A building network with clear operational boundaries
Connect building services, corporate systems and contractors while keeping control traffic and maintenance permissions explicit.

Separate facilities and corporate access
Control contractor maintenance windows
Preserve local building control
How the solution connects
Independent uplinks meet a controlled network boundary. Local access is separated by purpose.
Read the connection map
- Corporate services → Firewall + jump host · Primary path
- Approved contractor access → Firewall + jump host · Primary path
- Firewall + jump host → Catalyst distribution · Policy boundary
- Catalyst distribution → BMS + controllers · Separate zone
- Catalyst distribution → Metering + access control · Separate zone
- Catalyst distribution → Office network · Separate zone
The challenge on the ground
Building systems are often commissioned by different contractors, each leaving its own addressing, credentials and support method. A shared switch can turn those independent systems into one broad trust zone.
The useful design starts with controller protocols, required integrations and the person responsible for each system.
Inside the design
Use Catalyst distribution switching and dedicated access segments for BMS controllers, metering, access control and corporate devices. Enforce cross-zone traffic at an appropriately specified firewall.
Put integration services in a controlled zone and connect remote contractors through a managed jump host. A serial or fieldbus controller needs a protocol-compatible gateway; Ethernet switching alone does not translate its data.
Operating it day to day
Keep control loops local and identify the safe behaviour when upstream reporting is unavailable. Establish a change record for addresses, credentials and permitted flows before accepting each contractor handover.
Use time-limited remote access and retain controller configuration backups. Separate network ownership from the maintenance responsibility for the underlying building equipment.
What to test before handover
- Confirm normal local control with the reporting uplink disconnected.
- Test every approved integration flow and block unlisted cross-zone access.
- Exercise contractor access expiry.
- Restore a sample controller configuration in a safe test environment.
Technical references
The bill of materials
One building with an existing BMS, an office network and a facilities-management team. Quantities below describe the example; your proposal confirms the final equipment and services.
Cisco Meraki MS130-48P Cloud Managed 48-Port PoE Switch
MS130-48POffice/access PoE switching
View productComplete the installation
The equipment above is one part of the project. Include these items in the final scope.
- Cross-zone firewall and jump host
- Protocol gateways and fieldbus integration
- Controller backup and logging
- Building riser cabling, optics and UPS
Questions before you specify
Can every BMS device be connected directly to Ethernet?
No. Match each controller interface and protocol to an appropriate gateway, and document which services may cross into the corporate network.
Let’s design it for your site.
Send us the details below. We can turn the reference architecture into a scoped design, equipment schedule and quotation.
Start your projectBring these to the first conversation
- 01BMS/controller inventory and protocols
- 02Contractor access requirements
- 03Network ownership boundaries
- 04Local-control and reporting dependencies






