Campus LAN & Access Networking
Enterprise access and distribution switching with PoE+, micro-segmentation and identity-based access — the quiet layer everything in your building depends on.
What we deliver
The campus LAN carries everything: laptops, phones, cameras, access controls, the CEO’s video call. It’s also where unmanaged risk concentrates — flat networks where a compromised IoT sensor can reach the finance VLAN, and closets of aging switches nobody dares to touch.
Enrich builds campus networks with security as a design property: identity-based access control (NAC) so the network knows what’s connecting, micro-segmentation so devices reach only what they should, PoE+ engineering for the device fleet, and resilient distribution design that survives a closet failure. Our campus work spans corporate offices to high-density industrial sites — including a 150 KM integrated network for one of Asia’s largest refinery campuses.
The result is a LAN that’s boring in the best way: predictable, observable and safe to change.
What's included
Access & Distribution Switching
Resilient wiring-closet-to-core design with fast convergence — a single failure never becomes a floor outage.
PoE+ Engineering
Power budgets sized for cameras, APs, phones and IoT — including the ones facilities will add next year.
Network Access Control (NAC)
Identity-based port security: every device authenticated and profiled before it gets a VLAN, not after.
Micro-segmentation
Policy that keeps CCTV, guests, OT and corporate traffic in their lanes — breach containment built into the access layer.
Industrial & High-Density LAN
Hardened networking for plants, refineries and campuses where environment and distance break office-grade designs.
Lifecycle Refresh
Live-network switch refreshes executed closet by closet — end-of-life risk retired without user-visible disruption.
From assessment to operations
Assess
Physical survey, traffic and power audit, and a security review of what’s currently plugged in (the answer usually surprises).
Design
Topology, VLAN/segmentation model, PoE budget and NAC policy — engineered for the building you have and the devices you’re adding.
Deploy
Staged rollout with per-closet cutovers — users notice faster Wi-Fi and nothing else.
Operate
Monitoring, configuration governance and refresh planning — or a clean handover with as-built documentation.
Delivered on
Common questions
Our LAN “works” — why invest in it?
+
Because working and safe aren’t the same. A flat campus network makes every printer, camera and sensor a potential pivot into corporate systems, and aging access switches fail without spares or patches. The typical trigger is an audit finding, an office move or an IoT rollout — cheaper to fix by design than under pressure.
What does NAC give us in practice?
+
Visibility first: an authenticated inventory of every device on every port — most estates discover hundreds of unknowns. Then control: a contractor laptop lands in a restricted segment automatically, a spoofed camera gets quarantined, a leaver’s device stops working the day access is revoked. It turns the LAN from an open socket into a policy-enforcing system.
Can you refresh switches during business hours?
+
Mostly, yes: staged per-closet cutovers with pre-provisioned replacements typically cost users seconds of link flap, scheduled around what each floor does. Genuinely disruptive steps (core/distribution changes) are planned into agreed windows. A refresh plan that requires a company-wide shutdown is a badly planned refresh.
How do you handle OT and IoT devices that can’t run agents?
+
Profiling instead of agents: NAC fingerprints devices by behavior and characteristics, assigns them to tightly scoped segments, and alerts when a “camera” starts acting like a laptop. For industrial environments we design OT segmentation zones aligned to how the plant actually operates — as we did across a 150 KM refinery network.
Related services
Ready to get started?
Free consultation — we'll analyze your environment and recommend the right approach.