Example isolated Metasys BACnet/IP network - Metasys - LIT-12012458 - Field Device - 13.0

Metasys IP Networks for BACnet/IP Controllers Technical Bulletin

Document type
Technical Bulletin
Document number
Revision date
Product status

Figure 1 illustrates an Isolated Metasys BACnet/IP network. In this example, the network is to be converted to a Connected network at some time in the future. The network engine s are placed in the same VLAN and subnet (VLAN 5 and subnet would be the VLAN and subnet allocated by IT for the BAS network).

The subnetworks for the IP-based BAS devices are allocated from the BAS network's address space:

  • VLAN 10:
  • VLAN 11:
  • VLAN 12:
Note: It is not required that the VLAN number be included in the subnetwork address as shown in this example.

The devices are assigned to VLANs (10 through 12) within the BAS network.

The network engine s, Metasys server , and access switches are placed in VLAN 5 and subnetwork This is the VLAN and subnet pre-allocated by IT for when the BAS network will eventually be connected to the IT network. A firewall is connected to the BAS aggregation switch through an access port. The firewall routes traffic to the BAS subnet by way of a SVI ( in a different VLAN (100) on the BAS aggregation switch. These are also pre-allocated by IT for when the BAS network will eventually be connected to the IT network. Figure 1 illustrates an Isolated Network using these VLAN and subnetwork values.

Figure 1. Isolated Metasys BACnet/IP network example

The BAS Access switches are interconnected with each other, providing link redundancy. Because the BAS switches are interconnected by way of trunks, Rapid Spanning Tree Protocol (RSTP) best practices must be followed when configuring the trunks between the BAS switches.

The following table details the recommended IP address assignments for the devices in each of the VLANs within the BAS network.

Table 1. Recommended IP addresses for isolated network example




IP controllers

Network engine

10 /24 -

11 /24 -

12 /24 -

The BAS aggregation switch acts as the primary router for the BAS network, routing traffic within the BAS network as well as routing traffic between the BAS network and the firewall. The firewall routes traffic between the BAS network and a VPN, allowing remote access to the BAS network. The following route statements are required to achieve this behavior:

Table 2. Maintenance VLAN 20 ( /29)


Destination subnet



To the Internet

BAS Aggregation Switch

BAS Access Switch 1

BAS Access Switch 2

The ports connected to the IP-based Metasys devices need to be configured as access ports for the appropriate VLAN (10, 11, or 12). In addition, the following switch port configurations are required:

Table 3. Switch port configuration

Endpoint 1

Endpoint 2

Connection type

VLAN membership/allowed VLAN(s)

Aggregation Switch


Access port


Aggregation Switch

Metasys server

Access port


Aggregation Switch

Access Switches



Access Switch 1

Access Switch 2