How to Segment Surveillance Networks Safely

Surveillance network segmentation isolates video infrastructure from general enterprise traffic using dedicated VLANs, strict ACLs, and separate management paths. This reduces the risk of lateral movement and protects secure cameras from common intrusions.
- Isolate surveillance traffic on dedicated VLANs to limit lateral movement.
- Use strict access control lists to block unnecessary ports and protocols.
- Maintain separate management networks for cameras and enterprise systems.
- Verify segmentation with packet captures and access tests after configuration.
Why Isolate Video Infrastructure
Video systems handle continuous streams of data and often run older firmware. They are also physically accessible, which increases the risk of tampering. When surveillance gear shares the same network as corporate email or finance systems, a compromised camera can become a foothold for attackers.
Segmentation splits the network into logical zones. Each zone has its own rules for who can talk to whom. This approach limits damage. If an attacker gains access to a camera, they cannot immediately reach the server where financial records live.
The goal is not to make the network unbreachable. The goal is to make the path from the camera to the corporate core long, difficult, and monitored.
Consider a standard retail environment. The cameras monitor the floor and the back office. The NVR stores footage for thirty days. The corporate network hosts the point-of-sale terminals and the accounting software. If a vendor updates a camera firmware with a known vulnerability, the attacker gains a foothold on the local switch. Without segmentation, they can ping the accounting server, sniff the traffic between the POS terminals, or install a reverse shell. With proper VLANs and ACLs, the attacker is trapped in the camera VLAN. They cannot reach the storage VLAN unless they break the ACL rules, and they cannot reach the corporate VLAN unless they bypass the firewall.
This isolation also protects data integrity. If a camera is compromised, the attacker cannot delete footage stored on the NVR. They cannot alter metadata or export video to an external server. The damage is contained to the device itself.
Prerequisites Before Configuration
Before touching the switch configuration, you need a clear map of the physical layer. Identify every switch, camera, and NVR in the video system. Note the physical port used for each device. Create a simple spreadsheet with columns for device name, make, model, firmware version, IP address, switch, port, and VLAN assignment. This document becomes your reference point when troubleshooting or onboarding new staff.
You also need a plan for management access. Decide how engineers will log in to configure cameras. Do not use the same credentials as the enterprise directory for all devices. Create a separate set of admin accounts for the video network. Use strong passwords and store them in a password manager. Consider using a jump host or a bastion server for remote access. This adds an extra layer of authentication and provides a log trail of who accessed the network.
Inventory the firmware versions. Do not attempt segmentation on a system where half the cameras are on unsupported software. Update what you can before changing network rules. Some cameras require specific firmware versions to support certain features, such as VLAN tagging or advanced ACL support. Check the manufacturer documentation for compatibility.
Confirm that the NVR supports the VLAN tagging method you plan to use. Some older recorders require untagged traffic. Others handle tagged frames without issue. Test this with a single camera before rolling out the configuration. If the NVR drops frames when they arrive with a VLAN tag, you will need to configure the switch port to untag the traffic before passing it to the NVR.
Verify that your switches support the required features. You need managed switches with VLAN support, ACL capabilities, and logging functions. Unmanaged switches cannot enforce these rules. They simply pass traffic. If you are using a mix of managed and unmanaged switches, you must plan your topology carefully. Place unmanaged switches only in the camera VLAN, where they do not need to enforce security policies.
Step-by-Step Segmentation Process
-
Create dedicated VLANs for each zone.
Build a VLAN for the camera layer. Create another for the NVR and storage. Add a third for out-of-band management. This separation stops direct camera-to-server communication if you do not want it.
Reason: Physical separation of traffic types prevents accidental interference. It also makes troubleshooting easier because you know exactly which switch port belongs to which VLAN. For example, if you have a problem with video latency, you can isolate the issue to the camera VLAN. You do not need to check the corporate network for interference.
-
Assign cameras to the camera VLAN.
Connect each camera to a switch port and set that port to access mode for the camera VLAN. Do not leave ports in trunk mode unless required.
Reason: Access mode simplifies the configuration. It prevents the camera from seeing traffic intended for other zones. It also reduces the chance of a misconfiguration where a camera transmits untagged frames into a trunk. If a camera is set to access mode, it cannot send traffic to any other VLAN without an explicit rule. This simplifies the ACL logic on the switch.
-
Configure the NVR to the storage VLAN.
Move the NVR to its own VLAN. If the NVR needs to talk to multiple cameras, configure the switch ports to trunk the camera VLAN and the storage VLAN.
Reason: The NVR is the aggregation point. It needs access to video streams. Keeping it on a separate VLAN from the cameras prevents direct user access to the recorder from the office network. It also allows you to apply specific ACL rules to the NVR. For example, you can allow only the camera VLAN to send RTSP traffic to the NVR. You can block all other traffic from reaching the NVR.
-
Set up a management VLAN for out-of-band access.
Create a VLAN that is not used for video data. Use it for SSH, HTTP, and SNMP access to devices. Do not allow this VLAN to traverse the video VLANs.
Reason: Management traffic is sensitive. It contains credentials and configuration data. Isolating it from video streams prevents a compromised camera from intercepting management packets. This VLAN should be accessible only from specific workstations or jump hosts. You can apply strict ACL rules to this VLAN to ensure that only authorized users can access the devices.
-
Apply access control lists at the switch level.
Write ACLs that allow only the necessary ports. For example, allow UDP 554 for RTSP if the NVR uses it. Allow TCP 443 for HTTPS management. Block everything else by default.
Reason: ACLs act as a gatekeeper. They enforce the principle of least privilege. If a camera tries to send traffic to the enterprise network, the ACL drops it. You should apply these ACLs to both the ingress and egress directions. For example, on the camera VLAN, allow outgoing RTSP traffic to the NVR. Block all other outgoing traffic. On the NVR VLAN, allow incoming RTSP traffic from the camera VLAN. Block all other incoming traffic.
-
Segment the enterprise side with firewall rules.
Configure the firewall between the video VLANs and the corporate network. Allow only the specific IPs that need access. For example, allow the NVR IP to talk to the enterprise DNS server for time synchronization.
Reason: The switch ACLs handle internal traffic. The firewall handles traffic between the video zone and the rest of the business. You need both layers to be safe. The firewall provides an additional layer of defense. If a switch misconfiguration allows traffic to pass, the firewall can still block it. You should also use stateful inspection to track connections and drop invalid packets.
-
Disable unnecessary services on cameras and NVRs.
Turn off Telnet, FTP, and UPnP if you do not use them. Enable only SSH or HTTPS for management. Disable auto-discovery protocols if they are not required.
Reason: Every open service is a potential entry point. Disabling unused services reduces the attack surface. It also makes log analysis simpler because you know which protocols are active. For example, if you have Telnet disabled, you do not need to monitor for Telnet authentication failures. You can focus your monitoring on SSH and HTTPS.
-
Implement logging and monitoring.
Forward switch logs and NVR logs to a central server. Use a SIEM tool if available. Set alerts for repeated failed login attempts on camera devices.
Reason: Segmentation is not a one-time task. You need visibility. If an attacker tries to bypass the segmentation, you want to know immediately. You should also monitor for unusual traffic patterns. For example, if a camera suddenly starts sending large amounts of traffic to an external IP, it may be exfiltrating data. Set alerts for this type of activity.
-
Document the final configuration.
Save the switch configurations. Record the VLAN IDs, ACLs, and firewall rules. Keep this document in a secure location.
Reason: If a network engineer leaves, you need to understand the setup. Documentation prevents accidental changes that could break the video system. You should also version control your documentation. Keep a history of changes so you can roll back if a new configuration causes problems.
Common Mistakes to Avoid
Trunking all VLANs to every switch port.
This is the most common error. If a switch port carries all VLANs, a misconfigured camera can send frames to the wrong zone. Use access mode for endpoints and trunk mode only for uplinks. For example, if you have a switch with four ports, and two of them connect to cameras, set those two ports to access mode for the camera VLAN. Set the other two ports to trunk mode for the camera and storage VLANs.
Using the same VLAN for cameras and management.
Management traffic is sensitive. Mixing it with video streams makes it harder to secure. Keep them separate. If you use the same VLAN for cameras and management, an attacker who compromises a camera can access the management interface of the NVR. They can change the configuration, disable logging, or export footage.
Forgetting about the physical layer.
A camera plugged into a desk port is a segmentation failure. Use managed switches and label the ports. If a user plugs a camera into a corporate switch port, the segmentation is broken. You should use physical port security on the switch to prevent unauthorized devices from connecting. For example, you can limit the number of MAC addresses allowed on a port. If a user plugs in a second device, the port will shut down.
Ignoring the NVR as a target.
The NVR is often the most valuable asset. It stores footage. If an attacker gains access, they can delete or copy data. Treat the NVR with the same care as a database server. Apply strong access controls, encrypt storage, and monitor for unauthorized access. You should also configure the NVR to send logs to a central server. This ensures that if the NVR is compromised, you still have a record of the attack.
Not testing after configuration.
Many engineers apply the rules and walk away. They do not verify that the segmentation holds. Test it. Use a packet capture tool to verify that traffic is being blocked as expected. Use a login test to verify that unauthorized users cannot access the devices.
Verification and Testing
Run a packet capture from a workstation on the corporate network. Try to reach a camera IP. The request should fail. If the request succeeds, check the switch configuration. Ensure that the camera is on the correct VLAN and that the ACLs are blocking the traffic.
From the NVR, try to reach a corporate IP that is not allowed. The firewall should block the connection. Check the firewall logs to confirm that the connection was denied. You should also test the reverse direction. From the corporate network, try to reach the NVR. The firewall should block the connection if you do not want direct access to the NVR from the office network.
Check the switch logs. Look for port flaps or authentication failures. If you see unexpected activity, investigate immediately. Port flaps can indicate a physical connection problem or a device that is being repeatedly powered on and off. Authentication failures can indicate an attacker trying to guess credentials.
Use a tool like Wireshark to inspect frames. Verify that camera traffic is tagged correctly. Confirm that no untagged frames are crossing VLAN boundaries. If you see untagged frames on a trunk port, check the switch configuration. Ensure that the port is set to trunk mode and that the correct VLANs are allowed.
Test the management path. Log in to a camera from the management VLAN. Confirm that you cannot log in from the corporate VLAN. You should also test the firewall rules. From the corporate network, try to access the camera management interface. The firewall should block the connection.
If any test fails, adjust the rules. Do not assume the configuration is correct until you have proven it works. You should also perform a penetration test. Use a tool like Nmap to scan the video VLANs. Check for open ports and services. This will help you identify any misconfigurations that you may have missed.
Table: Recommended VLAN Structure
| Zone | VLAN ID Example | Devices | Allowed Traffic |
|---|---|---|---|
| Camera Layer | 100 | IP cameras, PTZ controllers | RTSP, ONVIF, Management |
| Storage Layer | 200 | NVR, VMS, Backup | Video streams, Logs |
| Management | 300 | Engineering laptops, Jump hosts | SSH, HTTPS, SNMP |
| Enterprise | 10 | Workstations, Servers | DNS, Time, Approved APIs |
Final Checks Before Go-Live
Review the ACLs one last time. Ensure the deny-any rule is at the end of the list. If you do not have a deny-any rule at the end, traffic that does not match any other rule will be allowed. This can create a security hole.
Check that the firewall rules match the switch VLANs. The firewall should be configured to block all traffic between the video VLANs and the corporate network, except for the specific IPs and ports that you have allowed. You should also configure the firewall to log all denied connections. This will help you identify any attacks or misconfigurations.
Confirm that all devices have unique IP addresses. Duplicate IP addresses can cause communication problems. You should also check that the subnet masks are correct. If a camera is on a different subnet than the NVR, it will not be able to communicate with it.
Verify that the time synchronization source is reachable from the video VLANs. If the cameras and NVR do not have the correct time, the logs will be inaccurate. This can make it difficult to correlate events. You should configure the devices to use a reliable NTP server.
Save the configuration. Schedule a backup. You should also create a rollback plan. If the new configuration causes problems, you need to be able to restore the previous configuration quickly. Keep a copy of the old configuration in a secure location.
Segmentation is a moving target. As you add devices or change the corporate network, update the rules. Keep the documentation current. A segmented network is a maintained network. You should also review the configuration regularly. Check for any changes that have been made by other engineers or vendors. Update the documentation to reflect these changes.
Frequently asked questions
Can I use the same switch for video and corporate traffic?
You can use the same physical switch, but you must configure VLANs to isolate the traffic. Do not rely on physical separation if you are using a shared switch.
Do I need a separate firewall for the video network?
A separate firewall is not always required, but a dedicated firewall or a dedicated firewall rule set improves security. It isolates the video zone from the corporate network.
How do I handle cameras that need internet access?
Most cameras do not need direct internet access. If they do, route that traffic through a dedicated proxy or firewall. Do not give cameras direct access to the corporate internet.
What if my NVR is on the same subnet as the cameras?
This is a segmentation failure. Move the NVR to a different VLAN. If you cannot move it, apply strict ACLs to limit the NVR's access.
How often should I review the segmentation?
Review it quarterly or after any major network change. New devices can introduce risks. Keep the documentation up to date.


