Series: Connecting AV and IT networks without losing control
In many AV-over-IP projects, the same discussion appears sooner or later: should we place the AV installation on the existing IT network, or should we build a dedicated AV network next to the corporate network?
On paper, the answer seems simple. AV-over-IP uses standard network technology: Ethernet, IP, VLANs, multicast, QoS and routing. So why would we still build a separate infrastructure?
In practice, many projects deliberately choose a dedicated AV network, often based on NETGEAR Pro AV switches. Not because AV is “not IT”, but because AV traffic behaves differently from normal office traffic.
The nuance matters. A separate AV network is not a religion. Q-SYS, for example, explicitly describes that Q-SYS can be deployed in both isolated and converged Ethernet network environments. So yes, AV and IT can share infrastructure, but only when the network is designed for it.
AV-over-IP is not ordinary office traffic
Most office applications are fairly tolerant. A file transfer that takes a little longer, a web page that reloads, or a cloud application that pauses for a moment: inconvenient, but usually not immediately visible to everyone in the room.
AV is different. Audio and video are real-time. When network behavior becomes unpredictable, you notice it immediately: dropouts, video stutter, discovery problems, delayed control, or devices that suddenly disappear from the software tool.
AV traffic therefore needs predictability. You want to know how much bandwidth is available, which ports carry which streams, where multicast is allowed to go, which uplinks are loaded, and who is responsible for changes.
Why AV is often separated
The first reason is stability. An AV network must keep working during a presentation, meeting, performance or live production. You do not want a backup job, software update, security scan or peak load on the corporate network to affect a Dante, NDI, Q-SYS or video-over-IP system.
The second reason is management. In many organizations, IT and AV are different disciplines. IT manages firewalls, switches, Wi-Fi, security, DHCP, DNS and policies. The AV integrator manages encoders, decoders, DSPs, cameras, touch panels, control processors and AV switches. A separate AV zone makes it clearer where responsibility starts and ends.
The third reason is multicast. Many AV protocols use multicast for discovery, timing or media. If multicast is configured incorrectly, traffic can be forwarded to far more ports than intended. In a dedicated AV network, you can deliberately configure IGMP Snooping, the IGMP Querier, QoS and VLAN profiles.
NETGEAR addresses this with Engage Controller, which provides certified AV profiles for technologies such as ST 2110, Dante, AES67, Q-SYS, AVB, NDI, lighting and video-over-IP. These profiles help make configurations repeatable and reduce configuration mistakes.
Separation does not mean never connecting
A common mistake is to treat “separation” as the same thing as “complete isolation”. In real projects, complete isolation is rarely practical.
An AV installation often still needs a connection to IT. Think of monitoring, remote management, firmware updates, logging, NTP, DNS, user interfaces, calendar integrations, Teams Rooms, Zoom Rooms, Dante Controller, Q-SYS Designer or NETGEAR Engage.
The real question is not:
Should AV be completely disconnected from IT?
The better question is:
Which parts of the AV network must communicate with IT, and under what conditions?
That is the core of a good design. Audio and video streams are often best kept local inside the AV network. Control, management and services can be connected in a targeted way through a firewall, control VLAN, management VLAN, out-of-band network or NAT solution.
Best practice: functional separation
Modern designs are less about physical separation and more about functional segmentation.
A practical model is:
IT network
|
Firewall / router / controlled connection
|
AV management / AV control
|
AV media VLANs
- Dante / AES67
- NDI / video
- Q-SYS
- Lighting
- Management
This prevents the AV network from becoming a fully open extension of the corporate network. At the same time, it prevents AV from becoming an unmanageable island.
Conclusion
Separating AV and IT is not outdated. It is often a practical choice to keep stability, manageability, multicast behavior and responsibility under control.
But separation is not the goal. The goal is an AV network that works reliably and can cooperate with IT in a controlled way.
In the next blog, we look at the technical reason why AV networks behave differently from standard IT networks: multicast, QoS and timing.
Sources
Eric Lindeman, NETGEAR ProAV Staff Systems Engineer Benelux
For more information about NETGEAR AV Switching, please contact the NETGEAR Pro AV Design Team via email: ProAVdesign@netgear.com
If you’d like to delve deeper into AV over IP switching, I invite you to check out our Online Academy via the link: https://academy.netgear.com/
On our training portal, you can find both AV and IT-related training courses. These courses are free to attend after registration, and at the end of each course, you can take an exam to earn a certificate.



