AV devices on the network: convenience, management and security risks

0
72
Series: Connecting AV and IT networks without losing control
Modern AV equipment is IP infrastructure. That makes segmentation, access control and clear responsibility essential.

AV devices are network devices

AV equipment has changed significantly over the past few years. Where audio systems once consisted mainly of analog cabling, matrices, and local control, modern installations now consist largely of IP-based devices.

Think of cameras, encoders, decoders, DSPs, touch panels, control processors, microphones, amplifiers, video walls, room systems, and switches. All of these devices have IP addresses. Many offer web interfaces, APIs, firmware management, user authentication, and cloud integration.

This makes AV systems more flexible, but also more vulnerable. Once AV is connected to the network, it becomes part of the overall security landscape.

The risk of a flat network

In a flat network, every device can effectively reach every other device. For small test setups, this can feel convenient: everything is visible, discovery works quickly, and firewall rules are not a concern.

In a professional environment, however, this is rarely acceptable.

Should every laptop on the corporate network be able to access a camera’s web interface?
Should guest Wi-Fi have access to a DSP?
Should every IT client be able to manage the AV switch?
Should an encoder have unrestricted internet access?

In most cases, the answer is no.

A dedicated AV network or AV zone helps limit access — not because AV must be hidden, but because risk and management need to remain under control.

Segmentation as a security measure

Network segmentation is a well-established security practice. MITRE recommends enforcing deny-by-default policies using ACLs and restricting both north-south and east-west traffic with firewalls. It also emphasizes regularly reviewing firewall rules, ACLs, and segmentation policies.

This principle applies directly to AV environments.

Instead of one large, flat network, you design logical zones:

IT client VLAN
AV management VLAN
AV control VLAN
AV media VLAN
Guest VLAN
Internet / cloud services
You then explicitly define which traffic flows are required between these zones.

Protect management interfaces

Many AV devices expose management interfaces such as HTTPS, SSH, vendor-specific tools, SNMP, or configuration software. These interfaces are intended for administrators — not for general users.

A good practice is:

Only AV/IT management subnets may reach AV management.
User VLANs may not reach switch management.
Guest Wi-Fi never reaches AV.
Remote support uses VPN, a jump host or an explicit firewall rule.

This prevents the AV network from becoming an unnoticed weak spot in the wider IT environment.

Management and responsibility

Security is not just about technology — it is also about ownership and responsibility.

During an outage, it should be immediately clear who owns which part of the system. Typically: IT manages firewalls, core switches, DHCP, DNS, internet access, and security policy. AV integrators manage AV configurations, endpoints, multicast profiles, audio/video routing, and room control

Without clear agreements, confusion arises quickly:

Who may update firmware?
Who manages the switch configuration?
Who may change firewall rules?
Who has access to NETGEAR Engage?
Where is the configuration backup stored?
Who tests changes before go-live?
A segmented AV zone makes these responsibilities clearer and enforces better collaboration between IT and AV.

Troubleshooting becomes easier

Segmentation also improves troubleshooting. If audio drops out, you do not want to search across thousands of office clients, printers, access points, and security systems.

A dedicated AV zone allows you to focus on relevant factors such as:

- multicast groups
- IGMP Snooping tables
- uplink utilization
- QoS markings
- PTP clock behavior
- firmware versions
- port profiles

This speeds up diagnosis and limits the impact of changes.

Security without making AV unusable

The key is balance. A network that is too open introduces risk. A network that is fully isolated becomes impractical. The right solution usually lies in between.

A workable approach is:

Keep AV media local.
Limit AV management to administrators.
Allow AV control only where needed.
Explicitly allow services such as NTP, DNS and logging.
Limit internet access to required functions.

This keeps AV usable without opening the network unnecessarily.

Conclusion

Modern AV equipment is part of the IP infrastructure. This means security, segmentation, and clear management responsibilities must be included in every AV-over-IP design.

A dedicated AV network is therefore not only beneficial for stability, but also essential for risk management and accountability.

In the next blog, we will take the next step: which traffic flows should actually be allowed between AV and IT?

Sources

Back to the 1st blog in this series

 

Eric Lindeman, NETGEAR ProAV Staff Systems Engineer Benelux


For more information about NETGEAR AV Switching, please contact the NETGEAR Pro AV Design Team via email: ProAVdesign@netgear.com

If you’d like to delve deeper into AV over IP switching, I invite you to check out our Online Academy via the link: https://academy.netgear.com/

On our training portal, you can find both AV and IT-related training courses. These courses are free to attend after registration, and at the end of each course, you can take an exam to earn a certificate.