PHYSICAL SECURITY & BUILDING SYSTEMS

Connect multi-site access control and CCTV without exposing every appliance.

Join authorised access-control panels, video systems, building-management controllers and other Ethernet appliances across sites through an encrypted Layer 2 fabric—without publishing their interfaces directly to the internet or maintaining a separate VPN tunnel for every location pair. DC Core can also supply preconfigured bridge appliances for installer-led deployments.

By DC Core engineeringReviewed 22 August 20268-minute read

SHORT ANSWER

Attach each physical-security network to an authorised local fabric agent, then carry only that defined Ethernet environment between sites.

Place the access-control, CCTV or building-system appliances on an appropriate local bridge or dedicated segment. The DC Core agent connects that bridge through one TAP attachment to approved remote agents. Central authorises participating agents and discovered source MAC locations; approved agents then exchange Ethernet frames through encrypted, resilient relay paths. DC Core can provide a preconfigured plug-and-play bridge appliance for each site, allowing the installer to connect the designated Ethernet segment and approved uplink without building an individual VPN. The appliances continue using their existing Ethernet behaviour while their management interfaces remain behind local network controls.

IMPORTANT BOUNDARY

Ethernet Fabric transports and governs the distributed Layer 2 connection. It does not automatically secure, patch or operate the cameras, door controllers, recorders, building controllers or their applications. Device lifecycle, credentials, local switching, safety behaviour and vendor support remain with the customer or physical-security integrator unless separately agreed.

THE NETWORK PATH

Keep the building segment local; extend only the authorised fabric.

Do not start by flattening every branch LAN. Identify the exact appliances, controllers and management systems that need to share Ethernet, then isolate that fabric from general user and guest networks.

See how frames cross the fabric
  1. 01

    Create a physical-security or building-systems zone

    Place the in-scope appliances on a suitable local bridge, VLAN or dedicated network boundary according to the device, safety and integrator design.

  2. 02

    Attach one agent or supplied bridge appliance per site

    Use an existing supported agent or a preconfigured DC Core fabric bridge. The installer connects its designated Ethernet port, power and approved uplink; one attachment can participate with multiple authorised locations.

  3. 03

    Approve agents and source MAC locations

    Central validates participants, prevents duplicate MAC ownership and blocks unknown or conflicting identities until authority is resolved.

  4. 04

    Carry frames through protected relay paths

    Approved agents establish AES-256-GCM-protected sessions and use the selected automatic, failover, striped or redundant relay policy.

  5. 05

    Monitor both the fabric and the application

    Observe agent-to-agent connectivity and fabric events separately from camera health, door state, recording, alarms and other vendor-specific application outcomes.

PLUG-AND-PLAY FOR INSTALLERS

A preconfigured bridge at each site, one governed fabric behind it.

DC Core can supply ready-to-install fabric bridge appliances for new or existing physical-security projects. This gives installers a repeatable hand-off without asking them to design and maintain a VPN mesh.

02 / INSTALL

Connect power, Ethernet and the approved uplink

The installer connects the designated building-system segment, power and agreed internet or private uplink using the project hand-off.

03 / VALIDATE

Commission the path with DC Core

DC Core checks fabric connectivity remotely, approves expected MAC locations and validates the required paths and selected resilience behaviour.

WHAT “PLUG AND PLAY” MEANSThe bridge can arrive preconfigured for the agreed fabric. The installer and customer still provide suitable power, cabling, switching, VLAN or bridge placement, internet uplink, physical protection and any safety or vendor sign-off required at the site.

LAYER 2 OR A NARROWER PATH?

Use Ethernet adjacency only when the system needs it.

Some physical-security platforms need Layer 2 behaviours; others work better through a small number of routed services. Choose from the protocol and operating requirement, not from habit.

Scroll sideways to compare all columns →

RequirementLikely patternDesign question
Broadcast, multicast or local discovery must cross sitesEthernet Fabric may be appropriate.What traffic volume and failure behaviour will replication create across every authorised connection?
A central server needs a known IP service at each siteA routed private service path may be narrower.Can access be limited to the required host, port and direction instead of extending the segment?
Vendor requires same-subnet or Layer 2 adjacencyValidate the requirement with a bounded fabric pilot.Is the behaviour documented and supported across the expected latency and loss profile?
Administrator only needs a web consoleControlled application publishing may be sufficient.Does the interface need direct device reach, or can a management service mediate access?
High-volume continuous CCTV streamsCapacity-led design is essential.Measure aggregate bitrate, peak behaviour, latency tolerance and recorder placement before rollout.

SECURITY & SAFETY CHECKS

A protected transport does not make a flat building network safe.

Extending Layer 2 can also extend broadcast reach and the potential impact of a compromised appliance. Preserve zones of trust and validate the system’s safe failure behaviour.

SEGMENTATION

Keep security technology separate by function and risk

Do not bridge user, guest and building-system networks simply because the fabric can carry Ethernet. Apply local segmentation and control any route into management or corporate services.

DEVICE SECURITY

Harden the appliances and management platform

Change default credentials, restrict administration, maintain supported firmware, protect recordings and personal data, and monitor vendor-specific security events.

AVAILABILITY

Define local behaviour during WAN or relay loss

Door controllers, alarms, recorders and building systems need a safe local operating state. Confirm what remains available when the cross-site path, Central or a relay is unavailable.

LAYER 2 SCALE

Measure broadcast, multicast and video load

Known unicast is sent to its authorised destination, while broadcast and multicast replicate across authorised connections. Size the fabric and prevent unmanaged Layer 2 loops.

UK GUIDANCE

The NPSA network-connected security technology guidance highlights the cyber and data risks around video surveillance and access-control systems. The NCSC Connected Places principles recommend explicit zones of trust and critical security boundaries. The fabric should reinforce that architecture, not bypass it.

RESPONSIBILITY BOUNDARY

Separate fabric health from building-system health.

A working agent connection proves the transport path is available. It does not prove that a camera is recording, a door event reached the controller or an HVAC command was accepted.

Scroll sideways to compare all columns →

AreaDC Core Ethernet FabricCustomer or system integrator
Fabric membershipAuthorised agents, MAC-location authority and protected agent-to-agent sessions.Approve sites and appliances, maintain accurate ownership and report expected device moves.
Local networkFabric TAP, agreed agent-side attachment and supplied bridge appliance where agreed.Switching, VLANs, power, cabling, loop prevention, firewalls and separation from other local networks.
AppliancesStandard Ethernet transport for in-scope devices.Firmware, credentials, configuration, vendor support, physical protection and secure lifecycle.
ApplicationConnectivity telemetry and relevant fabric events.VMS, access-control or BMS availability, alarms, recording, application users and business workflows.
Safety & recoverySelected relay resilience and documented fabric outage behaviour.Safe door, alarm and building operation; local fallback; incident procedures and recovery acceptance.

TWO-SITE PILOT

Prove the protocol, capacity and failure behaviour first.

Choose two representative locations and one application workflow. Keep the existing path available until the fabric and local fallback have been accepted.

  1. 01 / INVENTORY

    Map devices and traffic

    Record MACs, protocols, discovery, streams, controllers, management stations and current exposure.

  2. 02 / SEGMENT

    Define the local zone

    Choose the bridge or VLAN, agent position and routes that must remain outside the fabric.

  3. 03 / CONNECT

    Authorise two agents

    Attach the TAPs, approve MAC locations and validate expected unicast, broadcast and multicast behaviour.

  4. 04 / TEST

    Exercise real workflows

    Check application operation, bandwidth, latency, relay loss, Central outage and safe local fallback.

START WITH TWO LOCATIONS

Show us the building systems that need to communicate.

Share the sites, appliance types, current segments, management platform, Layer 2 behaviours, approximate traffic and whether installers need supplied bridge devices. We’ll map a bounded Ethernet Fabric pilot and state what remains with your physical-security or building-systems integrator.

Map two sites