Security network · VLAN · IEEE 802.1X · PoE
The network that connects cameras, alarms and doors. Segmented, powered and verifiable.
Images, alarms and access events now travel over the same infrastructure. If that network is left to each installer's judgement, a camera can become the way into the rest of the company, and a switch with no headroom can shut the video down at night. S3 designs the security system network to the same criteria as the system itself: segments, rules between them, power, remote access and a configuration that can be checked. The licensed security company or the integrator you choose builds the network. If the security equipment connects to an alarm receiving centre (ARC), a licensed security company installs it, as Spain's Private Security Act (Law 5/2014) requires.
What we decide in the design
Every decision is written into the technical report and becomes a requirement that is checked during acceptance testing.
Separate segments and a flow matrix
Video, intrusion, access control, device management and office sit on separate VLANs, and traffic between them passes through a firewall. Every permitted flow is written into a matrix: source, destination, protocol, port and reason. Anything not in the matrix is denied. For example, the operator workstation opens connections to the recorder, but no camera opens connections to the office, and devices can only be administered from the management VLAN.
Access control on every port
A junction box on a façade is a network socket within anyone's reach. We specify IEEE 802.1X authentication on the devices that support it. For those that do not, MAB: the switch authorises the port by the device's MAC address and assigns it to its VLAN. Because a MAC address can be copied, MAB is combined with a single device per port and an alert when that link goes down. Unused ports are disabled.
Power calculated for the worst case: PoE and UPS
For every port we set the device's PoE class (IEEE 802.3af, 802.3at or 802.3bt) and its maximum declared draw, with infrared, heater and motors all active at once. For every switch, the sum of those loads is compared with its PoE budget, leaving headroom. The power leaving the port is not the power reaching the device: under 802.3at, the port supplies up to 30 W and at most 25.5 W reaches the device. The UPS is sized from those figures and from how long each part of the system has to keep running during a power cut.
Redundancy where an outage would leave an area blind
If losing a link or a switch would leave an entire perimeter without video or control, we design rings with RSTP, or with ITU-T G.8032 where a shorter recovery time is required. Outdoors we specify industrial switches with an extended temperature range and surge protection, and optical fibre in dielectric cable between buildings, which isolates them electrically and avoids problems caused by differences in earth potential.
One time source for the whole system, and an event log
Cameras, recorders, the intrusion panel and access controllers take their time from an NTP server on site, synchronised to a reliable reference. If each device keeps its own time, a recording cannot be matched against the intrusion event or the access log, and it loses value as evidence. Devices send their events (logins, configuration changes, link failures) to a log server, with a defined retention period and alerts to your team.
Remote access over VPN, with no open ports
Anyone connecting from outside comes in over a VPN, with a named user account and two-factor authentication, and reaches only the segment they are authorised for. No ports are forwarded to cameras or recorders, and the manufacturer's P2P service is disabled: it connects devices to third-party servers without anyone having decided so. If the system needs to reach the internet, for example to send signals to the alarm receiving centre (ARC) or to download updates, that flow is in the matrix with its destination.
Hardening and the firmware life cycle
The specification sets concrete requirements: no factory passwords, named accounts with only the permissions they need, unnecessary services disabled (Telnet, UPnP, unencrypted HTTP, P2P) and signed firmware with declared support. The update procedure is written down too: a configuration backup before, priority for security patches and testing after. The EU Cyber Resilience Act, Regulation (EU) 2024/2847, requires manufacturers to report actively exploited vulnerabilities from September 2026 and, from December 2027, to declare a support period with security updates. The design already asks for that period in writing when equipment is selected.
Typical failures we design out
- Typical failure
- Cameras, recorder and office computers on the same flat network. An infected laptop reaches the recorder, and a compromised camera reaches the office.
- In the design
- Separate segments, a firewall between them and a flow matrix that denies anything not written down.
- Typical failure
- Switches chosen by port count. At night the infrared and heaters come on, the PoE budget is exceeded and the cameras reboot.
- In the design
- A worst-case power balance per port and per switch, with headroom, and UPS runtime calculated from the same load.
- Typical failure
- A recorder published to the internet through port forwarding or the manufacturer's P2P service, with the factory password unchanged.
- In the design
- Remote access over VPN only, P2P disabled, and hardening requirements checked one by one at handover.
- Typical failure
- Every device keeps its own time. The video shows one moment and the intrusion panel another, and nobody can reconstruct the sequence with certainty.
- In the design
- A common NTP server for the whole system, and the time on every device checked during acceptance testing.
- Typical failure
- A live port in the housing of an outdoor camera. Unplugging the camera and plugging in a laptop is enough to be inside the network.
- In the design
- 802.1X or MAB on every port, unused ports disabled and an alert when a camera's link goes down.
What you receive
- Network architecture, logical and physical
- VLAN and addressing plan
- Flow matrix
- PoE power balance and UPS runtime
- Verifiable configuration requirements
- Firmware update procedure
- Acceptance test protocol
- Designs S3
- Configures and installs the licensed security company or the integrator you choose
- Operates your team
Reference standards
- IEEE 802.1Q Virtual LANs (VLAN): separate traffic over the same infrastructure.
- IEEE 802.1X Port-based network access control.
- IEEE 802.3af/at/bt Power over Ethernet (PoE) and its power levels.
- RSTP · ITU-T G.8032 Link redundancy and loop-free rings.
- NTP (RFC 5905) Time synchronisation across devices.
- EN 62676-1-2 Video transmission in video surveillance: performance, timing and security.
- EN 50136 Alarm transmission to the ARC.
- Regulation (EU) 2024/2847 Cyber Resilience Act: cybersecurity and support requirements for products with digital elements.
Questions
Can the security system share switches with the corporate network?
It can, if the separation is done properly: dedicated VLANs, firewall rules and administration restricted to the management network. At Grades 3 and 4, or with a large volume of video, the design considers dedicated physical infrastructure, because it also separates faults, maintenance windows and responsibilities. The decision is justified in the technical report.
What if the installation is already in place?
It starts with an exposure audit, with written authorisation from the network owner: which devices can be reached from the internet or from the office, which P2P services are active and where factory passwords remain. That produces a prioritised remediation plan, with the target architecture and the flow matrix.
What does a verifiable configuration mean?
That every requirement has a test and an expected result. 'The recorder cannot be reached from the office' is checked by attempting that connection. 'No factory passwords remain' is checked by trying them. The test protocol records every check, and S3 supervises how it is carried out at handover.
Does S3 respond to network alerts once the system is running?
No. S3 designs and supervises the works. The event log and alerts go to your team or to whoever you designate, and maintenance of the security system is the responsibility of the licensed security company. Later on, S3 can audit the network against the flow matrix and the design requirements.
Before granting remote access, let's draw the network.
Tell us how your cameras, alarms and doors are connected today. The first conversation lasts 30 minutes, is with an engineer and is free of charge.