Security

Segmenting cameras and badge systems

Cameras, NVRs, badge panels, and door controllers belong on their own VLAN. They get a route to the recorder or the vendor cloud they actually use, and nothing else. They do not sit on the staff network. They do not sit on Guest. A second SSID named Cameras that lands on the office VLAN is not segmentation.

Updated 2026-09-24

Why this is a different job from guest Wi-Fi

Guest isolation stops a visitor laptop from reaching file shares. Camera and badge gear is the opposite problem. Those devices stay in the building for years, often with default passwords, skipped firmware, and a vendor remote path nobody documented.

When they share a VLAN with staff PCs, a cheap camera is a foothold on the same network as accounting. When they share Guest, a visitor can see or probe the same segment the NVR lives on. The guest article already said not to dump IoT onto Guest. This page is the actual split.

What “done” looks like

One VLAN for staff. One VLAN for guests. One VLAN for building devices: cameras, the NVR if it is on-site, badge controllers, and similar gear. The firewall allows that VLAN only where it must go.

On-site recording: cameras talk to the NVR. A small set of staff or a jump host can reach the NVR view. Cameras do not need a route to file servers, printers, or the UniFi console.

Cloud recording: cameras talk out to the vendor they are contracted with. That is still not a reason to put them on staff or Guest. Outbound to one vendor is not the same as unrestricted LAN access.

Badge and door gear talks to its controller or cloud. It does not need SMB to the file server. If a workstation must enroll fobs, give that one station a controlled path. Do not open the whole office to the panel.

A check that takes a few minutes

From a staff laptop, can you browse to a camera web UI by IP? From the guest SSID, can you? If either answers, the segment is not isolated.

From a camera or a spare port on that switch, can you reach a file share, a printer, or the firewall login? That is the other direction, and it is the one incident reports care about.

If you cannot name the VLAN those devices live on, that is the finding. Segmentation work starts with an inventory, not with a new SSID name.

What this page does not cover

It is not a camera buying guide. UniFi, Axis, a doorbell brand from a prior tenant: the VLAN rule is the same.

It is not a promise that Tailored Tech monitors every vendor cloud. Monitoring is the devices and paths in scope. A camera platform we cannot query is not watched because it is on a nice VLAN.

It is not a substitute for changing default passwords and taking the recorder off the public internet. Segmentation without those two is still a recorder anyone can find. Read the UniFi console article if the management UI is still published.

How Tailored Tech treats this

When the network is in scope we ask where cameras and badge gear live, whether those VLANs route to staff, and whether the recorder or controller is reachable from Guest or from the internet.

Fixing it is usually a defined change on the firewall and switch stack we already manage: a VLAN, a few rules, and a test from both sides. Multi-site or a recorder that has to stay reachable for a guard vendor takes a short project, not a standing mystery.

The guest Wi-Fi article is the visitor half. This is the building-device half. Do them as two checks, not one SSID rename.

Questions & answers

Questions on this topic

Short answers for buyers comparing options.

Can cameras just go on Guest so they are off corporate?

No. Guest is for visitors. Putting cameras there gives a lobby phone a path toward the NVR. Use a third VLAN.

We view cameras on our phones. Does a VLAN break that?

Not if you keep the path the vendor intended: the app to the cloud, or VPN plus the NVR. You do not need the camera subnet open to the whole LAN for a phone view to work.

Do badge systems follow the same rule?

Yes. Controllers and panels are long-lived devices with their own firmware problems. They get the building VLAN and a narrow path, not a seat on staff Wi-Fi.

Where does this live on a plan?

Wireless and network design sit in the Service Catalog under network work. Scope is confirmed in the agreement. One site with a known switch stack is usually a short project.

Want this applied to your environment?

Tell us how the business runs. We will map the model without a long pitch.

Start a conversation
Start a conversation