KNOWLEDGE CENTRE

Security Cameras, NVR & KVM Infrastructure

Practical infrastructure guidance for IP camera networks, NVR storage, PoE, switching, cabling, bandwidth and KVM planning.

Book 5 | Chapter 1

Chapter opening

Chapter 1 moves from the course overview into security cameras, nvr & kvm infrastructure. The aim is not to memorise product menus or commands. The reader should understand what problem the technology solves, how it fits into the wider security and cctv technical textbook, what normal operation looks like, and how to prove the result in the field.

This is the first chapter in the sequence, so it establishes concepts that later chapters build on.

Security textbookChapter 1

Learning objectives

  • Explain the main purpose of Security Cameras, NVR & KVM Infrastructure in plain language.
  • Trace CPU, memory, network and storage from a VM through the hypervisor to physical hardware.
  • Use evidence to separate a design problem from a configuration or physical fault.
  • Describe the business impact of a failure and the evidence required for handover.

Why this matters in a real company

Virtualization lets a company run several independent server workloads on fewer physical machines. The benefit is flexibility and easier recovery, but one badly designed host can also become a large single point of failure.

Course: Security and CCTV Technical Textbook

PLAIN ENGLISH

Technical terms used in this chapter

You do not need to memorise the jargon first. Understand what each term does and why somebody running a company would care about it.

Backup

Backup

An independent recoverable copy of data or system state.

In everyday business: It is the safety net for deletion, corruption, ransomware, hardware loss or major mistakes.

VLAN

Virtual LAN

A logical Layer 2 network that separates devices even when they use the same physical switches.

In everyday business: Staff, cameras and guest WiFi can be kept apart without buying a separate switch for each.

RAID

Redundant Array of Independent Disks

A method of combining drives for capacity, performance and/or tolerance of certain drive failures.

In everyday business: A failed disk does not always mean immediate data loss, but RAID is not a backup.

NAT

Network Address Translation

A router or firewall function that changes IP addressing as traffic crosses a boundary.

In everyday business: Many private office devices can share one public Internet address.

PAT

Port Address Translation

A form of NAT that lets many internal connections share one public address by tracking transport ports.

In everyday business: Hundreds of users can browse the Internet through one public IPv4 address.

PoE

Power over Ethernet

Technology that sends DC power and Ethernet data over the same twisted-pair cable.

In everyday business: A camera or access point can be installed with one network cable instead of a separate power outlet.

KVM

Kernel-based Virtual Machine

Linux kernel virtualization technology that turns Linux into a hypervisor.

In everyday business: A Linux server can run Windows and Linux virtual machines.

VM

Virtual Machine

A software-defined computer running on a hypervisor.

In everyday business: It behaves like a separate server even though it shares physical hardware.

See the complete plain-English glossary

BUSINESS TRANSLATION

What this means outside the server room

This topic matters because technical infrastructure exists to support everyday business operations. Understanding the purpose makes it easier to choose the right design and justify the cost.

RAID

What it means: RAID combines several drives so the storage system can keep operating through certain drive failures, depending on the RAID level.

In normal business language: Think of RAID as keeping the business open when one filing cabinet drawer breaks. It helps availability, but it does not protect you if somebody deletes the wrong folder, malware encrypts the files, or the whole building is lost.

Why the decision matters: Use RAID to reduce downtime from disk failure, and use backup for recovery from deletion, corruption, ransomware and larger disasters.

VLAN

What it means: A VLAN creates a separate logical network even when devices share the same physical switches.

In normal business language: Think of one office building with separate departments using the same corridors but different access-controlled areas. Staff, cameras, voice and guests can share the same switching hardware without all being in one open network.

Why the decision matters: Use VLANs to separate traffic for security, performance and easier troubleshooting without buying a separate physical switch for every department.

Hypervisor

What it means: A hypervisor lets one physical server run several isolated virtual machines.

In normal business language: Think of one office building divided into secure independent suites. The building is shared, but each tenant operates separately.

Why the decision matters: Virtualization reduces hardware sprawl and improves flexibility, but the physical host becomes important because several business systems can depend on it.

Virtual Machine

What it means: A virtual machine is a software-defined computer with its own operating system, memory, CPU allocation, disks and network interfaces.

In normal business language: It behaves like a separate server even though several VMs may share one physical machine.

Why the decision matters: VMs are useful for separating roles such as domain control, file sharing and applications while keeping management and recovery flexible.

Backup

What it means: A backup is an independent recoverable copy of data or system state.

In normal business language: Think of it as having a duplicate of important company records stored safely away from the live filing cabinet.

Why the decision matters: A backup only counts if it can be restored. Test recovery, not just backup completion.

Firewall

What it means: A firewall controls which network connections are allowed between users, systems and external networks.

In normal business language: It is a security checkpoint between parts of the company network. It should allow legitimate work while blocking unwanted access.

Why the decision matters: Firewall rules should describe real business flows such as 'staff may reach accounting on HTTPS', not unexplained broad permits.

1.1 IP camera design is a network design problem

An IP camera system is not only a camera-and-recorder purchase. The installer must account for endpoint count, switch ports, PoE demand, camera bitrates, uplink capacity, recording storage, VLAN/IP design, cable route, outdoor environment and UPS requirements.

Camera bitrate and recording storage

Storage is driven by the actual configured or measured bitrate over time, the number of cameras and the recording period. Resolution by itself is not enough because codec, frame rate, scene complexity, compression settings and variable bitrate behaviour can materially change storage use. Netcomtech's camera storage calculator therefore asks for bitrate rather than inventing a bitrate from megapixels.

Open the IP Camera Recording Storage Calculator.

PoE design for cameras

  • Identify each camera's published PoE requirement.
  • Confirm each switch port can supply the required type/class.
  • Add the endpoint loads and compare them with the switch's total PoE budget.
  • Include switch and camera loads in the UPS design if recording must continue during power interruptions.
  • For outdoor camera runs, follow the camera, cabling and surge-protection manufacturer's requirements for the installation environment.

Switch uplinks

Camera edge switches aggregate multiple video streams onto one or more uplinks. Calculate the expected aggregate traffic from the actual camera bitrates and add design headroom as an explicit user assumption. Do not assume that a switch with enough physical ports automatically has enough PoE budget or uplink capacity.

VLAN and addressing

Separate camera networks can simplify security policy, broadcast scope and troubleshooting, but the exact VLAN and firewall design depends on the customer's architecture. Document every camera's switch port, VLAN, IP method, recorder association and physical location. Avoid placing passwords in a general handover sheet.

NVR and storage planning

Check the recorder's published maximum camera count, supported codecs, inbound bandwidth, drive compatibility, storage architecture and retention features. If RAID is used, remember that RAID availability is not a substitute for an independent backup of footage that must be preserved.

KVM planning

KVM requirements depend on video interface, resolution, USB support, number of target systems, local vs IP access, rack-console requirements and remote-management policy. For IP KVM, also plan management addressing, authentication, firmware maintenance and access-control rules.

Rack integration

Record NVR, switch and KVM rack positions, power feeds and cable destinations. High-density camera deployments can create significant patching and PoE load in one cabinet, so rack power and cable management should be designed before the equipment arrives.

Related resources

PoE Field Guide | Troubleshooting Centre | Rack Handbook | Security devices at Server Warehouse | KVM devices | KVM with screens

1.2 Go deeper: installation and configuration

Use the procedure-driven playbooks when you need the practical installation, configuration, verification and troubleshooting steps.

WORKED BUSINESS SCENARIO

Scenario: five business servers now run on one host

The company consolidates a domain controller, file server, application server, monitoring server and Linux service onto one virtualization host.

What the chapter teaches us: Hardware use is improved, but one host, one storage pool or one network uplink can now affect several services at once. Virtualization changes the failure domain rather than removing it.

Think it through

  1. Which physical components can now stop all five services?
  2. What must be backed up independently?
  3. How would you prove that network and storage paths are resilient?
PRACTICAL WORK

Hands-on lab

Create one small lab VM, connect it to the intended virtual network, install an OS, record its vCPU, RAM and disk allocation, and prove network and storage paths.

Troubleshooting exercise

A VM is running but cannot reach the LAN. Check guest IP, guest firewall, vNIC, virtual switch or bridge, VLAN, host uplink and physical switch in that sequence.

Chapter field checklist

  • I can explain the subject without relying only on acronyms.
  • I can draw or describe the main traffic, storage, power or service path.
  • I know what normal operation should look like.
  • I know which logs, counters or test results prove the result.
  • I can explain the business impact if this component fails.
  • I would document the final configuration and evidence at handover.

Chapter summary

Security Cameras, NVR & KVM Infrastructure should now be understood as a business service with a technical implementation, not simply a collection of commands or product names. The important habit is to know the purpose, understand the dependencies, measure the result and document what was proven.

END OF CHAPTER

Review questions

  1. Explain the subject in plain language to a business owner.
  2. List the main dependencies that must be healthy before this service can work.
  3. Describe one realistic failure and the first three pieces of evidence you would collect.
  4. Explain what should be documented at handover.
  5. Which physical failures can affect multiple VMs at once?
  6. Why is a VM checkpoint not automatically a backup?

A good answer should explain the reason, not only repeat a product name or command.