WestPoint · Networks · Fortinet
The question is not whether the cameras reach. It is what else they reach.
Fortinet is not a switch house with a firewall alongside: it is a firewall with a network around it. And in video that points at one of the important decisions of the project, which is isolating the cameras from the rest.
What kind of manufacturer it is, and how you recognise it.
Fortinet — Firewalls, segmentation and networking with security built in. The order of that sentence is not accidental: security first.
Fortinet puts first that all the traffic passes through one place where it is looked at and decided on. The central product is the firewall, and around it there are switches and Wi-Fi access points administered from that same firewall. For a company with a small IT team that has a big advantage: a single screen governs the security rules, the ports and the Wi-Fi.
What it gives up is depth on the switching side. Its switches handle access and PoE well, and they are not the equipment you put at the centre of a campus network where throughput and millisecond recovery are tuned. Whoever buys Fortinet buys security with a network included, and it is worth buying it knowing that.
You recognise it at the door of the network: where there is a connection with the internet, with other sites or with third parties, and in companies that have decided that their inside network gets filtered too and not only the edge. It is the brand that turns up when somebody has taken seriously the question of what can talk to what.
How it is administered.
There is a full web interface and a command line behind it for what the interface does not reach. The configuration is exported to a file, compared and restored, which is what allows you to work in an orderly way. And there is a central tool to administer many firewalls at once with common policies, which is what companies with many branches use.
Isolating the cameras, which is the decision nobody argues with and almost nobody takes.
The area already covers why the cameras do not go on the office network. Here comes the fine part: what exactly is allowed.
Separating the cameras into their own network is the first step and it is not the last. A separate network still needs to talk to something: the cameras with the recorder, the guard's position with the recorder, the system with the time server, somebody from outside to look. Each of those conversations is a rule, and the difference between a well-made installation and a badly made one is whether those rules are four specific lines or one that says «let everything through».
The short list, which fits on a napkin: the recorder talks to the cameras and only over the ports it needs. The cameras do not talk to each other — there is no reason at all for one camera to see another, and if one is compromised, it must not be able to jump to the rest. The cameras do not go out to the internet, not even to update themselves: if they have to be updated, the update is taken to them. And nobody from the office network gets into the camera network; whoever watches, watches through the recorder.
And the honest side of the same argument: what is NOT a good idea is making the video from the cameras to the recorder cross the firewall. That traffic is a constant, enormous flow, and pushing it through the place where everything is inspected means paying for a firewall five times bigger for nothing. The good drawing is different: the cameras and the recorder on the same side, talking directly, and the firewall watching what goes IN and OUT of that bubble — the operator position, the way out to the outside, the integration with other systems. Much less machine, much more security.
Where it fits well, and where we would not put it.
The first is easy. The second matters and has a number behind it.
It fits as a border: between the security network and the company's, between the company and the internet, between sites, and in front of any third-party access — the maintenance firm coming in to look at a recorder, the centre that receives the alarms. It also fits as the complete network of a medium-sized installation, with its switches and its Wi-Fi administered from the same place, and there the simplicity of having a single screen is worth money.
We would not put it at the centre of a large video network doing the work of a campus switch: concentrating hundreds of cameras, tuning queues, millisecond recovery and fine multicast is not its ground, and forcing it means paying more for less.
And we would not size it by the big figure on the datasheet, which is the mistake we have seen made most often with this class of equipment. That figure is measured with almost everything switched off. As soon as content inspection and threat analysis are switched on, the traffic the unit really moves falls to a fraction — and if the video from forty cameras had to pass through there, the installation chokes and nobody understands why. It is sized by the with-everything-switched-on number, and it is designed so that the video does not pass through there.
What really decides things in a video project.
Five, and the first two are the ones that ruin the most budgets.
- The firewall's real throughput with inspection switched on, not the headline one. And the prior decision: what traffic crosses it. If the honest answer is «the video too», the drawing has to be redone before buying the equipment.
- The switches' power budget, with the winter consumption of the outdoor cameras and counting that the power is reserved by the class the camera declares and not by what it uses. It is the same sums as always and here they are forgotten more often, because the conversation has been about security and nobody has talked about watts.
- What happens when it goes down. A firewall at the border is a single point through which everything passes: either there is a pair that takes over on its own, or you have to accept that its failure leaves the installation with no view from outside and no alerts to the centre. Both answers are legitimate; what is not legitimate is not having given one.
Licences and subscriptions, and what happens when they expire.
Here the model is clear and expiry has concrete consequences, and they are not Meraki's.
The equipment is bought and the subscriptions are paid by period: the threat signature service, the content filtering, the antivirus and the manufacturer's support, usually in bundles. It is a predictable annual cost and it has to go into the client's operating budget from day one, because it is half the point of the product.
When they expire, the firewall does not switch off. It carries on filtering with the rules written into it, carries on separating the networks and carries on letting through only what is allowed. What stops arriving are the new signatures, the content lists and the right to update and to open a case. Put plainly: the part that protects you from what you already knew about carries on working; the part that protects you from this month's does not.
Who administers it when we leave.
This is the brand on this list where the boundary with the client is clearest, and not by accident.
A firewall belongs to IT. If the client has an IT department, the equipment is theirs, the passwords are theirs and they write the rules: there is no good reason for the camera installer to own the security of somebody else's network, and plenty of reasons for the opposite. Our job is to ask for what we need precisely and to check that it works.
And the tone, which is the same on all ten: turning up at an IT team that already has its firewall brand and telling them to fit another is the quickest way to stall the project. Almost always what is needed is not to change their firewall: it is to write four rules properly in the one they already have. We adapt to what is there and only propose equipment when it is genuinely missing, with the sums done and before signing.
Where to go next.
The separation of networks, the video traffic and what happens when a cable is cut are covered in the area, and they hold for any brand.
Get started
Are your cameras on the same network as the accounts department?
If nobody knows for certain, they are. Tell us how many cameras there are, where the recorder is, who watches them and from where, and which firewall you have fitted. We will tell you what gets fixed by writing four rules in what you already have and what genuinely has to be bought.