Monitor network VLAN division and address planning
Explain why the monitoring system needs to be independently networked, as well as the specific methods of VLAN, IP network segment, and port planning.
Why we need independent networking
- Security: Once the monitoring equipment is connected to the office network, it may become an entry point for network attacks; conversely, viruses and broadcasts on the office network will also affect monitoring.
- Stability: Video streaming takes up a lot of bandwidth and will affect each other when mixed with the business network.
- Manageability: Independent network segments facilitate fault location, traffic statistics, and access control.
- Compliance: Some industries require physical or logical isolation of security system networks.
VLAN planning suggestions
| VLAN | Purpose | Example network segment |
|---|---|---|
| VLAN 10 | Front-end camera | 10.10.10.0/24 |
| VLAN 20 | Storage and Backend (NVR/Server) | 10.10.20.0/24 |
| VLAN 30 | Monitoring center client and large screen | 10.10.30.0/24 |
| VLAN 99 | Device Management | 10.10.99.0/24 |
IP address planning
- Segmented by area or floor: For example, 10.10.10.1–.50 is Building 1, .51–.100 is Building 2, Facilitates direct location location via IP.
- Reserve expansion space: Reserve at least 30% of the addresses for each segment.
- Use a fixed IP for the camera: Do not use DHCP to avoid address changes causing the NVR to go offline.
- Unified Gateway: Usually located on the core switch.
- Create an address account: IP ↔ point ↔ MAC ↔ switch port corresponds one to one.
Switch port planning
- Access layer switches are deployed by region, and the uplink must meet the aggregation bandwidth (multi-port Gigabit uplink or 10 Gigabit).
- Reserve 10% to 20% spare ports for each switch.
- Enable port isolation or private VLAN to prevent cameras from accessing each other.
- Enable Storm Suppression and Loop Detection.
- Critical links are link aggregation or ring network redundant.
Bandwidth accounting
- Access switch: Uplink bandwidth ≥ the sum of the bit rates of all cameras under the switch × 1.2.
- Core switch: Upstream bandwidth ≥ cross-VLAN/cross-region access traffic.
- Important note: Playback, wall posting, and client multi-screen preview will generate additional traffic.
Common security measures
- Different VLANs are controlled through ACL, and only necessary ports are opened.
- Close unnecessary services on the device (Telnet, HTTP management port, etc.).
- Modify the default account password and disable the default account.
- Update firmware regularly.
Related content
Linkage integration of video surveillance, access control, and alarm systems: interface methods and implementation points
09-19
Moiré and false color in surveillance images: lens and sensor matching issues
09-18
Progressive transformation from analog to network: reusing coaxial and hybrid networking solutions
09-17
Lens dirt and protective window cleaning: invisible causes of image quality degradation
09-16
Surveillance video as evidence: retrieval process, preservation and legal effect
09-15
Permission classification and desensitization of video data: who can watch and who can export
09-14
Security system level protection: What requirements should the video surveillance part meet?
09-13
Computer room dynamic environment monitoring: temperature and humidity, mains power, water leakage and smoke detector access
09-12
