Business Support

Technical Support

About Guangxun

About Ainopol

Cross-Tenant Network Leakage in Multi-Tenant Campuses! Logical Isolation Technology Ensures Independent & Secure Data for Each Tenant
2026-09-12 11:40:56 13

Cross-Tenant Network Leakage in Multi-Tenant Campuses! Logical Isolation Technology Ensures Independent & Secure Data for Each Tenant

Within one office building, Company A provides financial data services, Company B runs cross-border e-commerce, and Company C operates a self-media studio. These three businesses share the property’s network infrastructure — physically sharing fiber optics and computer rooms — yet they must remain logically isolated. Client data of Company A must not be scanned by Company B; transaction records of Company B must stay inaccessible to Company C. Network failures or security incidents affecting one tenant must not spill over to others.

However, reality often falls short of this ideal. When designing networks for multi-tenant campuses, many operators only focus on enabling internet access. All tenants join the same network, sharing a large Layer 2 broadcast domain. Any tenant can scan other parties’ devices. If one endpoint gets infected, the entire floor may be compromised. When one enterprise’s internal network malfunctions, neighboring companies suffer outages too. What seems merely as “network cross-talk” actually exposes risks of data leakage, compliance violations and weakened trust for property leasing.

I. Risks of Cross-Tenant Network Leakage in Multi-Tenant Campuses

All tenants reside in the same broadcast domain and can discover each other

Legacy campus networks often assign an entire floor or building to a single VLAN, putting all tenants within one network segment. There are no boundaries between tenants. PCs from Company A can detect Company B’s printers, shared folders and even internal servers. Once one tenant’s endpoint is breached, attackers can move laterally across the network to access resources belonging to other tenants. For data-sensitive industries such as finance, legal services and healthcare, such network environments cannot pass compliance audits.

Bandwidth contention: anomalies of one tenant impact the whole network

All tenants share the egress bandwidth without refined traffic scheduling. When one enterprise performs large data transfers or bulk file downloads, video conferences and ERP access for other businesses may get throttled. Worse still, a broadcast storm or loop fault from a single tenant can paralyze network services for the whole floor.

One-size-fits-all security policies, unable to customize per tenant

Tenants have vastly different network security requirements. Financial enterprises demand strict behavior auditing and data encryption; e-commerce platforms need priority guarantees for transaction traffic; self-media studios care more about upload bandwidth. Traditional networks only support blanket speed limits and access controls, lacking the capability to tailor security rules for individual tenants.

Difficult fault attribution leading to disputes between tenants

When a tenant experiences network anomalies, property teams must identify whether the issue stems from building infrastructure, carrier lines or the tenant’s internal equipment. Without a unified monitoring and management platform, troubleshooting requires floor-by-floor inspections, which are time-consuming and inefficient. Tenants get poor experience, and property staff are overwhelmed.

II. How Logical Isolation Technology Safeguards Independent Tenant Data

Zhihui Guangxun’s converged connectivity-security solution is built on an all-optical network foundation. Logical isolation technology carves out independent network spaces for each tenant. While a unified fiber network serves as the physical underlay, tenants remain logically separated and invisible to one another.

  1. VLAN logical isolation with independent network segments per tenant
    Under the all-optical architecture, office spaces and endpoints of each tenant are assigned to dedicated VLANs. Tenants cannot communicate with each other by default. Devices from Company A cannot scan any terminals belonging to Company B. Even with shared physical infrastructure, each tenant occupies a separate logical network space. VLAN policies are deployed centrally on the OLT instead of configured switch by switch manually, eliminating human omissions. Zhihui Guangxun optical gateways enforce logical network isolation between different firms and teams to protect data security and privacy.
  2. Multi-SSID broadcasting for non-interfering tenant connections
    Each optical-electrical AP supports multi-SSID broadcasting. Different tenants connect to their dedicated SSIDs with VLAN logical isolation, ensuring fully independent, invisible data flows. Visitors use a guest SSID mapped to an isolated VLAN with internet-only access; tenant employees log into their exclusive SSIDs with tenant-specific access permissions. Onboarding new tenants only requires adding SSIDs and VLANs on the EAAS platform, completing configuration in 5 minutes with no physical changes.
  3. PON hard slicing for full Layer 2 / Layer 3 isolation of service domains
    Leveraging PON hard slicing capability, one physical fiber is divided into multiple independent logical networks. Office slices, security slices and guest slices achieve complete Layer 2 and Layer 3 isolation. Even if an information display panel or smart device of one tenant is compromised, attackers cannot cross slice boundaries to reach other tenants’ networks. Isolation is enforced at the optical layer rather than relying merely on policy configuration, delivering stronger security.
  4. Intelligent traffic steering to schedule service flows on demand
    Zhihui Guangxun’s solution meets diverse application demands for office work, cloud services, video conferencing, development testing and smart devices to ensure smooth operation of critical services. Fine-grained QoS scheduling allocates independent bandwidth channels for each tenant. Priority is granted to mission-critical traffic, while general internet traffic is allocated by weight. Large-volume transmission by one tenant will not consume bandwidth reserved for core business of other tenants.
  5. Unified management platform with tiered O&M for tenants
    Zhihui Guangxun EAAS cloud platform supports multi-tenant hierarchical management. Property administrators hold top-level privileges to view all tenant network status, assign bandwidth policies and resolve global faults. Each tenant receives an independent admin account to check its own network status, modify WiFi names and passwords, and manage user permissions — but cannot view or alter networks of other tenants. One platform with two permission levels preserves tenant autonomy while enabling unified property management. The EAAS cloud supports remote O&M via mobile devices and zero-touch deployment to cut on-site labor.
  6. Converged connectivity & security: security capabilities deployed alongside the network
    Zhihui Guangxun’s converged connectivity-security solution embeds native security capabilities into the network architecture rather than adding security appliances as afterthoughts. Portal authentication supports SMS verification and mini-program authentication to realize real-name verification upon network access. Full cloud log storage is retained for at least six months for traceable security auditing. It complies with the Cybersecurity Law and Public Security Ministerial Order No.176 requiring traceability of internet access behavior, enabling compliance from the start. Tenant data stays mutually invisible, security policies are customizable, and property operators do not need to deploy standalone security hardware for every tenant.

The core challenge for multi-tenant campus networks lies in balancing shared infrastructure with mandatory data isolation. Fully separate physical networks incur excessive costs, while unrestricted logical access carries severe risks. Embedding isolation capabilities deep into the network, granting each tenant an independent logical domain and defining clear boundaries for every access attempt — this is what multi-tenant campus networks should deliver. Network cross-talk costs more than data; it costs tenant trust. Robust data isolation builds confidence for property leasing.

FAQ

Q: Will data be visible to other tenants if they share one fiber?
A: No. The all-optical network uses VLAN logical isolation and PON hard slicing to assign each tenant to an independent network segment. Tenants cannot communicate with each other by default. Devices of Company A cannot scan any terminals of Company B. Cross-tenant access paths are blocked at the network layer.

Q: Do tenants need to purchase their own network hardware?
A: No. The all-optical solution deploys shared fiber infrastructure managed by the property. Each tenant gets dedicated ONU terminals and optical APs without buying network equipment. Adding a new tenant only requires creating VLAN and SSID on the EAAS platform, finished within 5 minutes and requiring no physical modifications.

Q: Do tenants need separate network cabling?
A: No. Zhihui Guangxun optical-electrical ONUs eliminate extra wiring and can power access control units and cameras directly to reduce cabling costs. A single fiber carries all services, enabling instant activation once tenants move in without conduit rerouting.