A camera works all afternoon and disappears when its infrared LEDs turn on. A WiFi access point boots, but some radios stay disabled. Four spare ports remain on the switch, yet the next camera will not power up. These are different symptoms with one common lesson: switch selection needs a device schedule, a power calculation and a network plan.
This guide explains how to choose and commission PoE switches and network switches for offices, societies, CCTV racks and commercial buildings. It covers the numbers that matter, practical site layouts and the evidence an owner should receive at handover.
What a network switch does
A switch connects Ethernet devices and forwards traffic towards the appropriate destination. A camera sends video to its recorder; an access point carries wireless client traffic into the wired network; a staff PC reaches local services or the internet gateway.
A PoE switch adds a compatible power source to designated Ethernet ports. Power over Ethernet allows data and DC power to share the cable, reducing separate power adapters at cameras, APs and phones. It does not remove the need to design power capacity, cable quality or backup.
| Equipment | Main job | What to check |
|---|---|---|
| Network switch | Connect Ethernet devices | Port speeds, VLAN features, uplinks and capacity |
| PoE switch | Connect and power compatible endpoints | All switch checks plus PoE type, per-port limit and total budget |
| Router / firewall | Route and control traffic between networks | Policies, inspected throughput, remote access and logs |
| PoE injector | Add power to one compatible link | Standard, output power and supported Ethernet speed |
| NVR with built-in PoE ports | Record video and power supported cameras | Internal port topology, power budget and access method |
Some managed switches also route between VLANs. That capability does not automatically provide the same security inspection or policy features as a firewall. Decide where inter-VLAN traffic is controlled and test the intended rules.
How standards-based PoE supplies power
The switch is the Power Sourcing Equipment, or PSE. The camera, phone or access point is the Powered Device, or PD. A standards-based PSE checks for a compatible device before applying normal operating power. Classification and, where supported, negotiation help determine the power allocation.
A compatible lower-power endpoint can use a higher-capability standards-based port. The port rating is available capacity; it does not force the full rated wattage into the device. A non-PoE laptop on a correctly operating IEEE PoE port receives Ethernet connectivity without normal PoE operating power being applied.
Passive PoE is different. It may apply a fixed voltage without the same IEEE detection process. Match passive equipment only when voltage, polarity, pin arrangement and product requirements are explicitly confirmed. A listing that says only “PoE” is insufficient.
PoE, PoE+ and PoE++: read the standard, not just the label
| IEEE standard / type | Maximum PSE output | Approx. available at PD at top class | Typical selection context |
|---|---|---|---|
| 802.3af / Type 1 | 15.4 W | 12.95 W | Lower-power phones and some fixed cameras |
| 802.3at / Type 2 | 30 W | 25.5 W | Many enterprise APs and higher-load cameras |
| 802.3bt / Type 3 | 60 W | 51 W | Devices requiring four-pair higher-power operation |
| 802.3bt / Type 4 | 90 W | 71.3 W | Supported high-demand AP, camera or other endpoints |
The switch-side and device-side numbers differ because cable loss is part of the power path. These are maximum class capabilities, not the demand of every connected device. “PoE++” is used for more than one capability, so confirm the IEEE type and supported class. See the Ethernet Alliance PoE certification resources for interoperability guidance.
Read the endpoint datasheet for its required standard, maximum demand and reduced-power behaviour. Some APs boot on a lower class while disabling functions; other devices may refuse to start. WiFi 6, 6E or 7 branding alone does not establish the required power level.
Port count and power budget are separate calculations
A 24-port switch does not necessarily provide the maximum per-port wattage on all 24 ports simultaneously. The shared PoE budget may be much smaller than the sum of the individual port limits. It can also depend on the installed power supplies, redundancy mode or operating conditions.
Build a device schedule before ordering. Record endpoint model, quantity, maximum power, IEEE type/class, desired Ethernet speed and whether it must stay powered during an outage. Separate device-side consumption from switch-side allocation.
Some switches reserve power according to the detected class rather than the current measured draw. A camera drawing 6 W at that moment may reserve more capacity. Check how the chosen switch accounts for power and do not size solely from a quiet daytime dashboard.
Worked example: a mixed office and CCTV rack
Assume the switch reserves 15.4 W for each of twelve cameras, 30 W for each of four access points and 7 W for each of four phones. The phone allocation is an illustrative model-dependent value. These are switch-side allocations for this example; actual products may reserve differently.
| Device group | Quantity | Example allocation per port | Total |
|---|---|---|---|
| Fixed IP cameras | 12 | 15.4 W | 184.8 W |
| WiFi access points | 4 | 30 W | 120 W |
| IP phones | 4 | 7 W | 28 W |
| Combined allocation | 20 ports | — | 332.8 W |
A 250 W PoE budget is insufficient. A 370 W budget leaves only 37.2 W, even though four physical ports are still free. Using an illustrative 25% planning allowance gives 416 W. That allowance is a project choice for growth and uncertainty, rather than a universal IEEE requirement.
Select a configuration with adequate confirmed capacity, or divide the endpoints between suitable switches. Splitting critical devices can also reduce the effect of a single switch failure, but it adds power supplies, uplinks and maintenance responsibilities.
Camera demand changes after sunset
A camera’s maximum demand can include infrared illumination, heaters, defogging or pan/tilt movement. If testing happens only in daylight, the installation may miss the load condition that causes the fault.
For a CCTV switch, record camera power requirements and test the relevant high-load modes. Check power-denial logs, per-port allocations and the total budget when those modes operate. Also verify the NVR is recording rather than merely displaying live video.
An automatic PoE watchdog can restart a device that fails its configured check, but it should not conceal a recurring cable or power fault. Confirm that the check target and restart settings are appropriate, then retain the underlying fault evidence.
WiFi AP selection: speed and power must both match
An access point can need a multi-gigabit port and a specific PoE class at the same time. A 1 Gbps PoE++ port may supply enough power while restricting wired throughput. A 2.5 Gbps PoE+ port may provide the required speed while falling short of the AP’s full-power mode.
Use the exact AP datasheet rather than a rule that every new AP needs 90 W or 10G. Check its uplink speed, supported power modes, radio restrictions and maximum consumption. Pair switch selection with a real coverage and capacity design; our office WiFi access point placement guide covers the layout work.
Managed, smart and unmanaged switches
| Switch class | Where it can fit | Limits to examine |
|---|---|---|
| Unmanaged | A simple, small network with minimal configuration needs | Limited visibility and usually no configurable VLAN policy |
| Smart / web-managed | Smaller sites needing selected management features | Feature depth varies; confirm required functions individually |
| Fully managed | Offices and integrated ELV sites needing controlled operation | Requires configuration, backup and an accountable administrator |
For an office combining staff, guest WiFi, cameras and controllers, configurable VLANs and usable diagnostics are valuable. Verify the exact features: tagged VLANs, supported authentication, loop protection, event logs, PoE controls and configuration export. The word “managed” alone does not specify them.
Choose only features the team can configure and maintain. A capable switch with a forgotten password and no backup becomes difficult to support.
VLANs and switch ports: make the traffic path explicit
A camera port commonly carries one untagged camera VLAN. An AP may carry tagged staff and guest VLANs plus an agreed management arrangement. The switch uplink must carry the VLANs required at that access switch, with consistent settings at both ends.
Guest isolation requires enforceable policy. A separate SSID or VLAN name is not proof that a visitor cannot reach a camera, printer or management page. Test allowed and blocked flows from real clients.
Document who routes between zones. If routing happens on a core switch, the intended firewall may never see local inter-VLAN traffic. Our firewall setup guide explains how to plan the zone rules.
Uplink capacity: calculate the traffic crossing that link
Count the traffic that actually traverses the uplink, not merely the number of endpoints. If an NVR is attached to the same access switch as the cameras, local recording traffic may stay there. If the NVR is on the core network, those streams cross the access uplink.
For illustration, sixteen cameras averaging 8 Mbps produce 128 Mbps of video payload before overhead and additional streams. A 100 Mbps uplink cannot carry that recording load. A 1 Gbps uplink offers substantially more room, but office clients, live viewing, playback and bursts must also be considered.
For AP-heavy floors, estimate simultaneous application demand and monitor utilisation after occupancy. Advertised wireless PHY rates are not the actual uplink load. Use 10G uplinks where the aggregated requirement and growth justify them.
Link aggregation can distribute multiple flows and provide resilience when properly supported and configured. It does not generally make a single flow run at the sum of all member link speeds. Two loose parallel cables without the correct configuration can also create a switching loop.
Fibre uplinks for distant gates, floors and separate buildings
When a remote camera cluster is beyond a suitable copper route, place an appropriate access switch near that cluster and use fibre back to the main rack. Choose fibre type, optics, connector arrangement and link speed together.
Ordinary fibre carries data, not the PoE electrical supply. The remote switch requires local power and the agreed backup. Cabinet temperature, dust, water exposure and electrical protection matter as much as the fibre specification.
Fibre also avoids a metallic data connection between buildings, although the local electrical installation and remaining outdoor copper still need appropriate protection. Keep a strand schedule and test results so a later fault can be located.
Copper cabling: the switch cannot repair a poor link
For conventional structured copper Ethernet cabling, plan within a 90 m permanent link and a 100 m channel including patch cords. Use the actual route length, not the straight-line drawing distance. Specialist extended-reach modes are product-specific and may reduce data speed; they should not be treated as ordinary gigabit certification.
Use genuine solid-copper installation cable, compatible connectors and suitable factory patch cords. Select Cat6 or Cat6A from the target speed, distance, power demand and project specification. Avoid copper-clad aluminium and verify the installation material rather than relying on the outer jacket print.
PoE introduces resistance and thermal considerations. Cable bundles, ambient conditions and conductor size affect the design. Follow the cable manufacturer’s guidance and the specified installation requirements for high-power bundles.
Include DC resistance and resistance-unbalance checks where specified for PoE performance. They help investigate power delivery problems that a simple continuity tester cannot explain. Use the correct certification setup and keep labelled results; see our Fluke Testing guide and structured cabling guide.
UPS sizing: include the endpoints powered by the switch
The UPS sees switch AC input power, which includes switch electronics, power-supply losses and the power delivered to endpoints. The advertised PoE budget is available output capacity, not necessarily the present AC demand.
Build a complete backup load list: switches, firewall, NVR, controllers and any other required equipment. Avoid counting the cameras twice if their power is already included in the measured PoE switch input.
For an illustrative measured 450 W rack load and a 30-minute target, the delivered AC energy requirement is 225 Wh. The battery must provide more because of inverter losses, usable discharge limits, ageing and operating conditions. Select from the UPS manufacturer’s runtime curve for the chosen configuration and validate under representative load.
Check both the UPS watt rating and VA rating, its supported batteries and recovery behaviour. A backup only on the NVR does not keep recording alive when camera switches lose power.
Rack layout, cooling and switch environment
Mount switches where operators can reach ports and read labels. Keep ventilation openings clear and coordinate patch panels, cable managers, fibre trays and PDUs in a rack elevation. Maintain cable bend radius and avoid unsupported strain on connectors.
Check the switch operating-temperature range against the cabinet environment. A closed gate box can become much hotter than the shaded outdoor air. Fanless construction is not a guarantee that a switch can survive a sealed hot cabinet.
Record rack and metallic-pathway bonding requirements with the electrical design. Outdoor copper, camera poles and cabinet supplies need a coordinated protection approach suited to the site.
A troubleshooting method that saves time
First decide which function failed: power, Ethernet link, network reachability or application operation. Preserve the switch logs and note the time, affected port, device name and operating condition before repeatedly rebooting equipment.
| Symptom | First checks | Useful next evidence |
|---|---|---|
| No endpoint power | Port PoE state, compatible type/class, remaining budget | Detection status and power-denial log |
| Powered device, no link | Port enabled, cable termination, endpoint Ethernet state | Known-good short cable and port comparison |
| Link active, device unreachable | VLAN, IP address, gateway and policy | MAC learning, ARP and permitted service tests |
| Night-time camera restart | IR/heater demand and available allocation | Time-correlated power logs and cable measurements |
| AP running with reduced features | Negotiated power mode and port speed | AP status page and datasheet comparison |
| Several devices fail together | Switch supply, UPS, uplink and cabinet temperature | Shared event timestamp and upstream alarms |
Change one variable at a time. A successful test on a short patch lead helps isolate the installed cable path, but does not replace certification of that path. Restore the original configuration and retest the actual fault condition before closing the issue.
Commissioning and handover
- Reconcile each occupied switch port with device ID, location, cable ID and VLAN.
- Check negotiated Ethernet speed and endpoint PoE operating mode.
- Record total allocated and measured PoE power under the agreed operating conditions.
- Test CCTV recording and export, AP applications and other attached services.
- Verify guest isolation and restricted management access.
- Test the agreed UPS runtime and recovery after restoration.
- Save switch configurations, firmware details, optical module records and administrator ownership.
- Provide cable certification reports, port maps, rack elevations and service contacts.
Critical installations should also define failure expectations. A second switch or link adds value only when the topology, device support and failover behaviour are understood and tested. Backup configuration is recoverability; it is not automatic continuity.
What to specify in a switch BOQ
- Required copper port quantity and minimum speed for each device group.
- Number of PoE ports and required IEEE type/class by port group.
- Minimum usable PoE budget with the supplied power configuration.
- Uplink quantity, speed, fibre type and compatible optics.
- Required VLAN, loop-protection, monitoring and management features.
- Operating environment, mounting arrangement and ventilation requirements.
- Mains and UPS scope with the required runtime and validation method.
- Configuration, labelling, certification and handover deliverables.
State spare ports and spare watts separately. A spare gigabit port without enough PoE capacity may serve a PC but not the next access point. Include licence or subscription requirements if the selected management platform needs them.
Common questions about PoE switches
Will a 90 W port damage a 15 W camera?
A compatible standards-based PSE supplies power through the specified detection and classification process. Its maximum rating is capacity, rather than forced consumption. Confirm interoperability and avoid confusing passive injectors with IEEE PoE.
Do all WiFi 7 access points need PoE++?
No. Requirements depend on the exact AP. Some use PoE+, some require higher-power operation, and some support restricted modes at lower power. Check the datasheet and validate the negotiated mode.
Can a 100 Mbps camera port be sufficient?
It can be sufficient for a device whose supported rate and actual traffic fit comfortably within that link. The aggregated uplink still needs its own calculation. For new mixed office infrastructure, select speeds that match the full endpoint and growth plan.
Can an NVR’s PoE ports replace an external switch?
For a small compatible camera installation, they can simplify the layout. Check power budget, camera access, internal network behaviour and expansion. They do not automatically serve as a managed access switch for office users and APs.
Does a link light prove the PoE cable is good?
It proves a link is present at that moment. Category certification, power measurements and operational testing provide different evidence. Keep all the tests required by the project acceptance specification.
APYS Projects recommendation
For a new office or integrated society installation, choose a switch from the endpoint schedule and operating requirements. Confirm port speed, PoE class, shared budget, uplink capacity, security features and UPS load before ordering.
APYS Projects handles structured cabling, Fluke Testing, WiFi, firewall setup, CCTV and ELV systems, together with the required electrical coordination. We can plan rack layouts, switch configuration, camera and AP connectivity, testing and documented handover for offices, societies and commercial buildings.
Need a PoE switch sized for your site? Share your camera/AP models, quantities, cable distances and backup requirement. Enquiries: Purchase@apysprojects.com · +91 9921490342 · Contact APYS Projects.
Technical references
Further reading: Ethernet Alliance PoE certification, Cisco PoE troubleshooting and allocation, Fluke Networks four-pair PoE guidance, Fluke Networks installation guide and cable testing guidance. Verify the final design against the selected equipment datasheets and project requirements.