4.1 Typical System Topology

The IK10 vandal-resistant surveillance system is organized as a three-tier hierarchical network topology, with a dedicated power and grounding subsystem running in parallel. This architecture ensures that a single point of failure at any tier does not result in a complete loss of recording or alarm capability. The topology is designed to be scalable from small single-building deployments to large multi-site campus systems.

The core design principle is that every critical data path has at least two routes: fiber ring or dual uplinks at the distribution layer, primary/standby VMS at the compute layer, and local SD card backup at the edge layer. This "defense in depth" approach ensures that even a deliberate attack on the network infrastructure does not create a complete evidence gap.

IK10 System Network Topology Diagram
Figure 4.1: IK10 Anti-Vandal Surveillance System — Typical Network Topology with Three-Tier Hierarchy and Power/Grounding Subsystem
TierComponentsConnectivityRedundancy MechanismFailure Impact
Core/Data CenterCore switch, VMS primary/standby, RAID storage, NTP, SIEM10G/40G backbone; dual power feedsVMS active/standby failover; RAID rebuild; dual PSUStandby VMS takes over within 30 s; no recording gap
Distribution/AggregationAggregation switches (2–4 per zone)Fiber ring (ERPS/RSTP); dual uplinks to coreRing protocol reroutes within 50 msSingle switch failure: ring reroutes; no outage
Edge/AccessIndustrial PoE switches, IK10 cameras, strobe/siren, intercomCat6A PoE to cameras; SFP uplink to distributionCamera SD card local recording; PoE switch UPS-backedSingle camera offline: SD records locally; adjacent camera continues
Power & GroundingUPS, PDU, SPD, grounding busDedicated circuits; SPD at outdoor entry pointsUPS ≥30 min runtime; bypass modeMains failure: UPS maintains recording for ≥30 min

Deployment Scale Options

ScaleCamera CountTypical TopologyVMS ArchitectureStorage
Small (Single Zone)8–32 camerasSingle PoE switch + single aggregation switchSingle VMS server + NASRAID-5 NAS, 30 days
Medium (Multi-Zone)32–128 cameras2–4 edge switches + 2 aggregation switches + fiber ringPrimary + standby VMS + dedicated storageRAID-6 storage, 30–60 days
Large (Campus/Multi-Site)128–1000+ camerasFull three-tier with dual-site replicationVMS cluster + distributed storage + SIEMErasure coding, 60–90 days

4.2 Device Wiring Diagram

The device wiring diagram illustrates the physical connections between a single IK10 camera installation point and the supporting infrastructure. Every connection is specified with cable type, maximum distance, and protection requirements. The wiring design follows the principle that no cable should be exposed or accessible without tools, and every connection point should be sealed against moisture and protected against surge.

The junction box is a critical component in the anti-vandal wiring design. It serves as the transition point between the exposed camera pigtail and the protected conduit run. The junction box must be IP66-rated, mounted with anti-tamper screws, and include a tamper switch that triggers an alarm if the box is opened. All cable entries must be sealed with appropriate cable glands.

IK10 Camera Device Wiring Diagram
Figure 4.2: IK10 Camera Installation — Complete Device Wiring Diagram with Cable Specifications, Junction Box, SPD, and Grounding
ConnectionCable TypeMax DistanceProtectionNotes
Camera to Junction BoxCat6A shielded, pigtail≤3 m (exposed)Metal conduit from junction boxPigtail must be shortest possible; no slack loops
Junction Box to PoE SwitchCat6A shielded, 23AWG≤100 mMetal conduit; SPD at entry pointShielded cable required for outdoor/exposed runs
Grounding WireAWG 12 green/yellowShortest pathN/ACamera bracket → grounding bus; resistance <1 Ω
PoE Switch to AggregationOM3/OM4 fiber or Cat6A≤300 m (fiber) / ≤100 m (copper)Fiber preferred for long runsSFP modules; OTDR-tested after installation
Power (UPS to Switch)3-core power cable, 1.5 mm²≤10 m from PDUDedicated circuit; no shared with lightingUPS output → PDU → switch; no extension cords

Anti-Pull Design Rule: The cable must be anchored with a strain relief clamp inside the junction box, so that a pull force on the cable outside the box is transferred to the clamp, not to the RJ45 connector or camera port. The strain relief clamp must be rated for ≥50 N pull force. The conduit must be anchored to the wall or structure at intervals ≤500 mm to prevent the conduit itself from being pulled away.

4.3 Network Design Requirements

The network design for an IK10 surveillance system must address four key requirements simultaneously: sufficient bandwidth for all camera streams, network segmentation for security, redundancy for resilience, and quality of service (QoS) for alarm traffic prioritization. These requirements often conflict with each other and must be balanced based on the specific site constraints and risk profile.

VLAN Segmentation

All surveillance traffic must be isolated in dedicated VLANs to prevent unauthorized access and ensure that a compromise of the IT network does not affect surveillance recording. The minimum VLAN structure includes a camera data VLAN, a management VLAN, and an alarm/event VLAN. Cross-VLAN traffic is permitted only through the firewall with explicit allow rules.

VLANPurposeTraffic TypeAccess Control
VLAN 10 — Camera DataVideo stream transportRTP/RTSP, high bandwidthCameras only; VMS as receiver
VLAN 20 — ManagementCamera configuration and healthHTTPS, ONVIF, SNMP, NTPVMS and admin workstation only
VLAN 30 — Alarm/EventAlarm and event signalingLow bandwidth, high priorityVMS, alarm console, dispatch
VLAN 40 — Corporate ITGeneral office trafficMixedNo access to surveillance VLANs

Bandwidth Planning

Bandwidth planning must account for peak simultaneous recording, event-triggered high-quality streams, and management traffic overhead. The standard formula uses the per-camera bitrate multiplied by the camera count, with a 30% overhead factor for retransmissions, management traffic, and burst events. Storage IO must be sized separately with a 30% headroom above the sustained write rate.

Camera TypeResolutionCodecTypical BitratePeak Bitrate
IK10 Dome (Standard)4MPH.265+2–4 Mbps6–8 Mbps (event)
IK10 Dome (High-End)8MPH.265+4–6 Mbps10–12 Mbps (event)
Panoramic Multi-sensor4×4MPH.265+8–12 Mbps16–20 Mbps (event)
IK10 Bullet (Face Capture)4MPH.265+3–5 Mbps8–10 Mbps (event)

4.4 Storage Architecture & Redundancy

The storage architecture for an IK10 surveillance system must provide three guarantees: continuous recording without gaps, integrity verification for evidence admissibility, and rapid access for incident investigation. These requirements drive the choice of RAID level, hot spare strategy, write cache configuration, and backup policy.

RAID LevelMin DrivesFault ToleranceWrite PerformanceRecommended Use
RAID-531 drive failureGoodSmall deployments, ≤32 cameras
RAID-642 drive failuresModerateMedium deployments, 32–128 cameras
RAID-1041 drive per mirror pairExcellentHigh-write alarm-clip storage
Erasure Coding (EC)6+ConfigurableGood (distributed)Large deployments, 128+ cameras

Evidence Integrity Requirement: All exported evidence clips must be accompanied by a SHA-256 hash generated at export time and logged in the VMS audit trail. The export process must be role-restricted (supervisor authorization required) and the exported file must include embedded metadata: camera ID, timestamp, export user, and hash value. This chain of custody documentation is required for legal admissibility in most jurisdictions.