flagship-dante-products — Audinate: AES-256 available in DEP and Brooklyn 3 (June 5, 2025)

Live demo Join the beta