Pull vs push: two ways to get punches off a machine
For years, attendance machines worked in pull mode: desktop software on an office PC connects to the machine over the local network and downloads the punches. It works — but the PC must stay on, it only sees machines on its own network, and every branch needs its own copy.
Most ZKTeco and eSSL machines made in recent years also support push mode, known as ADMS (on newer firmware the menu is called Cloud Server Setting). In push mode the machine starts the conversation: it calls a server address you give it and sends each punch as it happens.
| Pull (desktop software) | Push (ADMS server) | |
|---|---|---|
| Who connects | The PC connects to the machine | The machine connects to the server |
| Fixed IP at the office | Needed for remote access | Not needed |
| PC left running | Yes | No |
| Many branches | One copy per site, or VPN | All machines call one server |
| Punches arrive | When someone downloads them | Live, within seconds |
What actually happens on the wire
The push protocol is plain HTTP. The machine identifies itself with its serial number and talks to a few addresses under /iclock/:
- Hello and settings — the machine asks
GET /iclock/cdataand the server replies with its options (for example how often to check in). Newer firmware first registers itself at/iclock/registry. - Sending punches — each new punch is sent with
POST /iclock/cdata?table=ATTLOG: the employee's PIN, the time, and how they punched (finger, face, card). - Asking for work — every so often the machine asks
GET /iclock/getrequest: "do you have a command for me?" This is how a server can ask it to re-send old punches, send its user list, or restart. - Reporting back — after running a command it answers at
/iclock/devicecmd.
Because the machine always makes the call, it works through an ordinary office router with no port forwarding. If the internet drops, the machine keeps its punches in memory and sends them when it is back.
What a good ADMS server must do
- Approve new machines — anyone who knows your address could point a machine at it. Punches from an unknown serial number should be kept but not counted until you approve it.
- Never double a punch — machines re-send data after a reconnect. The server must recognise punches it already has.
- Match PINs to people — the machine only knows a user number. The server links it to an employee, and shows punches whose PIN is not linked yet.
- Turn punches into attendance — first in, last out, late, overtime, absent, leave and holidays, using each employee's shift.
- Show machine health — when each machine last called in, so a silent branch is noticed the same day.
What you need to run your own
- A machine with an ADMS / Cloud Server Setting menu — check
Menu → Comm. - Web hosting with a domain — ordinary PHP hosting is enough; port 80 must be reachable (almost every host).
- ADMS server software — you can write it yourself from the steps above, or install a ready one.
- Five settings on the machine — explained in How to connect a ZKTeco machine to a cloud server.