Skip to main content
Altitude Network Solutions LLC

Fiber & Network Resilience

Offline Failback: On-Premise Advantages When the Network Drops

9 min read

Cloud-managed security is convenient until the link goes down. Here is what still works, what stops immediately, and why local execution matters for doors and cameras.

What The Network Dropped Actually Means

When someone says the network is down, they might mean three different things. The ISP circuit failed. The internal LAN has a switch or firewall problem. Or the connection between your site and a cloud security platform is unreachable even though local networking works fine.

Each scenario has different consequences. A WAN outage might not affect card readers talking to a local controller on the LAN. A firewall misconfiguration might block cloud management while doors still operate locally. A full LAN failure takes everything offline regardless of where the controller lives.

Before you evaluate any security platform, map which components require cloud connectivity for basic operation versus which only use the cloud for management and reporting. That distinction is the core of the offline failback conversation.

Cloud-Dependent Access Control and Video: What Stops Immediately

Pure cloud access control stores credentials and decision logic in the cloud. The reader at the door must reach the cloud to authorize each credential scan. When the link fails, doors may not unlock, or they may fail into an undefined state depending on firmware.

Cloud-only video platforms that stream directly from camera to cloud with no local recorder stop recording when bandwidth is unavailable. Events during the outage are lost. There is no buffer to backfill when connectivity returns unless the camera has local storage, which is often limited.

Mobile credentials add another dependency. Phone-based credentials require Bluetooth or NFC at the reader plus backend validation. If validation requires cloud reachability, a phone credential may fail when a physical card still works on a local controller.

Common misconception

Cloud-managed does not have to mean cloud-dependent. Many enterprise platforms manage from the cloud but execute access decisions locally. Ask specifically where credential validation happens.

On-Premise Controllers, Local Credentials, and Edge Recording

On-premise access control keeps the authoritative credential database and decision engine on a controller at your site. Readers communicate over the LAN. Valid credentials work even when the internet is completely offline. Events queue locally and sync when connectivity returns.

Edge recording puts video storage on a local NVR or camera SD buffer. Cameras continue recording to local media during WAN outages. When the link recovers, recorded footage can sync to cloud storage if your architecture includes that path.

Hybrid designs are common in well-engineered systems. Cloud portal for administration and reporting. Local controllers for real-time door decisions. Local NVR for continuous recording. Cloud as backup and remote viewing, not as the sole execution layer.

  • Local controller: doors operate on LAN connectivity only
  • Local NVR: continuous recording independent of WAN
  • Queued events: audit trail preserved during outage, syncs later
  • Cloud portal: management convenience when link is available

Fail-Open vs Fail-Secure During Outages

When a door controller loses power or network connectivity, electric locks must choose a safe state. Fail-secure means the door stays locked. Fail-open means the door unlocks to allow egress. Life safety codes require free egress in most commercial occupancies.

Mag locks and electrified hardware behave differently on power loss. Battery backup on controllers and locks extends runtime during outages. UPS sizing for access control panels is part of offline planning, not optional.

Your security policy and fire marshal requirements must align. A data center may want fail-secure on every door. A retail storefront may need fail-open on main egress during power failure. There is no universal answer.

Battery Backup, UPS Sizing, and Generator Considerations

Network outages and power outages often coincide. A controller that handles offline credentials beautifully still fails when its panel loses power. Access control power supplies with battery backup are standard on commercial installs. Battery capacity determines runtime.

UPS units on network closets keep switches and controllers alive through brief outages. Generator-backed facilities extend that indefinitely for critical systems. Size UPS for switch PoE load plus access control panels plus NVR, not just the rack switch nameplate.

Test battery failover during commissioning. Batteries degrade. A five-year-old access control power supply may not deliver the runtime its label suggests.

Hybrid Architectures: Cloud Management with Local Execution

The best commercial deployments often combine cloud convenience with local resilience. Administrators manage users and schedules from a browser. Controllers download configuration and credential updates when connected. Day-to-day access decisions happen locally without round-trip latency to a distant data center.

When evaluating vendors, ask about offline duration limits. Some systems cache credentials for seventy-two hours. Some cache indefinitely until the next sync. Some degrade features like anti-passback or occupancy limits when offline.

Document the expected offline behavior in your security runbook. Staff should know what works during an outage and who has mechanical keys for override.

Real Scenarios: ISP Outage, Firewall Failure, Ransomware Isolation

ISP outages are common and usually temporary. Local controllers keep doors working. Remote administration from off-site stops until the circuit returns or you fail over to cellular backup.

Firewall failures can block outbound cloud traffic while LAN traffic continues. Locally executed access control survives. Cameras recording to a local NVR survive. Remote viewing and cloud clip export fail until the firewall is restored.

Ransomware response sometimes requires isolating segments of the network. If your access control depends on cloud validation through a compromised VLAN, isolation can lock everyone out or leave doors in an unknown state. Segmentation design should keep security control traffic on protected infrastructure.

Questions to Ask Before Buying a Cloud-Only Platform

Use these questions in RFPs and vendor demos. Acceptable answers depend on your risk tolerance, but you should get clear answers, not marketing deflection.

  • Where is the credential database stored and where is each access decision made?
  • How long can the system operate fully offline with no cloud connectivity?
  • What features degrade or disable during extended offline periods?
  • Where is video recorded during a WAN outage and for how long?
  • What happens to fail-open and fail-secure behavior on power loss and network loss?
  • Can I export audit logs locally during an outage?
  • Is cellular failover supported for cloud management paths?

Altitude Network Solutions designs and installs commercial access control and video systems with offline resilience in mind. We deploy platforms that keep doors and cameras operational when connectivity does not. Contact us to review your current architecture or plan a new deployment.

Need Help With This on Your Site?

Altitude Network Solutions designs and installs commercial network and security infrastructure across Colorado. If this article raised questions about your facility, we can walk through your requirements and recommend a practical path forward.