PHYSICAL SECURITY & BUILDING SYSTEMS

Connect multi-site access control and CCTV without exposing every appliance.

Join authorised access-control panels, video systems, building-management controllers and other Ethernet appliances across sites through an encrypted Layer 2 fabric—without publishing their interfaces directly to the internet or maintaining a separate VPN tunnel for every location pair. DC Core can also supply preconfigured bridge appliances for installer-led deployments.

By DC Core engineeringReviewed 22 August 202610-minute read

SHORT ANSWER

Attach each physical-security network to an authorised local fabric agent, then carry only that defined Ethernet environment between sites.

Place the access-control, CCTV or building-system appliances on an appropriate local bridge or dedicated segment. The DC Core agent connects that bridge through one TAP attachment to approved remote agents. Central authorises participating agents and discovered source MAC locations; approved agents then exchange Ethernet frames through encrypted, resilient relay paths. DC Core can provide a preconfigured plug-and-play bridge appliance for each site, allowing the installer to connect the designated Ethernet segment and approved uplink without building an individual VPN. The appliances continue using their existing Ethernet behaviour while their management interfaces remain behind local network controls.

IMPORTANT BOUNDARY

Ethernet Fabric transports and governs the distributed Layer 2 connection. It does not automatically secure, patch or operate the cameras, door controllers, recorders, building controllers or their applications. Device lifecycle, credentials, local switching, safety behaviour and vendor support remain with the customer or physical-security integrator unless separately agreed.

SYSTEMS THAT MAY FIT

One network pattern for several building-technology estates.

The fabric is useful where the appliance or management platform genuinely requires Ethernet adjacency, discovery, broadcast or another Layer 2 behaviour across locations.

VIDEO SECURITY

Cameras, recorders and video platforms

Join selected CCTV or video-surveillance Ethernet environments to an authorised recorder or management site, subject to bandwidth, latency and vendor requirements.

  • Distributed camera or recorder estates
  • Traffic sizing before rollout
BUILDING MANAGEMENT

BMS, HVAC and energy controllers

Extend a controlled network path for supported building-management appliances without giving the wider corporate network implicit access to the segment.

  • Building automation networks
  • Remote monitoring and control platforms
OTHER APPLIANCES

Intercom, alarm and specialist Ethernet systems

Connect other vendor-supported Ethernet appliances where the protocol, failure behaviour and security boundary have been reviewed.

  • Site-specific security technology
  • Legacy or discovery-dependent devices

THE NETWORK PATH

Keep the building segment local; extend only the authorised fabric.

Do not start by flattening every branch LAN. Identify the exact appliances, controllers and management systems that need to share Ethernet, then isolate that fabric from general user and guest networks.

See how frames cross the fabric
  1. 01

    Create a physical-security or building-systems zone

    Place the in-scope appliances on a suitable local bridge, VLAN or dedicated network boundary according to the device, safety and integrator design.

  2. 02

    Attach one agent or supplied bridge appliance per site

    Use an existing supported agent or a preconfigured DC Core fabric bridge. The installer connects its designated Ethernet port, power and approved uplink; one attachment can participate with multiple authorised locations.

  3. 03

    Approve agents and source MAC locations

    Central validates participants, prevents duplicate MAC ownership and blocks unknown or conflicting identities until authority is resolved.

  4. 04

    Carry frames through protected relay paths

    Approved agents establish AES-256-GCM-protected sessions and use the selected automatic, failover, striped or redundant relay policy.

  5. 05

    Monitor both the fabric and the application

    Observe agent-to-agent connectivity and fabric events separately from camera health, door state, recording, alarms and other vendor-specific application outcomes.

PLUG-AND-PLAY FOR INSTALLERS

A preconfigured bridge at each site, one governed fabric behind it.

DC Core can supply ready-to-install fabric bridge appliances for new or existing physical-security projects. This gives installers a repeatable hand-off without asking them to design and maintain a VPN mesh.

02 / INSTALL

Connect power, Ethernet and the approved uplink

The installer connects the designated building-system segment, power and agreed internet or private uplink using the project hand-off.

03 / VALIDATE

Commission the path with DC Core

DC Core checks fabric connectivity remotely, approves expected MAC locations and validates the required paths and selected resilience behaviour.

WHAT “PLUG AND PLAY” MEANSThe bridge can arrive preconfigured for the agreed fabric. The installer and customer still provide suitable power, cabling, switching, VLAN or bridge placement, internet uplink, physical protection and any safety or vendor sign-off required at the site.

LAYER 2 OR A NARROWER PATH?

Use Ethernet adjacency only when the system needs it.

Some physical-security platforms need Layer 2 behaviours; others work better through a small number of routed services. Choose from the protocol and operating requirement, not from habit.

RequirementLikely patternDesign question
Broadcast, multicast or local discovery must cross sitesEthernet Fabric may be appropriate.What traffic volume and failure behaviour will replication create across every authorised connection?
A central server needs a known IP service at each siteA routed private service path may be narrower.Can access be limited to the required host, port and direction instead of extending the segment?
Vendor requires same-subnet or Layer 2 adjacencyValidate the requirement with a bounded fabric pilot.Is the behaviour documented and supported across the expected latency and loss profile?
Administrator only needs a web consoleControlled application publishing may be sufficient.Does the interface need direct device reach, or can a management service mediate access?
High-volume continuous CCTV streamsCapacity-led design is essential.Measure aggregate bitrate, peak behaviour, latency tolerance and recorder placement before rollout.

SECURITY & SAFETY CHECKS

A protected transport does not make a flat building network safe.

Extending Layer 2 can also extend broadcast reach and the potential impact of a compromised appliance. Preserve zones of trust and validate the system’s safe failure behaviour.

SEGMENTATION

Keep security technology separate by function and risk

Do not bridge user, guest and building-system networks simply because the fabric can carry Ethernet. Apply local segmentation and control any route into management or corporate services.

DEVICE SECURITY

Harden the appliances and management platform

Change default credentials, restrict administration, maintain supported firmware, protect recordings and personal data, and monitor vendor-specific security events.

AVAILABILITY

Define local behaviour during WAN or relay loss

Door controllers, alarms, recorders and building systems need a safe local operating state. Confirm what remains available when the cross-site path, Central or a relay is unavailable.

LAYER 2 SCALE

Measure broadcast, multicast and video load

Known unicast is sent to its authorised destination, while broadcast and multicast replicate across authorised connections. Size the fabric and prevent unmanaged Layer 2 loops.

UK GUIDANCE

The NPSA network-connected security technology guidance highlights the cyber and data risks around video surveillance and access-control systems. The NCSC Connected Places principles recommend explicit zones of trust and critical security boundaries. The fabric should reinforce that architecture, not bypass it.

RESPONSIBILITY BOUNDARY

Separate fabric health from building-system health.

A working agent connection proves the transport path is available. It does not prove that a camera is recording, a door event reached the controller or an HVAC command was accepted.

AreaDC Core Ethernet FabricCustomer or system integrator
Fabric membershipAuthorised agents, MAC-location authority and protected agent-to-agent sessions.Approve sites and appliances, maintain accurate ownership and report expected device moves.
Local networkFabric TAP, agreed agent-side attachment and supplied bridge appliance where agreed.Switching, VLANs, power, cabling, loop prevention, firewalls and separation from other local networks.
AppliancesStandard Ethernet transport for in-scope devices.Firmware, credentials, configuration, vendor support, physical protection and secure lifecycle.
ApplicationConnectivity telemetry and relevant fabric events.VMS, access-control or BMS availability, alarms, recording, application users and business workflows.
Safety & recoverySelected relay resilience and documented fabric outage behaviour.Safe door, alarm and building operation; local fallback; incident procedures and recovery acceptance.

TWO-SITE PILOT

Prove the protocol, capacity and failure behaviour first.

Choose two representative locations and one application workflow. Keep the existing path available until the fabric and local fallback have been accepted.

  1. 01 / INVENTORY

    Map devices and traffic

    Record MACs, protocols, discovery, streams, controllers, management stations and current exposure.

  2. 02 / SEGMENT

    Define the local zone

    Choose the bridge or VLAN, agent position and routes that must remain outside the fabric.

  3. 03 / CONNECT

    Authorise two agents

    Attach the TAPs, approve MAC locations and validate expected unicast, broadcast and multicast behaviour.

  4. 04 / TEST

    Exercise real workflows

    Check application operation, bandwidth, latency, relay loss, Central outage and safe local fallback.

COMMON QUESTIONS

Multi-site building-system network FAQs.

Vendor protocols and site safety requirements determine the final design.

Can DC Core supply the onsite Ethernet bridge device?

Yes. DC Core can provide a preconfigured fabric bridge appliance for an installer-led deployment. The agreed hand-off identifies the power, uplink and building-system Ethernet connections, while DC Core handles fabric onboarding and remote path validation.

Do the cameras or door controllers need public IP addresses?

No. In the intended design, appliances remain on the local building or physical-security network and use the fabric attachment. The local agent needs the agreed connectivity to DC Core, but individual appliance interfaces do not need to be published directly to the internet.

Does every site need a VPN to every other site?

No. Each participating DC Core agent uses one local TAP attachment that can connect to multiple authorised agents through the fabric. You manage fabric membership and resilience policy instead of maintaining a separate point-to-point tunnel and adapter for every site pair.

Can Ethernet Fabric carry CCTV video?

It can transport Ethernet frames for authorised devices, but suitability depends on aggregate bitrate, stream direction, recorder placement, latency, packet-loss tolerance and relay capacity. Measure real traffic in a two-site pilot before wider deployment.

Does MAC authorisation replace device authentication?

No. MAC-location authority helps govern which discovered source identities may use the fabric and detects conflicts or unexpected moves. Devices and applications still need suitable credentials, secure protocols, supported firmware and role-based administration.

What happens if Central is unavailable?

Previously authorised MAC mappings and active sessions can remain available in agent memory during a temporary Central outage. New devices and new connectivity remain blocked until authority returns. Building systems still need a safe local mode for wider network or power failure.

START WITH TWO LOCATIONS

Show us the building systems that need to communicate.

Share the sites, appliance types, current segments, management platform, Layer 2 behaviours, approximate traffic and whether installers need supplied bridge devices. We’ll map a bounded Ethernet Fabric pilot and state what remains with your physical-security or building-systems integrator.

Map two sites