Serving Katy, Houston & surrounding areas • Licensed & Insured • 20+ Years (832) 359-2425
EVOTECH technician working inside a network cabinet
Fast EVOTECH reply

Start your EVOTECH request in under a minute.

1 minsimple request
Texaslocal and remote help
Inboxlead saved and emailed
Get a fast EVOTECH response Most requests only need name, phone, city, and service.
Choose a service and EVOTECH will guide the next step.
(832) 359-2425

EVOTECH uses your details only to reply, quote, schedule, or help with your requested service.

South Conroe · I-45 corridor · Offices, retail & large homes

Camera IP Addressing and VLAN Planning for Conroe 77384 Businesses and Larger Homes

Along the I-45 frontage in south Conroe, a camera system usually shares a building with card terminals, a phone system, guest Wi-Fi and an office network that someone else already manages. In the newer two-story neighborhoods off the same corridor, one house can carry a dozen cameras, a doorbell, smart locks and a mesh Wi-Fi kit. In both settings the cameras need an address plan that fits the network already in place, written before the first cable is pulled rather than improvised on a ladder. Here is how EVOTECH builds that plan. We are based in Katy/Houston and travel to south Conroe, so phone first and we will confirm a slot for your specific 77384 address.

Address plan before installCamera VLAN & firewall rulesWorks with your IT providerTime sync for evidenceHandover documentation

Why cameras on a shared network need a plan of their own

Cameras are the heaviest continuous users on most small-business networks. Each one pushes a main stream and a lower-resolution substream to the recorder around the clock, and many also announce themselves with discovery traffic. Drop them onto the same flat network as the registers and office computers and three things tend to follow.

  • Collisions. The installer picks addresses that look free on install day. Months later the IT provider adds a printer, or the DHCP pool grows, and two devices land on one number.
  • Exposure. Inexpensive cameras often try to contact cloud services on their own, and on a flat network any infected laptop can reach their login pages directly.
  • Finger-pointing. When something breaks, the camera installer blames the network and the IT provider blames the cameras, because nobody wrote down who owns which addresses.

An address plan fixes all three before they start. It is a short document, and it is the single most useful thing a camera contractor can hand your IT provider.

What a written camera address plan looks like

This is an illustrative layout for a single-suite office or retail space. The exact numbers change per site; the structure is what matters.

BlockExample rangeWhat lives thereHow it is assigned
Gateway.1Firewall or router interface for the camera networkStatic
Infrastructure.2 to .9Managed PoE switches, uplinks, bridgesStatic
Recording.10 to .19NVRs, a video management server, storageStatic
Cameras.20 to .149Grouped by area: exterior in one run, interior in another, so an address tells you where to lookStatic or reservation
Doors and intercoms.150 to .169Access control panels, door stationsStatic
Service pool.200 to .230Technician laptop, temporary devicesDHCP

The example assumes a /24 network with 254 usable addresses, which covers almost any single building. Picking the range itself deserves thought. We steer away from 192.168.0.x and 192.168.1.x for business camera networks, because staff who connect from home over a VPN very often have one of those exact ranges on their home router, and overlapping subnets break VPN routing in confusing ways. A less common block inside 10.x.x.x or 172.16 to 172.31 avoids that, and your IT provider usually has a preference we follow.

Giving cameras their own VLAN, and the rules around it

A VLAN separates camera traffic logically on the same physical switches. Camera ports are set as untagged access ports on the camera VLAN; links between switches and the firewall carry it tagged alongside the office and guest networks. Then the firewall decides who may talk to whom:

  • Cameras to recorder: allowed.
  • Cameras to the internet: blocked. They do not need it when the recorder handles time, alerts and remote access.
  • Recorder to the internet: limited to the services you choose, such as the manufacturer’s remote-viewing relay and firmware checks.
  • Office network to recorder: allowed only on the viewing ports, for the people who watch footage.
  • Guest Wi-Fi to anything on the camera side: blocked.

One technical consequence surprises people. ONVIF discovery, the feature that lets a recorder find cameras automatically, relies on multicast that does not cross VLAN boundaries. Cameras on a segmented network are added by address rather than discovered, which is one more reason the plan must exist before installation day.

For a small retail suite with four to eight cameras, a PoE recorder can be a sensible alternative: its back-panel ports form an isolated camera network by design, and only the recorder’s single LAN connection touches the office network. It stops scaling once you outgrow its port count or need cameras far from the recorder.

Gateway, DNS and time: the settings that decide whether footage holds up

Gateway. If the recorder sits on the same VLAN as the cameras, a camera can technically work without a gateway. The moment a viewing station or recorder sits on a different VLAN, every camera needs a correct gateway, or its replies have no route back and live view fails in ways that look random.

DNS. Anything that uses a hostname, including internet time servers, email alerts and cloud relays, fails silently without a DNS server. Blank DNS fields are one of the most common findings on systems we inherit.

Time. When footage is handed to an insurer or to police after an incident, the timestamp is part of the evidence. Camera clocks drift. We point the cameras at the recorder or an internal time source, point the recorder at a reliable external source, and confirm the time zone is set to Central with daylight saving handled, so a clip from November does not read an hour off.

Remote viewing for owners and managers without opening ports

Forwarding recorder ports to the internet is still common and still a bad idea: exposed recorders are scanned constantly. The workable options are the manufacturer’s relay app, where the recorder makes an outbound connection and the phone meets it there; a VPN into your firewall, which your IT provider controls; or a video management platform with its own secure remote gateway. Whichever you choose, each person gets an individual account on the recorder with only the rights they need, rather than everyone sharing the admin login.

The same discipline in a large 77384 home

The two-story homes in the master-planned sections of south Conroe bring a residential version of the same problem. A common pattern: the internet provider’s gateway runs its own network, a mesh Wi-Fi kit set up in router mode runs a second one on top of it, wired cameras hang off a recorder on one side, and the doorbell and floodlight cameras join the Wi-Fi on the other. Local viewing mostly works, while remote access and automatic discovery grow flaky because of the double NAT between the two networks.

The fix is one routing device and one source of automatic addresses: the mesh in bridge or access-point mode, or the gateway in passthrough so the mesh does the routing. Consumer mesh kits rarely support VLANs, so in a home we reserve addresses for Wi-Fi cameras in the mesh app, keep wired cameras behind the recorder’s PoE ports, and write the whole thing down.

How the engagement runs, from survey to sign-off

  1. Walk the site and, for a business, talk with whoever manages the network to get their subnet and VLAN assignments.
  2. Deliver the written address plan to you and your IT provider before any cabling starts.
  3. Stage switch and camera settings so installation day is about mounting and verifying, not typing.
  4. Add each camera to the recorder by address and confirm both streams.
  5. Prove the firewall rules: show that a camera cannot reach the internet and that an authorized office computer can view.
  6. Hand over the address plan, a switch-port map and the admin credentials, delivered to the owner securely rather than taped to the rack.

What moves the quote, and the errors that cause second visits

Your itemized quote follows an on-site estimate. It depends on device count, whether managed switching already exists, whether your IT provider handles the firewall side or we do, whether an occupied retail or medical suite needs after-hours work, how many floors or buildings are involved, and how much of an existing system is being reused.

Second visits usually trace back to a camera subnet that overlaps a VPN range, cameras left on the guest network, a recorder stuck behind double NAT, no time source configured, a DHCP scope that was never shrunk to exclude the fixed block, or a switch port moved to a different VLAN without updating the map.

Frequently asked questions

Our IT company manages the network. Do you work with them or around them?
With them. We ask for their subnet and VLAN assignments first, send them the address plan before installation, and document what we configure so they can support it afterward. Camera work that ignores the existing network owner is how most of the problems on this page start.
Do cameras really need their own VLAN in a small office?
Not always. A small suite with a handful of cameras on a PoE recorder is already isolated by the recorder itself. Once cameras connect through the building’s own switches, share wiring with office computers, or number more than the recorder’s ports, a dedicated VLAN with firewall rules is the cleaner design.
Why did you pick an unusual address range instead of 192.168.1.x?
Because home routers use 192.168.0.x and 192.168.1.x so widely. If an employee connects from home over VPN and their house uses the same range as your camera network, traffic meant for a camera can stay inside their house. An uncommon range avoids that conflict entirely.
Can the cameras still send motion alerts if they are blocked from the internet?
Yes, when the recorder is the device that sends alerts and handles remote viewing. The cameras only need to reach the recorder, which is exactly what the firewall rules allow.
Do you come to Conroe for a single-suite job?
Yes. The crew comes up I-45 from Katy/Houston, since there is no Conroe office. Tell us the suite address and scope at (832) 359-2425 and we will line up a date for the on-site estimate.

Get a written camera address plan for your Conroe site

Start with an on-site estimate: we survey the network, coordinate with your IT provider, and give you an itemized quote plus a plan both of you can support. Call (832) 359-2425.

Book a Consultation
EVOTECH technician working inside a network cabinet
Before you go

Ready for EVOTECH to help?

Before you leave, send the quick version. We will review the page you came from and reply with the clean next step.

1 minsimple request
Texaslocal and remote help
Inboxlead saved and emailed
Send the quick request No long questionnaire. A real EVOTECH lead comes straight to the inbox.
Choose a service and EVOTECH will guide the next step.
(832) 359-2425

EVOTECH uses your details only to reply, quote, schedule, or help with your requested service.

Need Camera System Pricing?
Call, message, or request a free estimate for security cameras, surveillance, and security wiring.
Fast quote today • Same-day response available
Call Now: 832-359-2425 Chat on WhatsApp Book Appointment
Free Estimate Request
Thank you. EVOTECH received your request.
Fast quote • Call, WhatsApp, or send your request now
Free Camera System Estimate
Need security cameras or surveillance wiring? Send your details now for fast pricing.
Thank you. EVOTECH received your request.