Business Support

Technical Support

About Guangxun

About Ainopol

Enterprise All-Optical Network Terminal Access Control & Zero Trust: Level-2 Cybersecurity Classified Protection Compliance Implementation Practice
2026-07-27 10:01:11 2

Enterprise All-Optical Network Terminal Access Control & Zero Trust: Level-2 Cybersecurity Classified Protection Compliance Implementation Practice

A precision equipment manufacturing enterprise operates a 3-building campus with around 600 employees. Its converged network carries diverse terminals including office PCs, workshop PLCs and sensors, over 200 surveillance cameras, access controllers, and daily visitor mobile devices. Before renovation, the flat network architecture brought prominent security loopholes. Prior to the Level-2 Cybersecurity Classified Protection (Equal保 2.0) assessment, security auditors identified two critical risks: unregulated access for surveillance and access control devices with no identity verification mechanism; visitor Wi-Fi access enabling unauthorized lateral probing of office shared files.

The enterprise adopted the AINOPOL Integrated Communication & Security all-optical network solution, which integrates all-optical infrastructure, native network security capabilities and unified O&M platforms. Based on the actual campus deployment process, this article elaborates on the standardized implementation of terminal access control + zero trust security.

I. Full Asset Inventory & Logical Planning: Establish Identity and Access Baselines

Prior to security deployment, the enterprise completed a one-week comprehensive network asset inventory, classifying all connected terminals into three categories with targeted access policies:

1. Manageable terminals: Office PCs and mobile devices supporting client installation and identity authentication;

2.Dumb terminals: Cameras, access controllers, PLCs and printers incapable of client deployment or manual password verification;

3. Temporary visitor terminals: Uncontrolled external mobile devices with uncertain security status.

Corresponding VLAN planning was implemented to build three logically isolated networks for office, security monitoring and visitor services. All services share a unified physical all-optical backbone with independent logical isolation, laying a fundamental baseline for standardized terminal access control.

II. Port-Embedded Access Control: Build Inline Security on All-Optical Infrastructure

Traditional networks rely on standalone switches for passive access management, forming long-term security blind spots for dumb terminals and visitor access. After upgrading to the AINOPOL all-optical architecture, access control is no longer implemented via discrete overlay devices, but embedded into optical ports and link pipelines. The security multi-service gateway integrates firewall, IPS, antivirus, behavior audit and real-name authentication capabilities in one hardware platform, eliminating security management gaps caused by multi-device splicing.

Office terminal access mechanism: All wired and Wi-Fi connected office terminals pass mandatory 802.1X identity authentication. Terminals with invalid credentials are automatically isolated in a restricted quarantine zone with no access to core business systems.

Dumb terminal access mechanism: For unautomatable dumb devices including surveillance cameras, access controllers and PLCs, the solution adopts ONU physical port + MAC address binding to fix specific devices to dedicated ports. The system instantly identifies abnormal plugging and unapproved device replacement, automatically disconnecting risky links to fill the long-standing management vacuum of dumb terminal access in traditional networks.

Visitor access mechanism: Independent isolated VLAN for visitor Wi-Fi, restricting all visitor terminals to pure Internet access. Cross-domain access to office and security monitoring networks is blocked by default policies, fundamentally preventing internal network probing risks from external visitors.

III. Zero Trust Overlay: Default Deny & Continuous Verification for Internal Access

Successful network access does not grant unrestricted internal traversal permissions. The campus implements a zero trust security logic of default deny, continuous verification based on authenticated access. Even identity-validated terminals require secondary authorization verification for every access request to core services such as OA and ERP systems.

Terminals lacking antivirus software or long-unupdated system patches are limited to restricted access permissions until security baseline compliance is completed. All business accesses pass encrypted tunnels to mitigate man-in-the-middle eavesdropping and prevent lateral movement risks after single terminal compromise.

Notably, zero trust is not a replacement for traditional firewalls, but a complementary overlay security layer. Firewalls defend against external boundary threats, while zero trust governs fine-grained authorization for every internal access behavior, realizing full-link internal security control.

IV. Level-2 Classified Protection Compliance: Four Core Control Point Implementation

The overall solution precisely matches standard assessment clauses of Cybersecurity Classified Protection 2.0, fully meeting compliance requirements:

1. Security zone & boundary protection: VLAN isolation separates office, security monitoring and visitor domains, with standardized policy control for cross-domain access, fulfilling boundary access control compliance requirements.

2. Communication & transmission security: Encrypted tunnels carry all core business access traffic, ensuring transmission integrity and confidentiality of service data.

3. Computing environment security: 802.1X and multi-dimensional identity authentication realize mandatory user identification; terminal security baseline inspection supports intrusion prevention and malicious code defense mechanisms.

4. Security management center capability: The EAAS cloud platform provides unified visualized monitoring of online terminals, permission changes and security alarms, with traceable operation logs to meet centralized management and audit compliance standards.

V. Daily O&M Mechanism: Sustained Security Compliance Operation

Network renovation is the foundation, while standardized daily operation ensures long-term compliance. The campus currently relies on the EAAS platform for real-time online terminal inventory and abnormal security alarm monitoring, with weekly security trend report generation. New employee network access and new equipment deployment follow unified asset registration and baseline verification procedures, achieving "file creation before network access".

During compliance assessments, full records of terminal access history, access time and service behavior can be directly retrieved from the platform, eliminating temporary log sorting on discrete switches.

The campus practice verifies that embedding terminal access control and zero trust capabilities into native all-optical network architecture is far more stable and labor-saving than temporary security patching before assessments. Identity verification, logical isolation and continuous security validation take effect simultaneously with network activation, reducing subsequent O&M pressure and compliance risks significantly. For ongoing network renovation selection, embedding security capabilities at the infrastructure stage is more efficient than overlaying discrete security devices in the later stage.

FAQ

Q1: How to balance convenience and security for visitor networks?

A: Deploy independent isolated VLANs for visitors with Internet-only access permission and strict cross-domain access blocking. Complete internet behavior logs are retained at the gateway side to meet audit and regulatory requirements, achieving convenient access without internal network security risks.

Q2: Is the traditional firewall redundant after deploying zero trust?

A: Firewalls are not recommended for removal. Zero trust focuses on fine-grained authorization and continuous verification of internal network access behaviors, while firewalls undertake external boundary threat defense. The two form a superimposed defense system. Campuses retain boundary firewalls while leveraging zero trust to supplement internal fine-grained security control capabilities.

Q3: What identity verification items are focused in Level-2 Classified Protection assessment?

A: Key audit items include valid user identity marking & verification, password complexity & periodic update mechanisms, and security labeling for core subjects and objects. Compliance implementation can be realized through combined deployment of 802.1X, Portal authentication and MAC whitelist mechanisms, subject to official GB/T 22239 standards and institutional verification specifications.