Campus Area Network โ Multi-Building LAN with Identity, Segmentation & Evidence
A CAN (Campus Area Network) connects multiple buildings across a campus (corporate, university, hospital, plant) into one low-latency, high-reliability fabric.
SolveForce designs CANs that are secure-by-default, identity-aware, and observableโfrom fiber backbones and distribution switching to Wi-Fi 6/6E/7โwith 802.1X/NAC, microsegmentation, and audit-grade telemetry.
Where CAN fits in the stack:
๐ง Fabric โ Networks & Data Centers โข ๐ Access โ LAN โข ๐๏ธ Metro โ MAN โข ๐ Wide โ WAN
๐ Security โ Cybersecurity โข ๐ช Access โ NAC โข ๐ Per-App โ ZTNA / SASE
๐งฉ East-West โ Microsegmentation โข ๐งฐ Cabling/Power โ Structured Cabling โข Racks & PDUs
๐ Evidence/Automation โ SIEM / SOAR
๐ฏ Outcomes (Why SolveForce CAN)
- Low-latency campus fabricโ predictable performance for voice, collaboration, EMR/OT, and AI/edge workloads.
- Identity-first accessโ 802.1X EAP-TLS everywhere; device posture gates before network entry.
- Least-privilege by designโ role/tag-based segmentation with microsegmentation for crown-jewel apps.
- Operational clarityโ standardized VLAN/IP plans, DHCP/DNS/IPAM hygiene, PoE budgets, and change automation.
- Audit-readyโ auth/port/wireless events, changes, and SLOs exported to SIEM with runbooks in SOAR.
๐งญ Scope (What We Build & Operate)
- Backbone & Distributionโ single-mode (SMF) rings/spurs between buildings; distribution switches with 25/40/100/400G uplinks.
- Access Switchingโ 1/2.5/5/10G multigig, PoE/PoE+/UPOE for APs/cameras/phones/badges.
- Wi-Fi 6/6E/7โ high-density RF planning, roaming/handoff tuning, IoT/guest isolation.
- Access Controlโ 802.1X (EAP-TLS), NAC (posture + dynamic VLAN/ACL/SGT), guest sponsor portals. โ NAC
- Segmentationโ VLANs/VRFs/SGT and microsegmentation policies for least privilege. โ Microsegmentation
- Servicesโ DHCP, DNS, AAA (RADIUS/TACACS+), NTP, IPAM; logging & retention.
- Facilitiesโ IDF/MDF layout, fiber/copper plant, UPS/generator integration, environmental monitoring. โ Structured Cabling โข Racks & PDUs
๐งฑ Building Blocks (Spelled Out)
- Topologyโ hierarchical (Access โ Distribution โ Core) or leaf/spine for larger campuses; L3 at distribution/core to bound L2 domains.
- Fiber plantโ SMF for inter-building; MMF inside buildings; diverse conduits/entrances for resilience.
- Wi-Fiโ dual/tri-band with 6 GHz where legal; fast roaming (802.11r/k/v) for voice; separate SSIDs for corp/guest/IoT with distinct policies.
- Identity & Postureโ certificates via PKI; MDM/UEM + EDR health checks; contractor profiles with time-boxed access.
- Segmentationโ role/tag intent compiled to ACL/SGT/NetworkPolicy; IoT/OT in function-specific enclaves; deny east-west by default.
- Cloud/Metro tie-inโ CAN uplinks to MAN ring or colo hub, then private on-ramps to cloud. โ MAN โข Direct Connect
๐ ๏ธ Design Patterns (Choose Your Fit)
A) Identity-First Campus
802.1X EAP-TLS on wired & Wi-Fi, NAC posture gates, dynamic VLAN/ACL/SGT; guest/contractor portal (Internet-only).
โ NAC โข IAM / SSO / MFA
B) Zero-Trust CAN + Per-App Access
C) OT/IoT & Life-Safety
Device profiling, function-based enclaves, strict allowlists; 802.1X where feasible; fallback MAC auth tightly scoped; NDR monitors anomalies.
โ NDR
D) High-Density / Learning & Healthcare
6E for capacity, AP placement by seat/bed counts; roaming and airtime fairness tuned; voice/telemetry QoS lanes.
E) Campus โ DC / Cloud
Inter-building SMF to distribution hubs; routed core to colo; private on-ramps to cloud; SD-WAN for branches.
โ Colocation โข Direct Connect โข SD-WAN
๐ SLO Guardrails (Targets You Can Measure)
| KPI / SLO | Target (Recommended) |
|---|---|
| Access port 802.1X auth (p95) | โค 2โ5 s |
| Wi-Fi association + DHCP (p95) | โค 2โ4 s |
| Roam time (p95, same SSID) | โค 50โ150 ms (voice-safe) |
| One-way CAN latency (p95) | โค 1โ3 ms campus; โค 0.5โ1 ms intra-DC |
| Jitter (one-way) | โค 1โ3 ms |
| Packet loss (sustained) | < 0.1% |
| PoE headroom per switch | โฅ 20% at peak draw |
| Change success rate | โฅ 99% (staged rings + rollback) |
| Evidence completeness | 100% (auth, posture, RF, changes) |
SLO breaches open tickets and trigger SOAR actions (quarantine, RF retune, rate-limit, rollback). โ SIEM / SOAR
๐ Security (Zero-Trust at the Edge)
- 802.1X everywhere (wired & wireless); RA/DHCP Guard & DAI on access; MACsec on sensitive uplinks. โ Encryption
- Per-App Access via ZTNA/SASE; campus policy blocks lateral movement. โ ZTNA โข SASE
- Microsegmentation for workloads and crown-jewel systems. โ Microsegmentation
- Keys/Secrets from vault; short-lived tokens; no plaintext in configs. โ Secrets Management โข Key Management / HSM
๐ Observability & NOC
- Wiredinterface/PoE, EAP states, errors, QoS queues, link events.
- Wi-FiSNR, airtime, retries, client load, roam metrics; DHCP/DNS timings.
- SecurityNAC decisions, guard hits, segmentation denies, ZTNA attach times.
Dashboards, alarms, and monthly reports; escalation runbooks. โ NOC Services โข Circuit Monitoring
๐ต Commercials (What Drives Cost)
- Building count & distances, fiber laterals/conduits, switch/port & PoE counts, Wi-Fi density, NAC/AAA licensing, cabling & UPS.
- Managed vs co-managed support, software subscriptions, maintenance windows.
๐ ๏ธ Implementation Blueprint (No-Surprise Rollout)
1) Survey & goals โ users/devices per building, density, voice/IoT/OT needs, compliance.
2) Fiber & topology โ SMF ring/spur design, diverse entrances, distribution/core architecture.
3) Address & VLAN plan โ per-building/zone scheme; IPAM updates.
4) Identity & posture โ 802.1X EAP-TLS, device certs, NAC policy; guest/contractor flows.
5) Wi-Fi RF โ heatmaps, AP placement, channel/power plans; 6 GHz where supported.
6) Segmentation โ VLAN/VRF/SGT map; microseg intents; default-deny.
7) Services โ DHCP/DNS/NTP/AAA; log export parsers; SIEM dashboards.
8) Pilot & rings โ one building/floor โ campus; staged changes with rollback.
9) Operate & drill โ quarterly RF tune-ups, failover tests, NAC reviews; publish RCAs.
โ Pre-Engagement Checklist
๐ Where CAN Fits (Recursive View)
1) Grammar โ campus fabric in Networks & Data Centers & Connectivity.
2) Syntax โ feeds Cloud and metro hubs via routed cores.
3) Semantics โ Cybersecurity enforces identity, posture, segmentation.
4) Pragmatics โ SolveForce AI predicts congestion/coverage and auto-tunes policy.
5) Foundation โ consistent terms via Primacy of Language.
6) Map โ indexed in the SolveForce Codex & Knowledge Hub.
๐ Build a CAN Thatโs Fast, Secure & Auditable
Key terms in plain language
Open a term for a concise explanation of language used on this page.
Fiber Internet
Internet delivered through strands of glass using light. Fiber commonly supports high capacity, low latency, and strong upload performance, but availability must be confirmed for the exact address.
Latency
The time it takes data to travel between two points. Lower latency improves voice, video meetings, cloud applications, gaming, and other real-time services.
SD-WAN
Software-defined wide area networking. It manages multiple connections and chooses paths based on application needs, performance, and policy to improve resilience and control.
VPN
A virtual private network creates an encrypted connection across another network, commonly allowing remote users or offices to access private resources securely.
Cybersecurity
The practices and controls used to protect identities, devices, networks, applications, and data from unauthorized access, disruption, or manipulation.
Zero Trust
A security model that does not automatically trust a user or device because of its location. Access is continuously verified and limited to what is necessary.
SASE
Secure Access Service Edge combines networking and security capabilities in a cloud-delivered architecture so users and locations can receive consistent policy wherever they connect.
Identity and Access Management (IAM)
The systems and policies that determine who a user is, what resources they may access, and how that access is authenticated and reviewed.