The commissioning punch list said VLAN 40. Dedicated AV. Isolated from corporate. Isolated from guest. Someone initialed the drawing, the rooms came up, and everyone left.
A VLAN ID is a label. Isolation is a claim. Most AV sites never test the claim after the punch list.
Isolation is not the VLAN number
IT and AV both treat "we put it on its own VLAN" as the end of the security conversation. It is usually the start.
A VLAN without enforced Layer 3 policy is a named broadcast domain. CISA's long-standing infrastructure guidance is to segment networks and limit unnecessary lateral traffic. Private VLANs, VLAN ACLs, and VRFs show up in that writeup because a tag by itself does not stop a packet.[4]
Crestron's own NVX design guide is honest about the next problem. The AV segment still needs DNS, DHCP, Active Directory, and RADIUS. You have to cut traversal rules to get those services onto the "isolated" VLAN.[2] Every hole you cut for commissioning stays open unless someone is watching who actually uses it.
NETGEAR's InfoComm 2026 security session said the part most punch lists skip: air-gapped AV is no longer a viable defense, and lateral movement across flat VLANs is the failure mode.[3]
Two failures that were not advanced
Kontek published the first one on August 4. While looking for an AV device with a basic diagnostic command, they got answers back from six-figure scanning equipment and servers. They tested again from the guest network. Same result. About twenty people from IT, security, and other departments were on a call within a day. The cause was a segmentation misconfiguration, not a novel exploit.[1]
The second story is smaller. A university's first AV-over-IP pilot. A leftover box still acting as a DHCP server. The campus already had one. The conflict took down a campus segment.[1]
Audinate documents the same class of failure for Dante: more than one DHCP server on a network is a known way to break addressing.[7] Kontek just showed what happens when that box also sits on a network that was supposed to belong to someone else.
Kontek's line is the whole post: test and verify segmentation, never assume isolation.[1]
Why AV is worse at this than the rest of the LAN
AV-over-IP is multicast by design. Crestron says that without IGMP snooping, a switch that receives a multicast stream transmits it to every port and can saturate every link. They also say that flood can be a denial-of-service attack if someone does it on purpose.[2]
NETGEAR's IGMP note is the same idea without the vendor jargon. Multicast without snooping floods ports that never asked for the stream.[9]
Dante needs the same discipline. Audinate tells people to configure IGMP snooping on isolated AV networks, and to talk to the network team before touching it on enterprise fabric.[8] If snooping is off, the querier is missing, or a trunk does not carry the VLAN you think it carries, discovery and media leak sideways. The room still works, so nobody opens a ticket.
That is the AV version of isolation theater. The picture comes up. The VLAN still exists in the spreadsheet. The traffic does not stay where the drawing said it would.
There is a second leak that looks like a feature. NVX, Dante, Q-SYS, and most control processors need management access. Someone enables a cloud bridge, a vendor VPN, or a temporary port forward for a remote support session. The punch list never gets a line that says tear that down. The July endpoints post covered the Shodan version of this. The VLAN version is quieter: the device can now talk to the internet, and nothing on the AV VLAN is watching egress.
What "prove it" looks like on a live site
You do not need a red team. You need a habit.
- From the guest VLAN, can you see AV management ports, mDNS, Dante discovery, or NVX multicast groups?
- From the AV VLAN, can a codec or DSP open unexpected destinations: SMB, RDP, SSH, or anything on the public internet?
- Is there a second DHCP server, a second IGMP querier, or an extra default gateway that should not exist?
- After a change window, did a new talker, a new peer, or a new multicast group appear?
- Who owns the answer to those questions 90 days after commissioning, AV or IT?
If the answer to number five is "whoever gets the callback when the room dies," you do not have isolation. You have a drawing.
CISA's 2025 microsegmentation guidance is useful here even if you never say "zero trust" to a client. Smaller segments are not the point by themselves. The point is visibility into smaller groups of resources, and a limit on how far a compromised box can walk.[5][6]
Flow data is the continuous test
A one-time packet capture at commissioning is better than nothing. It is also stale the first time someone adds a signage player, enables a vendor tunnel, or patches a switch and loses the querier.
NetFlow, IPFIX, and sFlow already describe who talked to whom, on which ports, and how much moved. That is enough to see:
- a guest or corporate address appearing as a peer of an encoder
- a codec opening internet egress
- a new device joining the AV multicast groups
- a DHCP or discovery storm after a change window
You do not need the media. You do not need an agent on a Q-SYS Core or an NVX endpoint. You need the switch or firewall you already installed to export the metadata it is already generating.
That is the job AVoIP Guard is built for. Point the existing exporter at a collector, let a site baseline build, and treat "this codec should never talk to that subnet" as an alert instead of a hope.
What to do this week
Pick one live site. Not the lab.
Export flows for a few days. Compare the talkers you see to the VLAN drawing. Send the mismatches to whoever signed the punch list. If the drawing and the flows agree, you have a baseline. If they do not, you get the incident conversation before the incident.
FAQ
Isn't a dedicated AV VLAN enough? It is a required first step, not a finished control. A VLAN without ACLs, a querier, and a way to see who actually talks across it is a label. Crestron, NETGEAR, and CISA all treat the tag as the start of the design, not the proof.[2][3][4]
Can guest isolation fail even when the firewall rules look right? Yes. Kontek's guest-network case was a segmentation gap, not a missing checkbox on a sales drawing. Trunks, helper addresses, mDNS reflectors, and "temporary" vendor paths are how guest and AV meet in the middle.[1]
Will turning on IGMP snooping break Dante or NVX? Leaving it off is how multicast floods the rest of the switch. Audinate and Crestron both require snooping on the AV fabric; the breakage usually comes from enabling it without a querier, or from doing it on a shared enterprise VLAN without the network team.[2][8]
Do we need packet capture to prove isolation? No. Flow metadata is enough to see unexpected peers, unexpected egress, and new talkers. Capture is useful when you already know something is wrong and need the payload. You do not need the payload to notice a codec calling the internet at 2 a.m.
Who should own this after commissioning? Whoever still has a service relationship with the rooms. If that is the AV MSP, isolation verification belongs in the monthly work, not in a one-time IT ticket from the install.
Sources
[1] https://kontek.com/resources/av-security-surprises-lurking-on-your-network — Kontek: AV Security Surprises Lurking on Your Network [2] https://docs.crestron.com/en-us/9496/Content/Topics/AV-over-IP_Network-Design.htm — Crestron DM NVX AV-over-IP Network Design [3] https://www.infocommshow.org/2026-sessions/netgear-rethinking-network-security-for-av-over-ip — NETGEAR InfoComm 2026: Rethinking Network Security for AV-over-IP [4] https://www.cisa.gov/news-events/news/securing-network-infrastructure-devices — CISA: Securing Network Infrastructure Devices [5] https://www.cisa.gov/news-events/alerts/2025/07/29/cisa-releases-part-one-zero-trust-microsegmentation-guidance — CISA: Microsegmentation in Zero Trust Part One alert [6] https://www.cisa.gov/resources-tools/resources/microsegmentation-zero-trust-part-one-introduction-and-planning — CISA: Microsegmentation in Zero Trust Part One [7] https://dev.audinate.com/GA/dante-controller/userguide/webhelp/content/troubleshooting_dante_ip_address_configuration.htm — Audinate: Troubleshooting Dante IP Address Configuration [8] https://support.getdante.com/hc/en-gb/articles/5285123768607-Multiple-Leader-Clocks — Audinate: Multiple Leader Clocks / IGMP snooping [9] https://kb.netgear.com/000037833/What-are-multicast-and-IGMP-snooping-and-how-do-I-configure-these-features-on-an-Easy-Smart-Managed-Switch-using-the-Easy-Smart-user-interface — NETGEAR KB: Multicast and IGMP snooping