Network Access

Your guide to network connectivity, communications, VLANs, and topologies
Optigo Networks Network Access webinar with Distech Controls

The worlds of IT and Operational Technology (OT) are merging more and more these days as the Internet of Things grows in prominence. This collaboration between IT and OT is great, but there are still gaps in understanding that keep these worlds from fully working together.

To help, we teamed up with Distech Controls to create a webinar series on networking, for OT professionals. In this edition about Network Access, we dug into network connectivity, communications, VLANs, and topologies. Check out our webinar recording on Network Access, and read the recap below! You can also download the PDF handout of our presentation to refer back to later.

The webinar dug into a lot of topics, including:

We did talk a bit about the network access layer, Ethernet, Wi-Fi, hot spots and clients, and managed and unmanaged switches in this webinar. We covered it in much more depth in our Introduction to Networking session, though, so definitely give that a watch if you’re looking for a comprehensive explanation.

The main thing to understand from the network connectivity section is how different elements might be used to connect your network. This diagram outlines a simple network example. Here, you can trace the network management system, through the router or core switch, to an aggregation switch and network controller, edge switches, and various end devices. This diagram will be useful to refer back to as you learn more about topologies and VLANs!

Operational Technology network diagram

There are a few different forms of network communication, including unicast and broadcast messaging.

In computer networking, broadcasting refers to transmitting a packet that will be received by every device on the network. Broadcasting is different from unicast addressing, in which a device sends a message to one other device, identified by a unique IP address.

On BACnet networks, we can use unicast to mimic broadcast messaging, through a BACnet Broadcast Management Device (BBMD). You can broadcast within subnetworks, but not across the entire system of subnetworks. That would be far too hectic on a large system. Instead, messages sent to a BBMD will convert broadcasts into unicasts, which can be sent directly to switches in other subnetworks. From there, the switch can broadcast the message to the rest of the subnetwork. We actually have an entire blog post on BBMDs, if you’d like to learn more.

Operational Technology BBMD BACnet Broadcast Management Device

Operational Technology BACnet Broadcast Management Device BBMD

Virtual Local Area Networks (VLANs) are a great way to segment and isolate services on your network. If you have a variety of device types scattered across a series of different switches, you can separate those services using VLANs to assign and restrict communication access. You might do this for security purposes, if there are multiple services connected to the same switch.

In this case, for example, the lighting, CCTV, and access are all on their own VLANs. Although lighting and CCTV might be on the same switch, the devices on VLAN-10 are not accessible from VLAN-20 or VLAN-30.

Virtual Local Area Networks (VLANs)

It can also be useful to understand the difference between Access and Trunk. VLAN Access ports connect to devices, while VLAN Trunk ports connect multiple VLANs. This diagram helps illustrate that distinction.

Access and Trunk in Virutal Local Area Networks

You can configure and manage your VLANs through a graphical user interface (GUI), or through a command-line interface (CLI) if you’re comfortable with it.

Graphical User Interface and Command Line Interface

Finally, we covered different network topologies. There are many different topologies that you could consider for your network, including daisy-chain, ring, as well as home run or star. Note that the same building can use one topology to connect the switches and a different topology to connect the devices. You don’t need just one design to connect everything in your building, because there are pros and cons to each design.

Daisy-chaining is a solution that is low on cost. You don’t need big switches, and your distance from the switch isn’t too limited. Unfortunately, network performance is often low, it’s difficult to troubleshoot, port security is an issue, and there is no redundancy.

 

Daisy-chain networking

Daisy-chain networking

A ring topology does have redundancy. However, you’re limited in how many devices you can use, it requires more ports on a switch, and you’re limited on distance. It’s also more expensive to “close the ring” in your design.

 

Ring topology

Ring topology

Note that it’s often preferable to have many small daisy-chains, rather than having one long chain in a ring topology. 

Switch network topology

One large ring connecting many devices.

Switch network topology

Those same devices connected in a series of short daisy chains, instead.

Star and home run topologies come with a lot of benefits. You can enjoy port security, easier troubleshooting, higher network performance, and a simple installation process. While this solution does come with a higher price tag, more ports, and limited distance, it’s still our recommended solution. 

 

 

Switch network topology

Switch network topology

While you’re selecting a design topology, you might want to consider your need for redundancy. Redundancy is essentially a “back-up” system, so that you’re prepared for the unexpected. If a switch goes down, for example, aggregation switch redundancy means that you won’t suffer downtime. 

Optigo Networks Network Access webinar with Distech Controls

Spanning Tree Protocol (STP) is another way to ensure your network stays online. It’s used for breaking communication loops and recovering from failures. 

On an STP-enabled system, if there is a loop between two Ethernet ports, one port will pass traffic (in Active mode) and the other port will block traffic (in Standby mode). As soon as the loop breaks, the blocking port will begin passing traffic so that all of the devices in the ring will maintain Ethernet connectivity. This might get activated if a device in the loop is disconnected or malfunctions, for example. 

 

Spanning tree protocol

Spanning tree protocol


We hope you enjoyed this webinar! Be sure to check out our deep dives on Internet, Transport and Application, and Designing a Network with Distech Controls’ ECLYPSE and Optigo Connect next.

Recent Blog Posts

You’re in the design phase of a new building. Contractors and vendors are all coming at you with demands.

The consulting specifying engineer of today is venturing into totally new territory: Division 25.

If you’re tired of going on site to capture BACnet data, look no further than your JACE.

OT Networks Overview

The latest release from Visual BACnet brings huge convenience and time saving for users with JACE controllers.

Recent Projects

Coventry University

COVENTRY UNIVERSITY

Chris Goodman, the Senior BMS Technician at Coventry University, had broadcast storms that were happening more and more frequently. 

Ongoing construction due to Coventry’s campus expansion meant lots of new activity, with technicians installing new devices and making network changes. Already juggling these constant additions and alterations, Goodman and his small team then had to deal with the subsequent broadcast storms. As the broadcast storms became more frequent, Goodman and his team needed a solution.

Find out how Visual BACnet helped Chris solve the broadcast storms and improve Network Health in our free case study!

Data center expansion with OTI and Optigo Connect

DATA CENTER EXPANSION

Stack Infrastructure is a portfolio of hyperscale computing data centers. OTI completed work on Phases I and II, and returned for the Phase III build-out of a 4-megawatt data hall and brand new central plant. The Optigo Connect network put in place in Phases I and II was expanded on this project. The team achieved quick roll-out of a large, multi-service redundant network using the Optigo OneView management interface. Going forward, the facility management team can use OneView to remotely monitor equipment, manage power usage, and meet up-time goals.

Optigo Connect MR Soluciones The Landmark

THE LANDMARK

The Landmark is a sophisticated mixed-use high-rise in Mexico. The owners wanted to integrate all OT systems in the skyscraper, while maintaining separate networks for each application. The Landmark is the fourth joint project between Optigo Networks and MR Soluciones. Together, these companies provide robust services to meet any challenge.

Australian Bureau of Statistics at 45 Benjamin Way with Delta Building Automation

45 BENJAMIN WAY

Delta Building Automation (Australia) had a big job renovating the Headquarters for the Australian Bureau of Statistics (ABS) at 45 Benjamin Way. The building owner wanted to improve the building’s energy use and increase their National Australian Built Environment Rating System (NABERS) score to more than 4.5 stars, out of a possible total of six. Securing the network both internally and externally was a big priority, as well.

Penn State University Optigo Networks Visual BACnet

PENN STATE UNIVERSITY

When Tom Walker looked at Penn State University’s Navy Yard network, he saw huge issues. The system was busy and loud, to the point where the overrun network was bringing down the entire building. Because this was happening on the MS/TP network, pinpointing the problem would mean boots on the ground to segment and test the chain, piece by piece.

Penn State University Optigo Networks Visual BACnet

PENN STATE UNIVERSITY

When Tom Walker first started working at Penn State University four years ago, there were a lot of network issues. Buildings were dropping offline. Broadcast traffic was pushing 90,000 packets per hour. Walker was on the phone almost every single night because devices were down or had to be reset.

 

Torre Manacar Mexico City Optigo Connect

TORRE MANACAR

When MR Soluciones began work on Torre Manacar, they knew they needed a flexible and scalable network infrastructure to support a wide array of integrated systems. Optigo Networks was a natural fit for the massive project, designing a robust network at a competitive cost.

short

SHORT PUMP TOWN CENTER

Short Pump Town Center, an upscale retail center, underwent a complete renovation in 2014. The flexibility of Optigo Networks’ solution meant the retail center’s unknown final design was not a barrier to placing IP surveillance equipment in the field.

BOULEVARD MALL

BOULEVARD MALL

Optigo Networks connected New York-based Boulevard Mall’s security surveillance devices in December 2015, using a Passive Daisy Chain topology.

Visual BACnet tech support team

TECH SUPPORT TEAM

One tech support team at a manufacturer purchased an account with Visual BACnet in April 2017, for technical problems around the world.