The short answer
Panel Networking
A controller panel usually carries more than one network: the control network that links the controller to SCADA and engineering, the device network for drives, instruments, and remote I/O, and sometimes a separate management network or a private I/O ring, and the panel design keeps them distinguishable and, where the design requires it, separate. The switch sits on the rail with its ports labeled against the network schedule, the copper cables from the field land on couplers or a small patch panel rather than being plugged straight into the switch, the fiber enters through a management tray with radius control and lands on a patch panel, the radio or cellular router is mounted as a panel component with its antenna feed through the surge entrance, and every cable carries a label at both ends. The result is a panel where a technician with the drawing can find any link, read its port status, and replace any cable without guessing.
Key points
- Know which networks are in the panel and keep them separate by port, virtual network, or physical switch as the design requires.
- Field copper lands on couplers or a patch panel; field fiber lands on a fiber patch panel in a tray.
- The switch, the router, and the media converters are panel components: rail-mounted, on 24 volts, on the UPS, grounded, labeled.
- Network cables stay out of the power wireway; shields and switch chassis bond to the panel ground.
- Every port and cable is labeled against the network schedule, and the switch configuration is backed up with the panel drawings.
The networks in a panel
| Network | Members | Separation |
|---|---|---|
| Control network | Controller, SCADA path, engineering access, touchscreen | Its own virtual network or switch; the firewall boundary is here |
| Device network | Drives, instruments on Ethernet, remote I/O adapters | Separate virtual network or a second controller port; multicast handled |
| Private I/O ring | Remote I/O drops on a ring protocol | Physically separate; nothing else on it |
| Management | Switch management, network monitor | Its own virtual network where the switch supports it |
| Telemetry | Radio or cellular router to the control network | Behind the site firewall or the controller second port |
Placement
The switch mounts on the rail near the controller, away from the drives and the power section, with its ports facing the wireway that carries the network cables. Field copper enters through the surge entrance where it leaves the building, or directly where it does not, and lands on couplers or a patch panel; short patch cords then run to the switch, so that a field cable is never plugged directly into a switch port and a port change is a patch cord, not a field cable. Fiber enters through a tray or a small enclosure that controls the bend radius, lands on a fiber patch panel, and patch cords run to the transceivers. The radio or cellular router mounts as a panel component with its power from the UPS-backed supply, its Ethernet to the switch or the controller port, and its antenna coax through the arrestor at the surge entrance.
Cables and grounding
- Network cables run in their own wireway or a separated section, never beside drive output cables or in the power wireway.
- Shielded copper is bonded at the switch end through a shielded connector or a shield clamp to the panel ground; the switch chassis is bonded to the same ground.
- Fiber patch cords are dressed with radius protection and never tie-wrapped tightly.
- Cable lengths are kept short and slack is stored in the tray, not coiled in the wireway.
- Cables are labeled at both ends with the link name from the network schedule; ports are labeled with the device they serve.
Components
- Switch
- Industrial, managed, rail-mounted, 24 volt, on the UPS, alarm contact wired, configuration backed up.
- Media converters
- Where a device has only copper and the link is fiber; industrial, rail-mounted, with link fault pass-through set deliberately.
- Router or firewall
- At the boundary between the site and the outside; a cellular router with its firewall, or a small industrial firewall ahead of the radio.
- Patch panel and couplers
- Rail-mounted couplers or a small patch panel for the copper; a fiber patch panel for the fiber.
- Surge protection
- Ethernet protectors on copper that leaves the building, or fiber instead; a coaxial arrestor on the antenna feed.
Documentation
The network drawing shows the switch, its ports, the devices, and the links with their media and their virtual network; the network schedule lists every address, every port, and every cable; the switch configuration file is stored with them. A panel whose network can be reconstructed from its drawings is a panel that can be repaired by someone who has never seen it. The labels on the ports and the cables are the drawing made physical.
Frequently asked questions
- One switch or two?
- One managed switch with virtual networks serves most panels. Two physical switches are used when the design requires physical separation, such as a private I/O ring, or when the control and device networks must not share hardware for security reasons.
- Where does the cellular router go?
- In the panel as a component, on the UPS-backed supply, with its antenna feed through the surge entrance and its Ethernet to the port the design assigns, usually the controller second port or a firewalled switch port. Not on a shelf with a wall adapter.
- Can I plug the field cable straight into the switch?
- It works, and it costs a patch cord. The problem is later: the field cable is stiff, it takes a bend it should not, the port is changed by unplugging a field cable, and the label is on the wrong thing. Couplers are cheap.
- Does the panel network need a firewall?
- Wherever the panel connects to something outside its zone: the radio, the cellular network, the plant business network. A remote site with a cellular router uses the router firewall; a plant panel on the control network relies on the plant boundary firewall. The zone drawing decides.
Related topics
- Network SwitchesSelecting and installing the Ethernet switch in a control panel: managed against unmanaged, industrial ratings and DIN rail mounting, ports and media including fiber, ring protocols, power and grounding, and the configuration documented with the panel.
- Network DrawingsThe two drawings every control network needs: a logical drawing of zones, subnets, VLANs, firewalls, and conduits, and a physical drawing of switches, ports, cables, fiber, radios, and sites. What each shows and why they are sensitive.
- Network SchedulesThe tables behind the network drawings: the address schedule of every device, the switch port schedule of every port, the VLAN table, and the conduit list of what the firewalls permit. How they are built, kept as the single source of truth, and protected.
- Segmenting a Remote SiteA lift station, a well, or a tank site as its own zone: the site firewall and what it permits, the modem as transport with no public address, cameras and extras off the control segment, engineering access through the plant, and local control without the link.
- Dirty or Damaged ConnectorThe most common fiber fault: a connector end face with dust, oil, or a scratch that takes decibels from the link and damages its mate. How to inspect with a scope, what contamination and damage look like, how to clean properly, and when to replace it.
- Panel Surge ProtectionSurge protection of a controller panel as a system: a single entrance and the ground bar it lands on, staged protection on the power, protectors on every loop and data line that leaves the building, the radio feed, layout, and the checklist after a strike.
Direct contact
Have a controls question?
Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.