PHYSICAL SECURITY & BUILDING SYSTEMS
Connect multi-site access control and CCTV without exposing every appliance.
Join authorised access-control panels, video systems, building-management controllers and other Ethernet appliances across sites through an encrypted Layer 2 fabric—without publishing their interfaces directly to the internet or maintaining a separate VPN tunnel for every location pair. DC Core can also supply preconfigured bridge appliances for installer-led deployments.
SHORT ANSWER
Attach each physical-security network to an authorised local fabric agent, then carry only that defined Ethernet environment between sites.
Place the access-control, CCTV or building-system appliances on an appropriate local bridge or dedicated segment. The DC Core agent connects that bridge through one TAP attachment to approved remote agents. Central authorises participating agents and discovered source MAC locations; approved agents then exchange Ethernet frames through encrypted, resilient relay paths. DC Core can provide a preconfigured plug-and-play bridge appliance for each site, allowing the installer to connect the designated Ethernet segment and approved uplink without building an individual VPN. The appliances continue using their existing Ethernet behaviour while their management interfaces remain behind local network controls.
Ethernet Fabric transports and governs the distributed Layer 2 connection. It does not automatically secure, patch or operate the cameras, door controllers, recorders, building controllers or their applications. Device lifecycle, credentials, local switching, safety behaviour and vendor support remain with the customer or physical-security integrator unless separately agreed.
SYSTEMS THAT MAY FIT
One network pattern for several building-technology estates.
The fabric is useful where the appliance or management platform genuinely requires Ethernet adjacency, discovery, broadcast or another Layer 2 behaviour across locations.
Panels, controllers and management services
Connect approved building-access segments to a central management environment while keeping controller interfaces off the public internet.
- Door and gate control networks
- Centralised administration where supported
Cameras, recorders and video platforms
Join selected CCTV or video-surveillance Ethernet environments to an authorised recorder or management site, subject to bandwidth, latency and vendor requirements.
- Distributed camera or recorder estates
- Traffic sizing before rollout
BMS, HVAC and energy controllers
Extend a controlled network path for supported building-management appliances without giving the wider corporate network implicit access to the segment.
- Building automation networks
- Remote monitoring and control platforms
Intercom, alarm and specialist Ethernet systems
Connect other vendor-supported Ethernet appliances where the protocol, failure behaviour and security boundary have been reviewed.
- Site-specific security technology
- Legacy or discovery-dependent devices
THE NETWORK PATH
Keep the building segment local; extend only the authorised fabric.
Do not start by flattening every branch LAN. Identify the exact appliances, controllers and management systems that need to share Ethernet, then isolate that fabric from general user and guest networks.
See how frames cross the fabric →- 01
Create a physical-security or building-systems zone
Place the in-scope appliances on a suitable local bridge, VLAN or dedicated network boundary according to the device, safety and integrator design.
- 02
Attach one agent or supplied bridge appliance per site
Use an existing supported agent or a preconfigured DC Core fabric bridge. The installer connects its designated Ethernet port, power and approved uplink; one attachment can participate with multiple authorised locations.
- 03
Approve agents and source MAC locations
Central validates participants, prevents duplicate MAC ownership and blocks unknown or conflicting identities until authority is resolved.
- 04
Carry frames through protected relay paths
Approved agents establish AES-256-GCM-protected sessions and use the selected automatic, failover, striped or redundant relay policy.
- 05
Monitor both the fabric and the application
Observe agent-to-agent connectivity and fabric events separately from camera health, door state, recording, alarms and other vendor-specific application outcomes.
PLUG-AND-PLAY FOR INSTALLERS
A preconfigured bridge at each site, one governed fabric behind it.
DC Core can supply ready-to-install fabric bridge appliances for new or existing physical-security projects. This gives installers a repeatable hand-off without asking them to design and maintain a VPN mesh.
Configured for the agreed site and fabric
DC Core prepares the bridge for the customer, fabric and location so installers can follow one consistent connection plan rather than build a new VPN at every site.
Connect power, Ethernet and the approved uplink
The installer connects the designated building-system segment, power and agreed internet or private uplink using the project hand-off.
Commission the path with DC Core
DC Core checks fabric connectivity remotely, approves expected MAC locations and validates the required paths and selected resilience behaviour.
LAYER 2 OR A NARROWER PATH?
Use Ethernet adjacency only when the system needs it.
Some physical-security platforms need Layer 2 behaviours; others work better through a small number of routed services. Choose from the protocol and operating requirement, not from habit.
| Requirement | Likely pattern | Design question |
|---|---|---|
| Broadcast, multicast or local discovery must cross sites | Ethernet Fabric may be appropriate. | What traffic volume and failure behaviour will replication create across every authorised connection? |
| A central server needs a known IP service at each site | A routed private service path may be narrower. | Can access be limited to the required host, port and direction instead of extending the segment? |
| Vendor requires same-subnet or Layer 2 adjacency | Validate the requirement with a bounded fabric pilot. | Is the behaviour documented and supported across the expected latency and loss profile? |
| Administrator only needs a web console | Controlled application publishing may be sufficient. | Does the interface need direct device reach, or can a management service mediate access? |
| High-volume continuous CCTV streams | Capacity-led design is essential. | Measure aggregate bitrate, peak behaviour, latency tolerance and recorder placement before rollout. |
SECURITY & SAFETY CHECKS
A protected transport does not make a flat building network safe.
Extending Layer 2 can also extend broadcast reach and the potential impact of a compromised appliance. Preserve zones of trust and validate the system’s safe failure behaviour.
Keep security technology separate by function and risk
Do not bridge user, guest and building-system networks simply because the fabric can carry Ethernet. Apply local segmentation and control any route into management or corporate services.
Harden the appliances and management platform
Change default credentials, restrict administration, maintain supported firmware, protect recordings and personal data, and monitor vendor-specific security events.
Define local behaviour during WAN or relay loss
Door controllers, alarms, recorders and building systems need a safe local operating state. Confirm what remains available when the cross-site path, Central or a relay is unavailable.
Measure broadcast, multicast and video load
Known unicast is sent to its authorised destination, while broadcast and multicast replicate across authorised connections. Size the fabric and prevent unmanaged Layer 2 loops.
The NPSA network-connected security technology guidance highlights the cyber and data risks around video surveillance and access-control systems. The NCSC Connected Places principles recommend explicit zones of trust and critical security boundaries. The fabric should reinforce that architecture, not bypass it.
RESPONSIBILITY BOUNDARY
Separate fabric health from building-system health.
A working agent connection proves the transport path is available. It does not prove that a camera is recording, a door event reached the controller or an HVAC command was accepted.
| Area | DC Core Ethernet Fabric | Customer or system integrator |
|---|---|---|
| Fabric membership | Authorised agents, MAC-location authority and protected agent-to-agent sessions. | Approve sites and appliances, maintain accurate ownership and report expected device moves. |
| Local network | Fabric TAP, agreed agent-side attachment and supplied bridge appliance where agreed. | Switching, VLANs, power, cabling, loop prevention, firewalls and separation from other local networks. |
| Appliances | Standard Ethernet transport for in-scope devices. | Firmware, credentials, configuration, vendor support, physical protection and secure lifecycle. |
| Application | Connectivity telemetry and relevant fabric events. | VMS, access-control or BMS availability, alarms, recording, application users and business workflows. |
| Safety & recovery | Selected relay resilience and documented fabric outage behaviour. | Safe door, alarm and building operation; local fallback; incident procedures and recovery acceptance. |
TWO-SITE PILOT
Prove the protocol, capacity and failure behaviour first.
Choose two representative locations and one application workflow. Keep the existing path available until the fabric and local fallback have been accepted.
- 01 / INVENTORY
Map devices and traffic
Record MACs, protocols, discovery, streams, controllers, management stations and current exposure.
- 02 / SEGMENT
Define the local zone
Choose the bridge or VLAN, agent position and routes that must remain outside the fabric.
- 03 / CONNECT
Authorise two agents
Attach the TAPs, approve MAC locations and validate expected unicast, broadcast and multicast behaviour.
- 04 / TEST
Exercise real workflows
Check application operation, bandwidth, latency, relay loss, Central outage and safe local fallback.
COMMON QUESTIONS
Multi-site building-system network FAQs.
Vendor protocols and site safety requirements determine the final design.
Can DC Core supply the onsite Ethernet bridge device?
Yes. DC Core can provide a preconfigured fabric bridge appliance for an installer-led deployment. The agreed hand-off identifies the power, uplink and building-system Ethernet connections, while DC Core handles fabric onboarding and remote path validation.
Do the cameras or door controllers need public IP addresses?
No. In the intended design, appliances remain on the local building or physical-security network and use the fabric attachment. The local agent needs the agreed connectivity to DC Core, but individual appliance interfaces do not need to be published directly to the internet.
Does every site need a VPN to every other site?
No. Each participating DC Core agent uses one local TAP attachment that can connect to multiple authorised agents through the fabric. You manage fabric membership and resilience policy instead of maintaining a separate point-to-point tunnel and adapter for every site pair.
Can Ethernet Fabric carry CCTV video?
It can transport Ethernet frames for authorised devices, but suitability depends on aggregate bitrate, stream direction, recorder placement, latency, packet-loss tolerance and relay capacity. Measure real traffic in a two-site pilot before wider deployment.
Does MAC authorisation replace device authentication?
No. MAC-location authority helps govern which discovered source identities may use the fabric and detects conflicts or unexpected moves. Devices and applications still need suitable credentials, secure protocols, supported firmware and role-based administration.
What happens if Central is unavailable?
Previously authorised MAC mappings and active sessions can remain available in agent memory during a temporary Central outage. New devices and new connectivity remain blocked until authority returns. Building systems still need a safe local mode for wider network or power failure.
RELATED EVALUATION
Review the fabric, access model and operating boundary.
START WITH TWO LOCATIONS
Show us the building systems that need to communicate.
Share the sites, appliance types, current segments, management platform, Layer 2 behaviours, approximate traffic and whether installers need supplied bridge devices. We’ll map a bounded Ethernet Fabric pilot and state what remains with your physical-security or building-systems integrator.