VLANs for Video Surveillance Tutorial

By John Scanlan, Published Sep 26, 2016, 11:12am EDT (Info+)

Many people confidently say to 'use VLANs' as an answer to IP video networking problems and as a way to signal expertise.

But how should VLANs be used? What benefits do they really deliver or not?

IPVM Image

In the note, we examine:

  • Segmentation of applications across VLANs
  • Untagged vs tagged VLANs
  • Static vs dynamic VLANs
  • VLANs for uplinks
  • Bandwidth and VLANs
  • QoS and VLANs
  • Common applications of VLANs

********

***** (******* ***** **** *******)********* ******* * ****** ******** ****** or ******** **** ******** ******** ******* networks, ****** ******* ** *** **** "invisible" ** *** ****** ** *********** with ******* ** ******* ****** **** are ****** ********.

*** ******* ** ******* ***** ***** on * ******* ****** / ********* network. ** **** ********, ************ ******* is ********* **** ******* ****** *** VOIP ******* *** ***** ******** *****. The **** ******* **** *** *********** with **** ***** ** *** ************ below *** *** ****** *** *** NVR, ** **** *** ** *** same ****.

IPVM Image

Untagged **. ****** *****

***** *** *** *********** ***** ** VLANs, ****** *** ********:

******** *****

** *******, *** ***** ** * switch *** ***** ** * ******* untagged **** (********* **** ** *), meaning **** *** ***** *** "***" all ******. ****** ******** ***** ** another **** ** ** ******** ********** this *******.

*** ******* ******** ***** ** ******* configuration, ** ** ******** ****** ************* (cameras, *******, ***.) **** ** *********, as ******* ** ****** ******* ** the **** ** *** ******. *******, ports (********* *******) *** **** ** assigned ** * ****** ******** ****. So ** * ******** ****** **** see ******** *****, **** ** ****** file ********/********, ************, *** ****, ***** must ****** *** ******* (*****) ** route *** *** **** ******** ********, both ** ***** *** **********.

****** *****

***** *** **** ** ****** **** specific **** *** ***** ***.** *******. Traffic ******** *** ******* *** **** is ****** **** * ******** ** which ** ********* ** *** ********* device.

*** ******* ** ****** ***** ** that ***** *** ** ******** ** more **** *** ****, ****** ********. However, *** ******* ********* ** ***** ports **** **** ******* ***.**, ***** is *** ********* ** **** ** cameras ** ***** ******** *******, *** requires ********** ******* ********** ** ** installed/configured ** ***. ******* ** ****, tagged ***** *** ********* **** **** for ******.

Static *****

**** ***** ************ ******** *** ****** VLANs ********** *** ****. *** *******, ports *-** ** * ****** *** be **** ** *** ******* ***, while **-** *** **** ** *** camera ****.

**** ***** ****** ***** *** **** common, *** ******** ** *** **, but **** ** ******** ************ ** devices *** ***** ** *****, ****** dynamic *****. ** *** ***** ***** we ******* * ******** ** *********** port ***** *****:

Dynamic *****

******* ***** ****** * **** ***** on *** *** *******, ***********, ** type ** ******. **** ******** ******* flexibility, ***** ******* *** ** ******* into *** ****, *** ********** ** needed.

*******, ******* ***** ** ******* ***** more ****-*********, ** *** ******** ** macros **** *** ****** *********** ** rules **** ** *******, ****** **** less ******** ****, ********** ** ************ as *******, *******, *** ***** ********* typically ******* ********* ** *** **** port, *** *** *** *****.

*** ***** **** *******

***** *** * *** ********** ** dynamic *****. ***** ** ******* ** image **** * ******* ****** **** shows *** ***** **** *************. *** switch **** ******** *** *** ******* of *** ****** ********** ** ** and **** *** ** ** *** appropriate **** ***** ** *** ********** policy.

IPVM Image

***** ******* **** *******

******* ***** *** **** *** *** two ***** *****, ******* ** ***** is ****** ** ************:

  • ******/"***** *****": **** ****** **** ********* such ** ***/**** ** ************* ***** the ****** **** ********* *** ****** it ** * ****. **** ** commonly **** ** ***** **** ** and ******* ******* ********, *** *** vast ******** ** ** ******* ** not ******* *** ******** *********, ****** it *********** ******* ** ************.
  • ****** *********/****: *******, ******* ***** ******* Active *********/**** *** ** ******** ** a ******** ***** ** ************ **** the ****** **********. *** ******* ******* these *********, *** ** *** ** useful ** ********* ******** ***** (******, security ********, ******, ***.) ****** ** view ************ *******, ********** ** ***** machine **** *** ** ****.

VLANs *** *******

***** *** *** **** ** ****** VLANs ** ****** ****** *****.

  • ********* **** *** ****:** ******** **** ******** ****** ***** and *** *****, ******** ****** ***** may ** ******** ** * ****** VLAN. **** ** *** ******** ****** to ***, ****** *** ****** ** VLANs **** ** ***** **** *** number ** ****** *****.
  • ****** ***** ****:******, ******* *** ** **** **** a ****** ****** **** ** *****, referred ** ** * ***** ****. Traffic ******* ***** ***** ** ****** as ******** ***** ***** ***.** (*** above). **** ****** ** ******** **** complex, *** ********* ********* ** ** allows *** **** *********** *** ******** and/or ****** ****** **********.

VLAN ********

********* ******** ** ****** ******** ** the **** ******* ** ***** *****. By ********** ******* **** ******** ******* LANs, ************ *** ******** ******* ** the **** ****** ** ******* **** or ***** *******. *** ********* ********, the ******** *** ********* ** **** other ** ******* ** *** ****** LAN *** *** ***** *** ************ VLAN.

********* *****

** ************, ***** *** *** **** to **** *********, * ******* ****. It ** *********** **** **** ***** reduce *** ****** ** ******* ** the ***, ***** ********** *** *** sent ** *** ****** ******** *******, but **** ** *** *********** ****. However, **** ********* **** ******* *********** on **** ***** ********, **** ******** of *******. ** * **-****** ***, they **** **** ****** ** ** effect. ** **** ************ ******* ******** your ** *******, ***** ******* ** those ******** **** ** ********.

VLANs *** ***

*** ** *** ******* ***** *** often **** ** *********** ** ********** bandwidth ** ******* **** *** ***** used ** *********** **** ******* ** service. *** *** ** *** ** VLAN ** **** ******* ********. * surveillance ****, *** *******, *** ******* higher ******** ** * ***** **** general **** ** ***** *****.

Equipment ************

************ ***** ******** ******* ******** ** used, ** ********* ******** ***** ** configuration **********. *** **** ******** ** managed ******** (**** *****-******* *** ***** switches) ********* ***** *** ****-*******. ***** may *** ********* *************** *** ************ ********** **** ***********.

VLAN ********* *** ************

*** ***** *** ******* ******, ********* on *** ***********:

  • ***** *******:** *** ****** ***** *******, **** as ***** ******, ***** *** ********* not **** ** ***-**** ********* ******** without **** ******* *** **** ***** deployed. ****, ******* ** ******** ********* on *** **** ******** ** ******* office *****, ** ******** ***** ***** require ******* ** *** **, ****** cost.
  • ********* *******:**** ******* * *** **** ***** services, ***** *** **** ** ******* and ***** ** ***-***** *******, ***** are ******** ***********. ** ** *** uncommon *** ***** ********** ** *** one **** *** ****, *** *** VOIP *******, *** *** *** ********, to ****** ******* ***** ********. ******* between *** ******* ****** **** *** security **** ** ******** ********, ** give ****** ******* ****** ** *****.
  • ********* ******* ******* *****:**** ***** * *********, ******** ****** network, ***** *** ***** *** ****** or *******. ** ****** **** *** general *** ** ******, *** *** separate ******** ******** *** ********* *** router.
  • ********* ******* **** *****:** ***** *******, ******** ***** *** be ****, **** **** ***** * dedicated ******** *******. ******* *** ******* are ****** ** ******** *****, ** prevent *** ********* ********* ** ***** on ********** ******** ******** ****** *** cameras' *** **********. **** ****** ******* is ******** ** *** *******, ** well, **** ************* ********* ***** * separate ****, ** ****** ******* *** create ********* ******* ***** *** ****** issues ** *** ************ ******.

***********

***** *** ***** ** ***** ** significantly ******** ** ****, **** ** have **** ********** ** ****** ****, preventing ************ ****** ** *****. *******, VLANs *** *** * ******* ** network ********, *** ****** ** ******** only **** *********. ******** * ***** converged ******* ******* **** ************* *** coordination, *** ****** *****.

**** **** *********

**** ***** ******** *******

Comments (16)

Great info!

Agree: 1
Disagree
Informative
Unhelpful
Funny

It would be interesting if you could cover Avaya's Fabric Connect networking technology that can help speed network implementation which have a large number of network cameras. (P.S. my current company is also an Avaya Platinum partner)

Agree
Disagree
Informative
Unhelpful
Funny

Thanks, John. One question about:

One of the reasons VLANs are often seen as restricting or allocating bandwidth is because they are often used in conjunction with quality of service. QoS may be set by VLAN in most managed switches. A surveillance VLAN, for example, may receive higher priority as a whole than general data or voice VLANs.

If the surveillance VLAN consists of a static group of ports on a non-blocking switch, how would having a higher priority improve its performance over the voice VLAN, also with its own discrete non-blocking ports?

Agree
Disagree
Informative
Unhelpful
Funny

Great question and also the most common argument for not implementing QoS.

Congestion, (#2). If you do check out this link please keep in mind (not mentioned in the linked article) that we will have other devices connected to the switch, devices that possibly consume much more bandwidth /resources than IP cameras. There may also be access or distribution switches connected to distribution or core switches, and the network congestion will be exacerbated by the aggregate traffic from the devices connected to those feeder switches. At some point our network will experience data burst / congestion / etc & we want to decide how traffic is handled.

Agree
Disagree
Informative: 1
Unhelpful: 1
Funny

How would this work for PCI compliance?

Agree
Disagree
Informative
Unhelpful
Funny

I've installed POS equipment and networking equipment for several of the largest retailers and they all used VLANs to separate their POS equipment. All of them had specific ports that the POS equipment needed to be connected to.

Agree
Disagree
Informative: 2
Unhelpful
Funny

Thanks John

What about VLAN Hopping? Would that not be a security concern for those larger retailers?

Agree: 1
Disagree
Informative
Unhelpful
Funny

Yes, and while I was not hardening the equipment for these retailers I can only guess that they implement security best practices to help mitigate double tagging & switch spoofing.

Agree
Disagree
Informative: 2
Unhelpful
Funny

Great article and surely will help move the needle forward for the industry. The more our industry understands network security, the better.

Agree: 1
Disagree
Informative
Unhelpful
Funny

how do we route two VLANs together to allow certain individuals on other
VLANs access to the surveillance network

Agree
Disagree
Informative
Unhelpful
Funny

It depends on the switches and routers in the network. Layer 3 switches can route between VLANs, or if using layer 2 switches, the router will route all interVLAN traffic. Depending on the brand and capabilities of the equipment, you can grant access between VLANs via firewall rules or ACLs. 

Agree: 1
Disagree
Informative
Unhelpful
Funny

It is smart to consider VLANs for large enterprise VMS. VLAN quickly identifies and manages multiple locations.

Agree
Disagree
Informative
Unhelpful
Funny

It was very interesting

Agree
Disagree
Informative
Unhelpful
Funny

Hello,

I wasn't able to access PoE Guide for IP Video Surveillance.

However the videos provide excellent information.

Agree
Disagree
Informative
Unhelpful
Funny

It's fixed now - PoE Guide for IP Video Surveillance sorry about that, and thanks for letting us know.

Agree
Disagree
Informative
Unhelpful
Funny

I wonder if this is on topic?

Can i plug a camera into a channel of an NVR, send the signal over a Nano Station bridge and only use the IP address of the Camera? or do i need to add the devices too?

Agree
Disagree
Informative
Unhelpful
Funny
Login to read this IPVM report.
Why do I need to log in?
IPVM conducts reporting, tutorials and software funded by subscriber's payments enabling us to offer the most independent, accurate and in-depth information.
Loading Related Reports