September 11, 2026 How VLANs and ACLs Create Boundaries in Industrial Networks

In industrial networks, the problem is not always that devices cannot communicate. Sometimes, the bigger risk is that too many devices can communicate with each other.

PLCs, HMIs, SCADA systems, cameras, engineering laptops, and remote maintenance terminals are often connected to the same local network for convenience. But if one device is misconfigured, an IP conflict occurs, or a maintenance terminal sends unexpected traffic, the impact may spread far beyond a single device.

That is why, when choosing an industrial router, it is worth looking beyond 4G/5G connectivity, Ethernet ports, and VPN support.

A more practical question is:

Can the router control which devices and network segments are allowed to communicate with each other?

A common approach is to combine VLANs, ACLs, and firewall policies.

1. Use VLANs to Separate Device Groups

The most direct role of a VLAN is to separate devices that would otherwise share the same Layer 2 broadcast domain.

For example, an industrial network could be divided like this:

  • VLAN 10: PLCs and industrial controllers
  • VLAN 20: SCADA and data acquisition servers
  • VLAN 30: Cameras and NVR systems
  • VLAN 40: Engineering laptops and maintenance terminals

These VLAN numbers are only examples. The actual design should depend on the site architecture.

Once the network is segmented, video traffic and broadcast traffic from cameras no longer share the same broadcast domain as PLCs. Maintenance laptops are also no longer automatically placed in the same network segment as control devices.

However, there is one important point:

VLAN segmentation alone does not equal access control.

If an industrial router allows unrestricted Layer 3 routing between all VLANs, devices in VLAN 10 may still communicate freely with VLAN 20, VLAN 30, and VLAN 40.

To create a real boundary, ACLs are also needed.

2. Use ACLs to Decide Which Traffic Is Allowed

An ACL, or Access Control List, can be treated as a set of communication rules.

Instead of simply defining:

VLAN 20 can access VLAN 10.

A better approach is to define the rule in more detail:

Who is accessing whom, over which protocol or port, and whether that traffic should be allowed.

For example, if a SCADA server needs to read data from PLCs, the rule can allow:

SCADA network → PLC network → Required application ports only

This is safer than allowing the entire SCADA subnet unrestricted access to the PLC network.

Likewise, a video surveillance VLAN usually has no reason to initiate connections to the PLC VLAN, so that traffic can be blocked.

Engineering laptops and maintenance terminals should also not automatically receive access to every control network.

A practical principle is:

Deny by default, then allow only what the application actually requires.

This way, when a new camera, laptop, or third-party device is added later, simply connecting it to the network does not automatically give it access to the entire OT environment.

3. Restrict Access to the Router Management Interface

Another often-overlooked point in industrial networks is the management interface of theindustrial routeritself.

If every LAN device can access the router's Web interface, SSH service, or other management functions, the network configuration remains exposed even if the PLC network has already been segmented.

A more controlled design is to separate management access from normal device communication.

Production devices should only handle their required communication tasks.

The router management interface should be accessible only from a dedicated management VLAN or specified maintenance hosts.

For remote maintenance, VPN access can be used to reach selected internal networks instead of directly exposing management ports to the public Internet.

For example, the USR-G806w supports VLAN functionality together with IP, domain name, and MAC filtering, Access Control, DMZ, anti-DoS protection, port forwarding, and other firewall-related functions. This allows network segmentation and access restrictions to be implemented within the same industrial router.

4. Do Not Treat VLANs, ACLs, and Firewalls as the Same Thing

In a practical deployment, these three mechanisms solve different parts of the problem.

VLANs separate the network into different zones.

PLCs, SCADA systems, video devices, and maintenance terminals can be placed into different network segments.

ACLs control which zones are allowed to communicate.

For example, SCADA may be allowed to access PLCs, while cameras are blocked from accessing the PLC network.

Firewalls control traffic entering and leaving the network.

This is especially important between 4G/5G networks, the public Internet, enterprise WANs, and the on-site OT network. Firewall policies can further restrict inbound connections, outbound traffic, port forwarding, and unnecessary access.

When these mechanisms are used together, the network boundary becomes much clearer.

For sites that require high-speed 5G connectivity, the USR-G816 provides firewall, access control, and VPN capabilities that can help create another protection layer between the public network and industrial devices.

5. A Practical Deployment Order

It is usually better not to start by writing dozens of complex firewall rules.

Start by listing the devices in the network:

PLCs, HMIs, SCADA servers, cameras, engineering laptops, and other terminals.

Then group them into VLANs based on their functions.

Next, identify the communication paths that are actually required. For example:

SCADA → PLC: Allow
Maintenance host → PLC: Allow when required
Camera → PLC: Deny
General terminal → Router management interface: Deny
Authorized management host → Router: Allow

After that, configure firewall rules, VPN access, and WAN-side policies.

The advantage of this approach is that even if a configuration error occurs, its impact is more likely to remain limited to one network zone instead of affecting the entire OT network.

When Choosing an Industrial Router, Ask More Than “Can It Connect?”

For industrial deployments, the more useful questions are:

Does the router support VLANs?

Can access rules be applied between different VLANs?

Can ACLs restrict traffic based on source, destination, and application requirements?

Can the management interface be limited to specific networks or hosts?

Does the WAN side provide firewall and VPN capabilities?

Industrial network security does not always require adding more hardware.

In many cases, simply separating the network first and then allowing only the communication that is actually required can establish a practical and effective access boundary.

That is also one of the most important roles of anindustrial routerbeyond simply providing connectivity.

REQUEST A QUOTE
Industrial loT Gateways Ranked First in China by Online Sales for Seven Consecutive Years **Data from China's Industrial IoT Gateways Market Research in 2023 by Frost & Sullivan
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy
Reliable products and services around you !
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy