An IP surveillance design must account for camera power, network bandwidth, recording capacity, retention and controlled access.
Practical example: 16-camera IP surveillance network
Camera count alone cannot determine bandwidth or storage requirements.
Scenario: Sixteen IP cameras record to an NVR and are powered from PoE switches.
The design checks aggregate camera bitrate, switch uplink capacity, PoE budget, NVR recording capability and storage retention. Cameras are placed in a dedicated network segment with access limited to the systems and users that need it.
Decision: Camera count alone cannot determine storage or network requirements. Resolution, frame rate, codec, scene activity and retention period all matter.
Common mistakes and selection checklist
Common mistakes
- Sizing NVR storage from camera count alone.
- Ignoring switch PoE budget and uplink bandwidth.
- Putting cameras on the ordinary user LAN with broad access.
What happens if you get it wrong?
Retention can be much shorter than expected, video can be lost or degraded under load, and poorly segmented cameras can increase the network's security exposure.
Selection checklist
- List camera resolution, frame rate, codec and expected recording mode.
- Estimate aggregate bitrate and required retention.
- Check NVR channel, throughput and storage capability.
- Verify PoE budget and switch uplinks.
- Segment camera traffic and restrict management access.
Camera traffic
Video bitrate depends on resolution, frame rate, compression, scene complexity and camera configuration. Multiply the expected bitrate by the camera count when estimating switch uplinks and recording traffic.
PoE power
The PoE switch must provide enough compatible ports and total power budget. Outdoor, PTZ and heated cameras can require more power than basic fixed cameras.
Recording storage
Storage depends on aggregate bitrate, recording schedule, retention period and redundancy. Motion recording can reduce storage, but actual results depend on activity.
Network segmentation
Cameras can be placed in a dedicated VLAN with controlled access to the NVR, management stations and required services. A VLAN alone does not define the security policy.