Application Scenario · Banking / Financial Intranet / Self-service Terminals

Banking / Financial Counter · Remote O&M and MLPS Compliance for Financial Intranet Security

For bank counter machines, self-service terminals and other financial-intranet equipment, a non-intrusive gateway deployed over the financial private network turns city-wide on-site O&M into unified remote control by the head office, satisfying MLPS 2.0 audit requirements.

Core solution for this scenario

APM-G220 Non-intrusive Smart Tuning GatewayDeployed over the financial private network to remotely take over teller machines / self-service terminals; data stays within the financial network and complies with MLPS 2.0
Banking / Financial Intranet / Self-service Terminals scenario

I. Industry Pain Points

Typical challenges for Banking / Financial Intranet / Self-service Terminals in equipment O&M and data acquisition.

  • A city commercial bank may have 50-200 branches, each running 2-8 teller machines or self-service terminals on the financial intranet — no internet connectivity, no unauthorized software.
  • When a device fails (system freeze, config needs updating), O&M staff can only drive on-site; a single visit averages 2-4 hours.
  • A failed teller machine directly disrupts service, creating high customer-complaint risk.
  • Financial-intranet compliance is strict and traditional remote-control solutions are unusable; MLPS 2.0 requires auditable operations, which legacy approaches can hardly log.
Typical Customer Scenario

A joint-stock commercial bank with 120+ branches across the province, each running 3-6 teller workstations. The branch front-end machines use dedicated peripherals such as encrypted PIN pads and ID card readers. Legacy remote-desktop software is blocked by the bank's intranet security policy, so fault handling depends entirely on vendor on-site visits — averaging 4 hours per trip, and even the next day for remote branches. After deploying G220, the IT operations center can remotely take over the full desktop of any teller station, unrestricted by intranet policy. On-site O&M dropped from 100% to under 20%, average fault recovery <10 minutes, and full-session screen recording satisfies CBIRC MLPS compliance audit.

II. Solution

Build a "screen layer + protocol layer" dual-source data closed loop with the AIXOT non-intrusive gateway combination.

  • Deploy an APM-G220 at the key equipment of each branch, connected to the head-office O&M center over the financial private network (leased line / VPN); control is via browser — no internet for the teller machine, no software install, no config change.
  • Remote troubleshooting, batch config updates and virtual CD-ROM remote reinstall cut on-site visits by 80%.
  • Full operation logs plus screenshot archiving satisfy MLPS 2.0 identity authentication, access control and security audit requirements.
  • Finance is a sensitive industry; 4G does not connect to the public network, the remote channel is closed within the financial private network, and the dual-port design guarantees isolation.

III. Deployment Steps

An executable path from interface inventory to a standardised closed loop.

  • Inventory video and USB interfaces of teller machines / self-service terminals at each branch; plan G220 deployment points
  • Backhaul over the financial private network (leased line / VPN) into the head-office private O&M platform
  • Record high-frequency operations (troubleshooting, config update, system reinstall) as standard keyboard/mouse scripts
  • Configure multi-level accounts and permissions; authorize before operation, record the entire session
  • Establish an alarm → approval → remote access → script execution → screen-archive SOP; route via the backup leased line if the primary drops

IV. System Integration & Data Connectivity

Standardised connection points with MES / SCADA / PLC / quality systems.

  • Connect to the MLPS compliance system: full traceability of identity authentication, access control and security audit
  • Connect to ITSM / ticketing: link remote operations to fault tickets and approval flows
  • Connect to the bastion host: unified authentication and permission control
  • Connect to unified monitoring: device-offline alarms auto-link to the G220 out-of-band channel

V. Value & Quantified Metrics

Measurable benefits from the non-intrusive solution.

80%↓On-site O&M reduced
≤5minFault response time
100%Operations auditable

VI. Deployment Boundaries & Compliance Red Lines

Compliance & applicable boundaries

Finance is a sensitive industry; 4G must not connect to the public network and the remote link must be confined to the financial private network / intranet. The G220 applies only to teller machines / self-service terminal industrial PCs with video output and USB input; pure embedded devices without a display require separate evaluation.

VII. FAQ

High-frequency questions for the Banking / Financial Intranet / Self-service Terminals scenario.

Does the teller machine need internet to be remotely controlled?

No. The G220 takes over physically via HDMI/USB; the teller machine itself stays offline and installs no software, and the remote link is closed within the financial private network.

Does it meet MLPS 2.0?

Yes. Full operation logs, screenshots and login/logout records are exportable, covering identity authentication, access control and security audit requirements.

What if the leased line drops?

Restore via the financial private network's backup leased line; the financial industry forbids 4G to the public network, and the dual-port design guarantees isolation.

Can config updates be batched?

Yes. Scripted batch modification of teller machine config parameters, synchronized city-wide, cuts on-site visits by 80%.

Related Scenarios & Products

Data Center / Server Room

Centralized out-of-band KVM O&M

→ View Scenario

Healthcare / Hospital Intranet

Remote O&M for devices (data stays on-premise)

→ View Scenario

Multi-site Enterprise

One platform to manage all sites' equipment

→ View Scenario