Manufacturing IT

Plant Networks & Industrial Connectivity

Wi-Fi that holds in a racked aisle, VLANs that separate production from office, and cabling built for a building with forklifts in it.

How should manufacturers design their networks?

Plant networks should separate office traffic, production equipment, scanners, voice and cameras into distinct VLANs with firewall policy between them; provide Wi-Fi validated for handheld devices moving through full racks rather than for an empty room; use fiber between buildings and closets; and place IDFs so copper runs stay within spec across large floor plates.

01

Warehouse Wi-Fi is an engineering problem

Steel racking, stacked inventory, refrigeration, high ceilings and moving equipment all attenuate and reflect signal. Handheld scanners have weaker radios than laptops and roam constantly.

Coverage has to be designed along the aisles and validated at device height with the racks loaded. A survey of an empty warehouse describes a building that will not exist next month.

02

What plant network work involves

  • VLAN architecture for office, production, scanners, voice and cameras
  • Firewall policy between segments and controlled vendor access
  • Fiber between office, plant and warehouse buildings
  • IDF placement, rack build, power and environmental planning
  • Access point design for aisles, docks and yards
  • Industrial switching for harsh locations
  • Redundant internet and failover for cloud ERP dependence
  • Labeling and as-built documentation for a working plant
03

Cloud ERP raises the stakes on connectivity

Once receiving, picking and shipping depend on a cloud ERP, an internet outage is a production outage. Redundant connectivity stops being a nice-to-have and becomes part of the operating plan.

04

SCADA & Industrial Network Design

A plant network designed around the Purdue model so control systems stay reachable without becoming a doorway into the business.

The Purdue model organizes a manufacturing environment into levels: Level 0 field instruments, Level 1 controllers, Level 2 local operator interfaces, Level 3 manufacturing operations and the control center LAN, Level 4 enterprise business systems, and Level 5 the internet. The design goal is that a problem in a higher level cannot directly reach a lower level, so a compromised office PC cannot send commands to a PLC.

05

Why the Purdue model matters

Industrial control systems were not designed for the internet. They often run old operating systems, rely on flat addressing, and assume every device on the network is trusted. When they are connected to the same network as the office, ransomware, misconfigured updates, or a single malicious email can stop production.

The Purdue model solves this by separating zones and only allowing traffic through controlled, documented paths.

06

Levels at a glance

  • Level 0 — Field devices, sensors, actuators and the instrument bus
  • Level 1 — PLCs, RTUs, PACs and motor drives that run the process
  • Level 2 — Local HMIs, operator stations and cell/area supervision
  • Level 3 — Manufacturing execution, SCADA servers, historians, control center LAN
  • Level 3.5 — Industrial DMZ: patch, AV, historian replica and jump server
  • Level 4 — ERP, finance, domain, business servers and enterprise desktops
  • Level 5 — Internet, email, web and public-facing services
07

The industrial DMZ is the gate, not the network

The DMZ is the only place where business and control systems are allowed to meet. A historian replica in the DMZ lets ERP and reporting read production data without touching the live SCADA server. A patch server in the DMZ can push updates to isolated equipment. A jump server lets vendors reach the device they support without a tunnel to the rest of the plant.

08

Plant Floor Networking & Industrial Ethernet

The physical layer that lets a plant keep running: hardened switches, fiber, ring topology and cabling built for heat, vibration and metal.

Plant floor networks have to survive conditions office networks never see: high heat, dust, vibration, electromagnetic interference from welders and VFDs, and physical abuse from forklifts and production carts. Industrial Ethernet uses hardened switches, ruggedized cabling, fiber between buildings and cabinets, ring topology for fast failover, and proper grounding and shielding. An office-grade switch in a machine cabinet will fail, often silently, until a line stops.

09

Industrial hardware choices

  • DIN-rail switches with extended temperature ratings
  • Managed switches with IGMP snooping and QoS for real-time traffic
  • SFP ports and fiber for building-to-building and long plant runs
  • PoE for cameras, access points and scanners where power is scarce
  • IP-rated enclosures where needed for dust, oil or washdown
  • Redundant power supplies and ring protocols for fast convergence
10

Topology and resilience

A ring topology lets the network heal around a single cut cable or failed switch in milliseconds. Redundant uplinks from each cell/area back to the control center keep a single point of failure from taking down a whole production zone.

11

Cabling for the environment

Cable that works in a ceiling does not work on a plant floor. We use armored, shielded, oil-resistant, high-flex or metal-clad cable where the path requires it, and we keep cable runs away from VFDs, welders and high-voltage lines.

12

Industrial Protocols & Machine Communication

EtherNet/IP, PROFINET, Modbus, OPC UA and MQTT: how machines talk, and how to get their data out without destabilizing control.

Modern machines commonly use EtherNet/IP, PROFINET or Modbus TCP over Ethernet. Older equipment still uses serial fieldbus such as Modbus RTU, DeviceNet or PROFIBUS. To get data from these systems to ERP and reporting safely, we use OPC UA or MQTT brokers as a translation and isolation layer, so business systems read from the broker instead of polling controllers directly.

13

Common protocols on the floor

  • EtherNet/IP — Common in North American automation, CIP-based
  • PROFINET — Siemens and process-oriented environments, deterministic
  • Modbus TCP / Modbus RTU — Widespread, simple, still everywhere
  • DeviceNet / PROFIBUS / CANopen — Legacy serial fieldbus survivors
  • OPC UA — Structured, secure, modern interoperability standard
  • MQTT — Lightweight publish/subscribe for IIoT and cloud data
14

Why protocol hygiene matters

Industrial protocols are often chatty and sometimes broadcast-heavy. A misconfigured DHCP server, a duplicate IP, or a device leaking multicast traffic can stop a deterministic network. IGMP snooping, VLANs, QoS and careful IP planning are not optional once the machine count grows.

15

Translation and northbound data

We never let ERP or BI talk directly to a PLC. Data flows from the controller to an HMI or SCADA, then to a historian or OPC UA/MQTT broker in the industrial DMZ, and from there to business systems. The return path is blocked.

16

Industrial Wireless & Heat Mapping

Plant Wi-Fi designed for scanners and mobile devices that move through racking, metal and changing inventory.

Warehouse and plant environments are full of signal killers: steel racking, high ceilings, refrigeration units, moving equipment and loaded inventory that changes by the day. A heat map shows actual signal strength at device height along the aisles, so access points are placed where they are needed and not where the ceiling makes it easy. Without it, barcode scanners and forklift-mounted terminals drop sessions, forcing users to re-enter work or lose scans.

17

What the heat map tells us

  • Signal strength at floor level, not just at the ceiling
  • Overlap and handoff zones between access points
  • Dead zones behind racking, coolers and machinery
  • Airtime contention from high-density devices
  • Roaming performance for the actual handheld models in use
  • Validation after inventory is loaded, not when the building is empty
18

Design for the devices that use it

Barcode scanners and vehicle-mounted terminals have different radios and roaming behavior than laptops. A design that looks good on a laptop survey can fail for handhelds. We validate with the same devices operators carry, moving at the same speeds they move.

19

Dedicated SSIDs for OT

Production scanners, AGVs, visitor devices, voice and office traffic should not share the same wireless space. We separate them with SSIDs, VLANs and bandwidth controls so a warehouse employee's phone does not compete with a scan that posts inventory to ERP.

20

Machine Connectivity & IIoT Edge

Connect older machines and brownfield equipment to reporting without letting them touch the control network.

Many productive machines have no Ethernet port, no API and no digital output. We connect them at the edge: add a sensor or tap an existing signal, collect data on a hardened gateway, and push it one-way to a historian or broker. The data flows out for OEE and reporting, but nothing flows back into the machine controller. The machine keeps running exactly as it did, and we do not ask the vendor to change anything.

21

Edge connectivity options

  • Edge gateways with digital, analog and serial inputs
  • Non-intrusive current, vibration, temperature and cycle sensors
  • OPC UA or MQTT brokers for northbound data
  • Cellular/LTE for remote or temporary equipment
  • One-way data diode logic where return traffic is not required
  • Timestamped buffering when connectivity is intermittent
22

Read-only is the rule

The fastest way to create a safety or warranty problem is to send commands back to an old machine. Our edge designs are read-only by default. If a control signal is required, it is engineered separately, documented, tested and approved by the machine owner and vendor.

23

Brownfield first, not rip-and-replace

You do not need all new machines to get useful data. The first phase is often a proof of concept on one or two lines: count cycles, measure uptime, capture downtime reasons. Once the value is proven, the design is repeated across the plant.

24

Multi-Site Manufacturing IT

Standards that let a second or third plant open without reinventing the environment.

Every site adds a network, a set of devices, a set of users and a piece of the inventory picture. Without standards, each location drifts into its own design, and reporting stops reconciling. Multi-site work means a repeatable network and identity template, consistent ERP location and dimension structure, reliable site-to-site connectivity, and one place to see all of it.

25

Standardize before you expand

  • Repeatable VLAN, addressing and equipment standard per site
  • Common identity, device policy and licensing model
  • Site-to-site connectivity with defined failover
  • ERP location, bin and dimension conventions
  • Consolidated inventory and financial reporting
  • Central monitoring across all locations
  • Documented per-site as-builts
  • Deployment runbook for opening a new location
26

Expansion is an IT project whether or not anyone plans it

New buildings need circuits ordered months ahead, cabling designed before tenant improvements finish, and an ERP location configured before the first receipt. Discovering that during move week is expensive.

We keep a deployment checklist so a new site is a repeat of a known process rather than an improvisation.

Common questions

Straight answers, no sales theater.

Can you improve Wi-Fi without recabling the building?

Often yes — placement, channel and power tuning, and adding a few well-placed access points fixes many aisle dead zones. When drops don't exist where coverage is needed, cabling is the honest answer.

Do you work with low-voltage contractors?

Yes. We design and specify, then manage the contractor to that specification so labeling and documentation stay consistent.

Can we implement a Purdue model without replacing our PLCs?

Yes. The model is about network zones and firewall rules, not about replacing controllers. The hard part is usually discovering what is actually on the floor and deciding what each device really needs to talk to.

Does every manufacturer need all seven levels?

No. The model is a reference, not a mandate. A small shop may collapse some levels, but the principle remains: separate control from office and make the path between them intentional.

Can we use standard Ethernet switches in the plant?

In clean, climate-controlled office areas, yes. In machine cabinets, production lines or warehouses, industrial switches are worth the cost because they fail less often and give better diagnostics when they do.

What is ring topology convergence time?

Depending on the protocol and switch hardware, ring healing can happen in under 50 milliseconds. That is fast enough that most production protocols do not notice a single link failure.

Can you connect old serial devices to the network?

Yes, with protocol gateways that convert serial to Ethernet or Modbus TCP to OPC UA. The gateway is placed in the right zone and configured to expose only the data required.

Will MQTT slow down control traffic?

No, if it is separated. MQTT is for telemetry, not control. It sits on a separate network path or VLAN, so production messages keep their priority.

How often should plant wireless be resurveyed?

After any major racking change, seasonal inventory shift, or when new devices are introduced. A static design is usually wrong within a year in a busy warehouse.

Can we fix dead zones without adding APs?

Sometimes — power, channel, antenna and orientation changes can fill gaps. But in many cases, especially in high racking or long aisles, adding an AP is the honest fix.

Will this void the machine warranty?

No, if done correctly. Non-intrusive taps and separate edge gateways do not modify the machine control system. We coordinate with the vendor when anything touches the machine's own network.

What kind of data can we get from old machines?

Cycle counts, run/stop state, uptime, part count, vibration, temperature, power draw and alarms. The goal is enough to calculate OEE and downtime without interfering with control.

Should each site have its own servers?

It depends on latency tolerance and what must keep running during a connectivity failure. Many manufacturers land on local infrastructure for production-critical systems and cloud for everything else.

How early should IT be involved in a new location?

As soon as the lease is being considered — circuit availability and lead times at that address can influence the decision itself.

Reviewed by the Machina IT engineering team ·

Schedule an IT assessment.

We review your network, security posture, cloud tenant and recovery plan, then hand you a plain-language report of what we found and what it means for the business.