August 26, 2026 Industrial VPN Router vs Managed Switch: Where to Configure VLANs?

When an industrial network fills up with devices, three problems show up in sequence: 

① office PCs and PLC-controlled equipment end up on one flat network, so broadcast traffic collides with control commands; 

② cameras push video streams around the clock and consume most of the bandwidth meant for production data; 

③ remote maintenance has to come in from outside, yet the whole internal network cannot be left open. All three trace back to the same fix — VLANs, which slice one physical network into isolated segments. 

Then comes the more practical question: where do the VLANs actually get configured? An industrial VPN router and a managed industrial switch each cover a different part.


The Short Answer: Divide the Work by Layer

For VLANs, these two devices are not doing the same job.

Layer-2 isolation belongs on the industrial switch.A VLAN is, at its core, a way to split broadcast domains. Which ports join which VLAN, how 802.1Q tags are applied, how trunk ports pass multiple segments through, port-based rate limiting and QoS — these are the native duties of a managed switch. The port a device plugs into decides its segment, and isolation is completed at Layer 2. Traffic management also lives at this layer: rate-limit the camera ports, prioritize the control ports.

Layer-3 interconnection belongs on the router.VLANs cannot reach each other by default; crossing over requires Layer-3 routing. An industrial VPN router takes on three tasks here: routing between segments, access control between segments (who can reach whom, on which ports only), and outbound NAT plus the uplink.

Remote access also terminates on the router.This is where the name "VPN router" comes from. Remote-maintenance tunnels end at the router, and combined with access-control rules, an external account can only enter designated segments — a device vendor is granted the PLC segment alone, with office and surveillance segments out of reach. Isolation policy is concentrated at one gateway point: simpler to configure, simpler to troubleshoot.

Mapped onto a Typical Industrial Network

A plant or a production line usually runs three segments: office (PCs, printers, APs), production (PLCs, CNC machines, data collectors), and surveillance (cameras, NVRs). The managed industrial switch assigns ports into the three VLANs; the router acts as the gateway for all three segments with access rules in place: the office segment may reach specific ports on the production segment, the reverse direction is blocked; remote accounts are mapped to the production segment only. The more heterogeneous the devices, the more this isolation becomes the baseline of network stability.

Few Devices: One Box Covers Both Levels

For a small network of eight or ten devices, buying a separate industrial switch is not economical — a multi-port industrial VPN router covers both levels at once. Take the USR-G809s: 2 gigabit SFP ports plus 8 gigabit Ethernet ports take in multiple cameras, collectors, and PLCs directly, saving one industrial switch; the unit supports managed VLAN division, with ports grouped into independent subnets as needed, and inter-VLAN routing plus access control completed on the same device; WiFi 6 AX3000 with a theoretical capacity of 256 clients covers phones and tablets in the office area; cellular modules come in 5G, 5G RedCap, or 4G, for sites where fixed broadband cannot reach; RS485/RS232 serial ports and DI/DO lines take care of field serial devices and digital on/off signals along the way; -40°C to 75°C wide temperature range and 9-60V wide voltage input mean no extra precautions in workshop environments. For edge computing needs, the router also supports custom development in Python, with serial plus I/O collecting up to 2000 data points, pre-processed locally before uploading.

More Devices: Gateway Plus industrial Switch

When ports run short, split into two levels: the router handles only the gateway and VPN egress, the managed industrial switch handles port expansion and Layer-2 isolation, a trunk port links to the router, and the router's sub-interfaces map to each segment's gateway. 

For the gateway, the USR-G816 is one option: 5G downlink at a theoretical 1.9 Gbps, dual SIM redundancy with automatic failover when the primary card drops; 3 gigabit LAN ports plus 1 gigabit WAN/LAN, with a gigabit port connecting the industrial switch; the full set of VPN protocols — PPTP, L2TP, IPSec, GRE, OpenVPN — with enhanced OpenVPN working as a client connected to 3 servers simultaneously while also serving as a server, covering both cross-site networking and remote maintenance; dual-band WiFi covers the office area. 

For batch deployments across dozens of sites, the cloud management platform's bulk configuration and disconnection alerts pushed via email and SMS save a large share of on-site inspection work.

Configuration Order, Step by Step

① Plan segments before touching devices: assign one VLAN ID and one IP range each for office, production, and surveillance, and settle it in one pass; 

② Divide ports on the industrial switch: a device enters the segment of the port it plugs into, with a trunk port linking the router; on small networks, divide directly on the router's ports; 

③ Configure the gateway and rules on the router: access control follows "deny by default, allow as needed"; 

④ Bind VPN accounts to segments: which segments remote access can reach is stated clearly in one rule on the gateway; ⑤ Keep a management segment: when debugging the network, this avoids getting locked out.

Where VLANs are configured is a matter of layers: isolation goes on the ports of the managed industrial switch, interconnection and access control go on the Layer-3 routing and firewall of the industrial VPN router, and remote access is terminated by VPN in one place. With few devices, one multi-port industrial VPN router covers everything; with more devices, split into gateway plus industrial switch across two levels. Plan the segments first, then configure in order, and get the isolation right in one pass.

REQUEST A QUOTE
Industrial loT Gateways Ranked First in China by Online Sales for Seven Consecutive Years **Data from China's Industrial IoT Gateways Market Research in 2023 by Frost & Sullivan
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy
Reliable products and services around you !
Subscribe
Copyright © Jinan USR IOT Technology Limited All Rights Reserved. / Sitemap / Privacy Policy