LAPP

In modern production facilities, data traffic is as dense as rush-hour traffic on busy roads. Machines report operating conditions, sensors provide measurement data, and controllers intervene within milliseconds. To ensure that all this information arrives reliably, industrial networks must be stable and well structured. This applies down to the level of individual components, whose influence is often underestimated. One such component is the network switch. Its role is to forward data packets to the correct end devices and maintain the flow of information throughout the operation. But how exactly does this work?

In modern industrial plants, sensors, controllers, machines and servers continuously exchange data. To keep this exchange organised, network switches act as traffic controllers. They identify which device is connected to which port and forward data to where it is needed. Unlike simple distributors, known as hubs, they prevent unnecessary network traffic and ensure stable communication. This is particularly important in industrial applications with numerous nodes and demanding requirements for availability and security.

What initially sounds straightforward quickly becomes more complex in practice, especially when choosing between unmanaged and managed switches. Jürgen Greger, Product Manager Industrial Communication at LAPP, emphasises: “Security and transparency are becoming increasingly important. Anyone who wants future-proof networks cannot do without managed switches.”

 

Unmanaged Switches: Data Traffic Without Traffic Lights

Unmanaged switches remain the standard in many installations. They distribute data packets based on MAC addresses, which are permanently assigned to each network adapter during manufacture and enable unique identification within the network. Once powered on, they immediately begin forwarding data packets without requiring any user configuration. This makes them both easy to integrate and cost-effective.

However, this simplicity has clear limitations. Unmanaged switches provide no information about the current status or exact structure of the network. If a data connection fails or traffic patterns change, operators typically only become aware of the issue when machines stop operating. Remote diagnostics and troubleshooting are not possible. Instead, engineers must rely on checking LED indicators directly inside the control cabinet. Thomas Leitmann, Application Engineer at LAPP, illustrates this principle with a metaphor:“Unmanaged switches are like road junctions without traffic lights, traffic rules or speed cameras. Everyone simply sets off without knowing who has priority. If an accident occurs, traffic comes to a standstill and nobody knows what caused it.”

 

Managed Switches: The Control Centre of Network Traffic

Managed switches represent the alternative. Like unmanaged switches, they forward data packets, but they can also be configured, monitored and adapted to specific requirements.Using a web interface or network management software, users can:

  • Prioritise data traffic
  • Enable or block ports
  • Retrieve status information
  • Detect faults and packet loss
  • Configure virtual local area networks (VLANs)
  • Create redundancy mechanisms for improved reliability

 

As a result, managed switches provide a high degree of transparency and control. They reveal which devices are communicating through which ports, where disruptions are occurring and how the network is behaving overall. This allows irregularities to be identified and resolved at an early stage, a crucial advantage for uninterrupted production. Thomas Leitmann adds: “To continue the road traffic analogy, managed switches are like junctions equipped with traffic lights and controlled traffic flows. Traffic is monitored and managed, including remotely through a central traffic control centre.”

 

Jürgen Greger und Thomas Le

Diagnostics, Transparency and Stability

The advantages of managed switches extend beyond the road traffic analogy and become evident in real industrial networking applications. Jürgen Greger explains: “When selecting switches, the decision should not be based on cost alone. Features such as transparency and adaptability deliver practical operational benefits. There is no doubt that managed switches are the better choice.”

One of their most important capabilities is advanced diagnostics. Managed switches monitor network traffic during operation, record data losses and identify bottlenecks. Through a feature known as port mirroring, data traffic at an individual port can be monitored and analysed. Tools such as Wireshark are frequently used to pinpoint communication issues with precision.

At the same time, the switch automatically builds a complete picture of the network in the background. It detects which devices are connected to which ports and creates a digital representation of the network topology. With unmanaged switches, technicians often have to reconstruct these relationships manually. Managed switches also enhance network stability. They support the creation of alternative communication paths that automatically take over if a connection fails. This ensures that data traffic continues uninterrupted even during faults. The failure is reported simultaneously, enabling rapid identification of the affected area and resolution of the root cause. As a result, downtime is reduced and operational reliability is significantly improved.

 

Cyber Resilience in Industrial Networks

Operational reliability also includes protection against cyber threats and unauthorised access, an area where managed switches provide important advantages.Virtual networks allow production networks, office networks and IT administration systems to be logically separated. This segmentation helps prevent disturbances or cyberattacks from spreading across the entire infrastructure.In practice, devices can be physically connected to the same switch while remaining unable to communicate with one another. This creates a security concept comparable to physical separation, but at a significantly lower cost.

In addition, managed switches offer security features that restrict unauthorised access. So-called port locks can disable unused ports and prevent unknown devices from being connected. Filtering mechanisms based on IP and MAC addresses further limit access to authorised devices while closing potential points of entry. This makes network manipulation considerably more difficult from the outset.

Jürgen Greger comments: “Cybersecurity strategies such as Defence in Depth and international standards such as IEC 62443 rely on protection against tampering and on clearly controlled access rights. Managed switches therefore make a significant contribution to the future security of industrial communications.”

 

Unmanaged at the Edge, Managed at the Core

Nevertheless, unmanaged switches are unlikely to disappear completely. They remain suitable as port extensions in simple applications, particularly at the edge of a network. In these environments, no safety-critical data is transmitted and a failure would not have immediate consequences.

Thomas Leitmann explains: “If all ports in a system are occupied, an additional unmanaged switch can help expand connectivity without altering the existing infrastructure. However, for modern production applications or safety-critical environments, this can no longer be considered a responsible solution.”

As connectivity continues to increase, so do the demands for transparency, security and responsiveness. This is precisely where managed switches demonstrate their strengths. By making networks visible, understandable and controllable, they provide the foundation for stable industrial communication. Jürgen Greger summarises it succinctly: “Anyone aiming for smooth and secure data traffic in industrial operations needs a well-organised traffic control centre that maintains oversight and can intervene when necessary. Managed switches provide the essential prerequisites for achieving exactly that.”