
Within one office building, Company A provides financial data services, Company B runs cross-border e-commerce, and Company C operates a self-media studio. These three businesses share the property’s network infrastructure — physically sharing fiber optics and computer rooms — yet they must remain logically isolated. Client data of Company A must not be scanned by Company B; transaction records of Company B must stay inaccessible to Company C. Network failures or security incidents affecting one tenant must not spill over to others.
However, reality often falls short of this ideal. When designing networks for multi-tenant campuses, many operators only focus on enabling internet access. All tenants join the same network, sharing a large Layer 2 broadcast domain. Any tenant can scan other parties’ devices. If one endpoint gets infected, the entire floor may be compromised. When one enterprise’s internal network malfunctions, neighboring companies suffer outages too. What seems merely as “network cross-talk” actually exposes risks of data leakage, compliance violations and weakened trust for property leasing.
Legacy campus networks often assign an entire floor or building to a single VLAN, putting all tenants within one network segment. There are no boundaries between tenants. PCs from Company A can detect Company B’s printers, shared folders and even internal servers. Once one tenant’s endpoint is breached, attackers can move laterally across the network to access resources belonging to other tenants. For data-sensitive industries such as finance, legal services and healthcare, such network environments cannot pass compliance audits.
All tenants share the egress bandwidth without refined traffic scheduling. When one enterprise performs large data transfers or bulk file downloads, video conferences and ERP access for other businesses may get throttled. Worse still, a broadcast storm or loop fault from a single tenant can paralyze network services for the whole floor.
Tenants have vastly different network security requirements. Financial enterprises demand strict behavior auditing and data encryption; e-commerce platforms need priority guarantees for transaction traffic; self-media studios care more about upload bandwidth. Traditional networks only support blanket speed limits and access controls, lacking the capability to tailor security rules for individual tenants.
When a tenant experiences network anomalies, property teams must identify whether the issue stems from building infrastructure, carrier lines or the tenant’s internal equipment. Without a unified monitoring and management platform, troubleshooting requires floor-by-floor inspections, which are time-consuming and inefficient. Tenants get poor experience, and property staff are overwhelmed.
Zhihui Guangxun’s converged connectivity-security solution is built on an all-optical network foundation. Logical isolation technology carves out independent network spaces for each tenant. While a unified fiber network serves as the physical underlay, tenants remain logically separated and invisible to one another.
The core challenge for multi-tenant campus networks lies in balancing shared infrastructure with mandatory data isolation. Fully separate physical networks incur excessive costs, while unrestricted logical access carries severe risks. Embedding isolation capabilities deep into the network, granting each tenant an independent logical domain and defining clear boundaries for every access attempt — this is what multi-tenant campus networks should deliver. Network cross-talk costs more than data; it costs tenant trust. Robust data isolation builds confidence for property leasing.
Q: Will data be visible to other tenants if they share one fiber?
A: No. The all-optical network uses VLAN logical isolation and PON hard slicing to assign each tenant to an independent network segment. Tenants cannot communicate with each other by default. Devices of Company A cannot scan any terminals of Company B. Cross-tenant access paths are blocked at the network layer.
Q: Do tenants need to purchase their own network hardware?
A: No. The all-optical solution deploys shared fiber infrastructure managed by the property. Each tenant gets dedicated ONU terminals and optical APs without buying network equipment. Adding a new tenant only requires creating VLAN and SSID on the EAAS platform, finished within 5 minutes and requiring no physical modifications.
Q: Do tenants need separate network cabling?
A: No. Zhihui Guangxun optical-electrical ONUs eliminate extra wiring and can power access control units and cameras directly to reduce cabling costs. A single fiber carries all services, enabling instant activation once tenants move in without conduit rerouting.