Someone new to woodworking once went through the tool inventory: a circular saw, a drill, chisels, a hand plane, plus homemade saw guides and a simple router table. A few months later a trim router and a full box of bits joined the list. The list kept growing, and the outlets around the workbench started running short.
A large shop runs into the same thing with a longer list: one CNC this year, cameras, industrial PCs and acquisition modules next year, possibly another one the year after. A network sized to today's equipment count usually gets rebuilt in the second year, cable trays included. The cheaper approach is to work backwards from the list three years out — decide which equipment belongs on Ethernet and how many ports the industrial VPN router in the cabinet needs, then let the installation follow.
While the floor is still empty, the work worth doing is the cable tray, the conduit and the spare runs. Adding one cable after the machines are in place means surface raceway, climbing the tray and routing around equipment that is already running. The labor costs more than the cable itself.
The practice is two ports per station: one for the equipment sitting there now, one for the neighbor arriving later. Cabling goes in tray or conduit, kept separated from power cables and crossing them at right angles. Joints stay at accessible points rather than under a machine base, and both ends of every run get a label — months later, when one cable has to be traced, a label beats memory. Power and network get reserved together, so adding a camera in a far corner does not mean pulling power again.
Whichever unit sits at the egress point decides the gateway, the rules and the remote access path for every segment behind it. One question settles it: can stable fixed broadband reach the site? Where it can, the WAN port carries the primary link and cellular stays as backup. Where it cannot — a leased building, broadband with a waiting list — cellular becomes the primary link rather than the fallback.
Two things tend to be missed on the cellular route. A private-network SIM needs the correct APN; the wrong one means no registration. And failover needs its own test: unplug the primary link with a stopwatch, watch whether sessions drop and how long recovery takes. At unattended sites, switchover time matters more than throughput.
This layer suits the USR-G816: 5G with SA and NSA, dual SIM (the second slot optionally a built-in eSIM, so switching carriers does not mean switching hardware), one Gigabit WAN port configurable as LAN plus three Gigabit LAN ports, and RS232/RS485 terminals that take legacy machine tools with only a serial port. DC9-36V wide input with reverse-polarity protection, -35~75°C, IP30, DIN-rail or wall mounting. Remote access lands here as well: PPTP, L2TP, IPSec, GRE and enhanced OpenVPN, with enhanced OpenVPN able to connect to three servers as a client or run as a server itself; three conditions — device offline, weak signal, data limit exceeded — can be set to push email or SMS alerts.
Which equipment belongs on Ethernet is not a question of distance from the cabinet, but of what one dropped connection costs.
Equipment that stops a process when it drops: a CNC receiving part programs, an industrial PC pulling toolpath files and production records. Equipment that holds bandwidth around the clock: cameras and the recorder. Equipment mounted beside a motor: acquisition modules and older machine tools. Motor starts and stops show up as packet loss on a wireless link, and a cable does not pick that up. All three belong on copper.
Wireless is for what travels with people — a laptop opening drawings, a tablet for job reporting, a handheld terminal scanning barcodes.
The simplest way to separate the two is by physical port: a few LAN ports to the machine area, others to office desks, with the rules written on the router itself. When after-sales support comes in from a remote site, the tunnel reaches only the machine segment, leaving the office network outside its scope. Managed switches and VLANs only earn their keep once the cabinet holds more than eight devices; below that, port-level separation is enough. This layer suits the USR-G809s: two switchable WAN/LAN ports, six Gigabit LAN ports, and two Gigabit SFP slots (one shares with its paired copper port, so only one of the two can run at a time); Wi-Fi 6 dual-band, up to 256 clients, DC9-60V, -25~75°C, DIN-rail mounting.
A single copper run tops out at 100 meters. With equipment at the far end of the building, pulling copper across the floor costs labor and picks up interference; running fiber from the SFP slot in the cabinet to a small switch on the far side does it better, and where two structures are involved the fiber also breaks the ground potential difference between them.
Where that far point carries only one or two low-bitrate camera feeds, or cabinet space is tight, the USR-G806w fits better: 10/100Mbps ports, 104×102×28mm, DIN-rail or wall mounting, -20~70°C, switchable between cellular, wired and Wi-Fi uplinks. Above eight HD feeds, move up to a Gigabit model.
Four places are worth over-specifying. Ports — a four-port device when three are in use today; hanging another switch next year for two more machines costs more than the difference. Address space — one reserved block per production line, so new equipment only changes the last octet. Configuration — name rules after the device, export them as a template, import straight into the second machine, and back up before every change. Documentation — update the address table and the rule list with each new device, so six months later it remains clear which rule serves what.
What keeps a large shop network stable is not one device with impressive specifications but the order of the work: the cheap part while the floor is empty, then the egress point, then machines separated from people, then fiber back from the far wall.
What remains is writing the egress end into the handover document: what the primary link is, how failover behaves, how address space is divided, which tunnel remote access travels through. With those four written down, the role of an industrial VPN router in the shop is clear too — holding steady the equipment wired to it, and leaving one controllable path for remote viewing.
1. Does a shop network need industrial-grade equipment from the start?
It depends on device count and running hours. Consumer-grade units usually begin queueing somewhere around twenty to thirty concurrent clients, and dust, wood chips and summer cabinet temperatures sit outside what they are built for. Where machines run continuously and the device count passes twenty, industrial-grade saves trouble; the segment serving temporary visitors can keep running on the old unit.
2. Should spare cabling follow today's device count or the one three years out?
Three years out. Trays and cable are cheapest while the floor is empty, and adding one run later means surface raceway and climbing the tray. The practice is two ports per station and one reserved address block per production line, so new equipment only changes the last octet.
3. What if broadband cannot reach the shop?
Treat cellular as the primary link rather than the fallback. Choose a dual-SIM model, with the two cards from different carriers to avoid a single carrier's dead spots, and confirm the APN on a private-network card. Verify failover once during acceptance: unplug the primary link with a stopwatch and time the recovery.
4. How long can one cable run be, and how is a crossing handled?
One hundred meters of copper per run. With equipment at the far end of the building, fiber is the easier answer — from the SFP slot in the cabinet to a small switch on the far side — and it removes the ground potential difference between two structures at the same time.
5. Should cameras run on cable or wireless?
On cable. The position never changes, the stream runs continuously, bandwidth is occupied day and night, and the camera often sits in the corner furthest from the cabinet. Reserve network and power together, leave power to a PoE switch, and keep recordings local so playback is the only traffic that crosses the link; the continuous stream stays inside the site.
6. Is a VLAN required to separate machines from people?
Not necessarily. With a modest device count, port-level separation is simpler: a few LAN ports to the machine area, others to office desks, rules written on the router. Managed switches and VLANs come in once the cabinet holds more than eight devices and the separation rules keep changing.
7. Do motor starts and stops affect the network?
Mostly on the wireless side. The interference from motor switching shows up as packet loss, so acquisition modules and older machine tools mounted near motors are better on cable. On the wired side, what suffers is usually power rather than signal, which makes wide input voltage and reverse-polarity protection worth more attention than signal strength.
8. When another CNC arrives later, does the network need re-planning?
Not if the headroom was there. With spare ports,