AINOPOL All-Optical Secure Networking Empowers the New Campus of Xinzhou Technical School,Building a Strong Cybersecurity Defense Line for the Campus.
Xinzhou Senior Technical School, founded in 1978, is a key public technical institution directly under the Xinzhou Municipal Government and administered by the Municipal Bureau of Human Resources and Social Security.
To overcome the constraints of limited space and outdated facilities at the old campus, and to better serve industrial upgrading in Xinzhou and cultivate high-skilled talents, the school has built a new high-standard campus, comprehensively improving its educational conditions and laying a solid foundation for upgrading to a technical college.
The new campus is larger in scale, wider in coverage and more densely populated. The stability and security of campus security and protection are directly related to the daily study and life of teachers and students as well as campus management order. From the early stage of construction, the school clearly required that: stable transmission of security systems and intranet security must be strictly guaranteed, fully comply with cybersecurity compliance standards of the education bureau and public security authorities, and ensure stable surveillance transmission, secure intranet protection, and traceable security records.
Why must cybersecurity protection be prioritized on campus?

Campus security network is not an ordinary local area network, but a core security network carrying surveillance video, access control records, alarm information and key area data. Without proper protection, the consequences are direct and severe:
Security data is highly sensitiveSurveillance footage and personnel access records involve campus safety and privacy. Illegal access, theft or tampering will directly lead to management and security risks.
Security systems must be immune to attacks and interruptionsOnce the security network is invaded or controlled, it may result in black screens, interrupted footage and disabled access control, directly losing security protection capabilities and disrupting normal campus order.
Compliance with mandatory requirements of the Education Bureau and police authorities is essentialAccording to regulations of education and cybersecurity authorities, the campus security network must implement boundary isolation, access control, intrusion detection and log retention. Without security protection, compliance inspection cannot be passed.
Prevention of intranet lateral penetrationMultiple networks coexist on campus for teaching, office work and dormitories. Without protection for the security network, risks from other areas can easily spread to the core security system, causing chain security problems.
For these reasons, the new campus of Xinzhou Senior Technical School has elevated security network safety to the bottom line of campus security, with key construction and strict protection.
Traditional Ethernet networking: Chassis core + access switches
This security network adopts a traditional Layer 2 Ethernet architecture, with optical fibers as the backbone and Ethernet cables connecting to terminals.
Core LayerAINOPOL ZH-CS8506E chassis core switches (dual main control, dual power supply) are deployed for data switching within the security intranet. Services such as video surveillance, access control and alarm systems are isolated via VLAN.
Access LayerAINOPOL ZH-CS5228P-LI, ZH-CS5554X-SI and other full-Gigabit PoE access switches are deployed in each building. They are uplinked to the core switch via optical fibers, while providing data transmission and PoE power supply for cameras, access control devices and wireless APs.
Aggregation & Optical ModulesFor long-distance buildings, ZH-CS5528X-24S-SI all-optical aggregation switches are used, equipped with Gigabit/10G optical modules.
This Layer 2 flattened architecture not only ensures high-speed forwarding of security services, but also reserves sufficient space for future expansion.
Three Core Security Protections Safeguard the Security Intranet

I. ZH-FW30G Firewall: Building the First Line of Boundary Security
As the core protection device at the security network egress, it strictly enforces boundary security compliance:
Intrusion Prevention System (IPS): Detects and blocks SQL injection, XSS attacks, DDoS attacks (SYN Flood, UDP Flood, etc.), port scanning and abnormal packet attacks. Includes IPS signature database update service.
Antivirus (AV): Scans viruses over HTTP, FTP, SMTP and other protocols, supports multi-layer decompression detection for compressed files, and blocks Trojans, worms, ransomware and other malware from entering the intranet.
Provides hard isolation protection for the security intranet and prohibits unauthorized external access;Implements finely configured access control policies, opening only compliant ports and closing all high-risk ports;Blocks external scanning, brute force cracking, illegal access and other malicious behaviors in real time, cutting off security risks at the source.
II. ZH-M1 Internet Behavior Management: Ensuring Priority for Security Transmission and Unoccupied Bandwidth
Focused on solving practical problems such as lagging security transmission and bandwidth preemption:
Assigns dedicated bandwidth and sets the highest transmission priority for surveillance, access control, alarm and other security devices;
Ensures stable transmission of security data even during high-traffic periods such as class breaks, dismissal hours and large-scale events;
Enables manageable, controllable and auditable network behaviors, meeting the behavior control and log retention requirements of Classified Protection 2.0.
III. ZH-M1 Intrusion Detection (IDS/IPS): 24/7 Intranet Risk Monitoring
Fully meets the mandatory requirements of education and public security authorities for intrusion detection and security auditing:
Monitors risky behaviors in the intranet in real time, including illegal access, abnormal connections and unauthorized operations;
Automatically alerts immediately upon threat detection, enabling rapid response and timely disposal;
Retains complete operation logs, traffic logs and alarm logs for more than 6 months, supporting regulatory auditing and event traceability.
04 Cloud-Based Intelligent O&M: Reducing Campus Management PressureGiven the limited capacity of the campus operation and maintenance team, all devices can be connected to the cloud with one click. Through the EAAS cloud unified management platform, remote control and management of all security network devices are realized.
With a computer or mobile APP, O&M personnel can view real-time device status and monitor network traffic. In case of faults, on-site inspection is not required; problem nodes can be located and fixed remotely via the platform, greatly improving maintenance efficiency.
From its founding commitment in 1978 to the high-standard launch of the new campus, Xinzhou Senior Technical School has always put safety and quality first.
With an all-optical stable architecture plus a three-tier security system integrating firewall, Internet behavior management and intrusion detection, AINOPOL has built a campus security network solution featuring stable transmission, high security, full compliance and easy management for the school. We fully safeguard campus safety and support the school’s steady progress toward its goal of becoming a technical college.