The short answer
Network Switches
The network switch in a control panel is a piece of control equipment and is specified like one: industrially rated for the panel temperature, mounted on the rail with a 24 volt supply and a grounded chassis, with enough ports of the right media for the devices in the panel plus the uplinks plus spares, and managed where the network needs anything more than a link. A managed switch gives port diagnostics, virtual networks, ring redundancy, multicast filtering for remote I/O, port security, and an alarm contact, all of which a plant network uses; an unmanaged switch gives a link and nothing else, and belongs only in the smallest panel with no redundancy and no segmentation. Fiber ports for the uplinks that leave the building, a documented configuration backed up with the panel drawings, and a firmware version in the asset inventory complete the specification.
Key points
- Managed switches for anything with redundancy, segmentation, remote I/O, or diagnostics; unmanaged only for the simplest isolated panel.
- Industrial rating for the panel temperature, DIN rail mounting, 24 volt supply, chassis grounded.
- Fiber uplinks for any link leaving the building; copper inside the panel and the room.
- Ring or redundancy protocols must match across every switch and device in the ring.
- The configuration is part of the panel documentation: backed up, versioned, and restorable.
Managed or unmanaged
| Capability | Unmanaged | Managed |
|---|---|---|
| Port status and error counters | Link light only | Full counters per port |
| Virtual networks | No | Yes |
| Ring or redundancy protocols | No; a loop is a storm | Yes, with the matching protocol |
| Multicast filtering for remote I/O | Floods every port | Group management and querier |
| Port security, disabled ports | No | Yes |
| Alarm contact and monitoring | No | Contact output and network management |
| Configuration backup | Nothing to back up | Configuration file, versioned |
| Where it belongs | A small isolated panel with a controller and a touchscreen | Everything else |
Specification
- Environmental
- Operating temperature covering the panel interior at summer maximum, which is above the room temperature; conformal coating for corrosive rooms; no fans.
- Mounting and power
- DIN rail, 24 volt DC from the panel supply, redundant power inputs where the switch supports them, an alarm contact for power loss.
- Ports
- Copper ports for the devices in the panel plus two spares; fiber ports or transceiver slots for uplinks; power over Ethernet where cameras or access points hang off the switch, with the power budget checked.
- Media
- Single-mode fiber for building-to-building; multimode acceptable inside a building; copper limited to 100 meters and never between grounds.
- Protocols
- The ring protocol used by the plant, spanning tree as the fallback, group management for multicast, time synchronization pass-through, and the management protocol the network monitor uses.
- Security
- Management on a dedicated network or virtual network, encrypted management access, unused ports disabled, port security where the design needs it, and a logged configuration.
- Listing
- Recognized or listed for use in the panel, with the ratings the panel standard requires.
In the panel
- Mounted where the patch cords reach the devices without crossing the power wireway; a small patch panel or couplers for the field cables.
- Chassis grounded to the panel ground bar; shielded copper cables bonded at the switch end.
- Fiber patch cords in a management tray or with radius protection, not in the wireway with the power conductors.
- Labels on every port matching the network schedule; a port label that says which device is on it saves a site visit.
- The alarm contact wired to a controller input and alarmed.
Configuration
A managed switch has a configuration: addresses, virtual networks, port assignments, ring settings, multicast settings, management accounts, and logging. It is built from the network drawing and the network schedule, saved as a file, and stored with the panel documentation and in the backup set, so that a failed switch is replaced by loading the file into a spare. The firmware version is recorded in the asset inventory and updated through the patch process. Default accounts are removed, the management interface is on the management network only, and the configuration is compared with the file after any change.
Ring topologies
Panels at a plant are often linked in a ring of switches so that one cable failure does not isolate a panel. The ring works only when every switch runs the same ring protocol with the same settings, one is the manager, and no device in the ring lacks the protocol. The network drawing shows the ring, the ring status is monitored, and a break is alarmed and repaired, because a ring with one break is a line with no redundancy. Devices with two ports that support the ring protocol can be in the ring; devices that do not are connected to a switch port, not spliced into the ring.
Frequently asked questions
- Can I use an office switch in a control panel?
- It will work until it does not: it is rated for an office temperature, it has a fan or a wall adapter, and it is not listed for the panel. An industrial switch costs more and is a control component; use one.
- How many spare ports?
- Two at minimum, more on a panel that will grow. A switch with no spare ports is replaced the day a camera is added.
- Do I need a managed switch in a lift station?
- If the station has a controller, a drive on Ethernet, a touchscreen, and a radio, and the design segments the radio from the drives, yes. A station with a controller and a radio on a two-port controller may not need a switch at all.
- Should the switch be on the UPS?
- Yes, along with the controller and the radio; a switch that drops on a power blip takes the communications down while the controller rides through.
Related topics
- Panel NetworkingThe network inside a controller panel: which networks exist and how they are kept apart, where the switch sits, copper patching and fiber entry, the radio or cellular router as a panel component, cable management, shield grounding, and labeling.
- Broadcast StormA network suddenly slow or dead everywhere, every link light solid: a loop between switches without protection, a failed ring protocol, or a device flooding broadcasts. Recognising a storm, breaking it with a cable pull, finding the loop, and preventing it.
- Switch Port Errors IncrementingWhat each counter on a managed switch port means and which fault makes it grow: check errors from a damaged cable or noise, late collisions from a duplex mismatch, runts from a bad transceiver, discards from congestion, link flaps from a marginal connection.
- VLAN SegmentationUsing VLANs to build the zones of a control network on shared switches: what a VLAN separates and what it does not, the zone-to-VLAN mapping, trunks and the native VLAN, routing only through a firewall, and where separate hardware begins.
- Network SchedulesThe tables behind the network drawings: the address schedule of every device, the switch port schedule of every port, the VLAN table, and the conduit list of what the firewalls permit. How they are built, kept as the single source of truth, and protected.
- UPS for Control PanelsKeeping the controller, the radio, and the SCADA server alive through an outage: AC and DC UPS types, what to put on the UPS and what not to, sizing for runtime and inrush, the battery as a maintenance item, the alarms a UPS must provide, and what happens when the UPS is the thing that fails.
Direct contact
Have a controls question?
Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.