GreatLight CNC Machining Factory logo
CNC Machining
Rapid Prototyping
Materials
Industries
News
About GL

Get Instant Quote

Network integration buyer guide

How to Connect CNC Equipment to the Local Network with Segment Isolation

This guide is for plant engineers and sourcing teams who need to connect CNC equipment to the local network without exposing the whole shop floor to one flat subnet. It covers the hardware you need at the machine, the switch and VLAN choices that actually isolate traffic, and the questions to ask a machining supplier before you hand over a controller. Read it before you order hardware or sign off on a network drawing.

VLAN and subnet isolationEdge firewall per cellOne-way data flow12-hour DFM reply
Drilling and milling machines on a line that connect CNC equipment to a segmented local network
Quick answer

Key takeaways

Segment per cell, not per brandOne VLAN per machining cell keeps a single bad controller from flooding the rest of the line.
Keep the controller off the office LANRoute production traffic through a router or firewall, never straight into the business subnet.
Count your data direction firstMost CNCs only need to send status out. Allow inbound only to a specific service and port.
Pick hardware with a swappable moduleShop-floor dust and vibration kill fixed-port units. Spare ports pay for themselves.
Ask the supplier about network options earlyIt changes the controller, the cabinet layout, and your lead time.
Selection table

Isolation options compared

Match the option to how many machines you run and how strict your data rules are.

OptionBest forMain trade-off
Unmanaged switch, one subnet2–3 machines, no shared dataAny fault reaches every controller
Managed switch with VLANsOne cell, 4–12 machinesNeeds a trained person to configure
Edge firewall per cellMixed brands and protocolsOne device per cell to license and patch
Routed subnet per cellMulti-cell plantsMore IP planning up front
Outbound-only data linkStatus and OEE collectionNo remote control of the machine
Air-gapped USB transferOld controllers, no EthernetManual and slow, but fully isolated

The short version

Segment per cell, keep one network path per controller, and test the boundary before production starts. If you need machined enclosures, brackets or panel plates for that design, send the drawing and we will reply with a quotation and free DFM analysis within 12 hours.

Where the risk sits

Why you connect CNC equipment and what that opens up

When you connect CNC equipment to the local network, the first gain is not remote control. It is visibility. Cycle counts, tool life, alarm codes and spindle load can leave the cabinet and land in a dashboard instead of being written on a clipboard. Program transfer stops depending on a USB stick that someone leaves in a pocket. For a plant running 127 machines, that alone changes how fast a job is set up.

The second gain is maintenance. A technician can pull a servo trace or a parameter set from a desk instead of walking the floor with a laptop. That is where the value is real, and it is also where the exposure starts.

A CNC controller was not built as a hardened network device. Many run an older embedded operating system, ship with a default password, and expose file shares or a web page on a port nobody documented. Once that controller sits on the same broadcast domain as your ERP server, a single infected laptop can reach it.

Segment isolation is the answer. It does not mean the machine is offline. It means the machine talks to a small group of approved systems, and everything else is blocked at a boundary you control.

  • 1
    VisibilityCycle time, alarms and tool data leave the cabinet in real time.
  • 2
    Program flowFiles move from CAM to controller without a USB stick.
  • 3
    Attack surfaceEvery added port on a controller is a way in.
  • 4
    Blast radiusSegmentation decides how far one fault can travel.
Judgement criteria

How to judge a network design before you buy

Start with the data. Write down every flow you need: program download, tool offset upload, status polling, alarm push, remote screen. For each one, note direction, protocol and port. If you cannot name the port, the design is not finished. Most CNC protocols use a fixed port; a few use a range, and that range must be documented.

Then set the boundary. A cell of four to twelve machines belongs behind one firewall or one routed subnet. The boundary device enforces the rule that production traffic never enters the office VLAN, and office traffic never enters the cell. If a machine needs a file from a server, put a jump host inside the cell instead of opening the server to the floor.

Then check the physical layer. Industrial Ethernet cable with shielded twisted pairs, M12 or RJ45 connectors rated for the environment, and a switch rated for the panel temperature. Cable run length matters: copper Ethernet is rated to 100 m per segment. Beyond that you need fiber, and fiber changes the switch model.

Finally, verify. A design that has not been tested is a drawing. Ping across the boundary should fail. A port scan from the office VLAN should return nothing from the cell. Confirm both before the line runs production.

  • 1
    Name every flowDirection, protocol and port for each one.
  • 2
    One boundary per cell4–12 machines behind a single enforced edge.
  • 3
    Check cable lengthCopper is rated to 100 m; plan fiber beyond that.
  • 4
    Test the boundaryFailed ping and empty port scan are the pass condition.
Hardware at the machine

What to install at the controller

The controller end is where most designs get sloppy. A controller with a single Ethernet port should not be the only device on the segment. Add a small managed switch in the cabinet so you can mirror traffic, tag VLANs, and replace a port without touching the machine. A five-port managed switch with 24 V DC input and DIN rail mount is enough for one machine.

Watch the power. Cabinet 24 V rails carry noise from servo drives. Use a switch with a wide input range and reverse polarity protection, and keep its power feed separate from the spindle drive feed where the cabinet layout allows.

For older controllers with only a serial port, use a serial-to-Ethernet gateway. That gateway becomes the only network device the controller sees, and it can enforce a single allowed TCP port in each direction. Do not bridge serial straight to a PC with a shared folder.

Label everything. Port number, VLAN ID, IP address and the name of the person who owns the change. On a floor with dozens of machines, an unlabeled switch port costs an hour of troubleshooting.

  • 1
    Managed switch in the cabinetFive ports, 24 V DC, DIN rail, VLAN capable.
  • 2
    Serial gatewayFor RS-232 or RS-485 controllers with no Ethernet.
  • 3
    Separate power feedKeep switch power away from drive power where possible.
  • 4
    Label every portVLAN, IP, owner and change date.
Supplier questions

Choosing a machining partner for network-ready parts

This topic sits at the edge of machining, and that is exactly why it matters in a buyer guide. Enclosures, brackets, panel plates, connector housings and DIN rail adapters for a segmented network are machined parts. If the supplier cannot hold a flatness or a hole position on a panel plate, your switch does not mount, your cable gland does not seal, and the cabinet is not rated.

So ask about tolerance in numbers. A network enclosure panel needs a flat sealing face and consistent hole pitch. GreatLight works to ±0.005 mm on critical features and Ra 0.8–1.6 μm on sealing surfaces, with finish options that include anodizing, powder coating and laser marking. Marking minimum character height is 1.5 mm, which matters if you label ports on the part itself.

Ask about material. Anodized 6061-T6 is common for panel plates and brackets. Stainless 304 or 316L suits wash-down areas. If the part lives near a drive, magnesium or aluminum helps with weight but not with shielding unless you add a conductive finish.

Ask about documentation. A network part is a system part. You want the inspection report, the material certificate and a drawing revision that matches what shipped. GreatLight provides reports on request and holds ISO 9001:2015, IATF 16949:2016, ISO 13485:2016 and ISO 27001:2022.

  • 1
    Tolerance in numbersAsk for the flatness and hole position figures, not adjectives.
  • 2
    Finish for the environmentAnodized aluminum indoors, stainless in wash-down areas.
  • 3
    Marking legibilityLaser marking minimum character height is 1.5 mm.
  • 4
    Paper trailInspection report and material certificate on request.
Pitfalls

Common mistakes that break isolation

The most common mistake is a dual-homed controller. Someone adds a second NIC so the operator can browse the internet from the machine panel, and the isolation is gone. One path per device. If the operator needs a screen, give them a separate terminal on a separate VLAN with no route to the controller.

The second mistake is a flat 192.168.x.x plan reused from the office. Address collisions appear months later when a new cell is added. Allocate a distinct range per cell and document it before the first cable is pulled.

The third mistake is trusting a wireless bridge. A shop-floor access point with a weak password is a door into the cell from the parking lot. If wireless is unavoidable, keep it on its own VLAN, use WPA3, and treat it as untrusted.

The fourth mistake is skipping the spare. A failed switch port at 2 a.m. stops the cell until someone drives in with a replacement. Keep one spare switch and two spare patch cables per cell, and record where they are.

  • 1
    No dual-homed controllersOne network path per device, always.
  • 2
    Unique address range per cellDocument it before cabling starts.
  • 3
    Wireless is untrustedOwn VLAN, WPA3, no route to controllers.
  • 4
    Keep spares on siteOne switch and two patch cables per cell.
Implementation

Step by step: from drawing to a tested boundary

Work in this order. Skipping a step usually means redoing the cabinet.

  • 1
    Inventory every controllerList model, firmware, available ports and the protocol each machine speaks. Note which machines have no Ethernet at all.
  • 2
    Write the data flow listFor each flow, record source, destination, direction, protocol and port. If a port is unknown, find it before ordering hardware.
  • 3
    Draw the cell boundariesGroup 4–12 machines per cell. Assign one address range and one VLAN per cell. Keep the office range separate.
  • 4
    Choose the edge deviceOne firewall or one routed interface per cell. Size it for the number of concurrent flows, not the number of machines.
  • 5
    Specify the cabinet hardwareManaged switch, 24 V DC, DIN rail, shielded cable, M12 or RJ45 connectors rated for the area. Copper runs stay under 100 m.
  • 6
    Configure and labelSet VLANs, disable unused ports, change default credentials, and label every port with VLAN, IP and owner.
  • 7
    Test the boundaryPing across the boundary must fail. A port scan from the office VLAN must return nothing from the cell.
  • 8
    Document and hand overSave the configuration file, the address plan and the as-built drawing. Store a copy outside the plant network.
FAQs

Questions buyers ask

Does segment isolation stop remote support from the machine builder?

No, but it changes how you allow it. Instead of a permanent inbound rule, use a temporary one that opens a single port to a single address for the duration of the session, then closes.

Some builders offer an outbound tunnel from the controller to their service platform. That keeps the inbound path closed and still lets them see alarms.

Can we run one firewall for the whole plant instead of one per cell?

You can, and it is cheaper. The trade-off is that all cells share one policy and one failure point.

If a single cell is compromised, the firewall has to separate it. Per-cell edges make that separation simpler and limit the blast radius.

What tolerance matters on a network enclosure panel?

Flatness on the sealing face and hole position for the gland and connector cutouts. A warped panel will not seal, even with a good gasket.

For most panels, ±0.05 mm on hole position is workable. Critical sealing features can be held to ±0.005 mm when the design calls for it.

Is wireless ever acceptable on the shop floor?

For tablets and handheld scanners, yes, on a separate VLAN with no route to the controllers.

For machine control or program transfer, treat it as untrusted. A weak access point password is an entry point from outside the building.

How do we handle a controller that only has a serial port?

Use a serial-to-Ethernet gateway inside the cabinet. It becomes the only network device the controller sees and can restrict traffic to one port in each direction.

Keep the gateway on the cell VLAN. Do not bridge it to a shared office folder.

What should we ask a machining supplier about network-ready parts?

Ask for tolerance figures, finish options and marking height. Laser marking minimum character height is 1.5 mm, which limits how small a port label can be.

Also ask for the inspection report and material certificate. A panel plate with no paper trail is a risk when the line is audited.

Send your network hardware drawings

Upload the panel plate, bracket or enclosure drawing. We quote in 12 hours and start production within 24 hours on approved files.

12-hour quote±0.005 mm tolerance100% inspectionNo minimum order quantity

Follow

More from GreatLight

We publish setup notes, tooling trials and inspection data from the factory floor.

FacebookTikTokYouTubeLinkedInInstagramThreadsPinterest

Trusted by engineers and manufacturers worldwide

Tesla Ford Motor Company BYD Auto Denso Magna International Boeing Airbus Medtronic KUKA FANUC