Why Your PoE Switch Browns Out Under Peak Camera Load
The service call always sounds the same: "cameras randomly reboot at night, but only in winter, and only some of them." The customer has already replaced two cameras and blamed the VMS. Nobody has looked at the switch, because the switch is "a 24-port PoE+ switch with 190 watts" and the spreadsheet says the cameras only need 160. The spreadsheet is wrong — not because anyone lied, exactly, but because PoE power budgeting has three or four layers of fine print, and the failure only shows up when several lines of that fine print land on the same cold night.
I keep seeing surveillance networks designed to the datasheet's headline wattage that run flawlessly through commissioning, pass the 30-day punch list, and then start dropping cameras the first week the temperature falls below freezing. Here is the actual math, and the audit that finds the problem before winter does.
The 80% Rule Most Datasheets Hide
A "190 W PoE budget" on a 24-port switch does not mean 24 ports quietly sharing 190 watts. It means the PoE controller will keep allocating power to ports until the pool is spent — and allocation is not consumption. With 802.3at negotiation, a Class 4 camera reserves 30 W from the budget even if it draws 9 W sitting idle in the summer. Depending on the switch's power management mode (static versus dynamic allocation), your 190 W pool can be "full" at six PTZ cameras that are collectively drawing 70 actual watts. Then camera seven powers up, negotiation fails or a lower-priority port gets shed, and you get the mystery reboot pattern.
My standing rule: plan to load a PoE budget to 80 percent of nameplate at worst-case draw, not typical draw. The remaining 20 percent is not waste — it covers negotiation overhead, cable losses, power supply derating at temperature, and the camera you will inevitably add in year two. A switch that lives at 95 percent of its PoE budget is not a working design; it is a scheduled outage.
How Power Budget Actually Gets Calculated
The arithmetic that holds up in the field: for every port, take the powered device's worst-case draw — not the "typical" number the camera datasheet leads with — then add cable loss, then check the sum against 80 percent of the switch's PoE pool, and separately check that no port exceeds its per-port class ceiling. A fixed dome that says "12.95 W max" is a Class 3/af-limit device; a bullet with IR illuminators might say "typical 8 W, max 22 W with IR at full" — that camera is a 25.5 W PoE+ planning line, because IR at full is exactly what happens at 2 a.m. when an intruder event makes the footage matter. IR illuminators alone can add 5 to 10 W to a camera's draw the moment dusk hits, which is why a site that is fine at the 10 a.m. commissioning walk fails at night: the whole camera population steps up in draw within the same twenty minutes of dusk.
A worked example makes the layers visible. Take a 16-camera site on a 24-port switch with a 190 W pool: ten fixed domes at 12.95 W worst case (129.5 W), four IR bullets at 22 W max (88 W), two PTZ units at 51 W with heaters (102 W). The naive spreadsheet used "typical" numbers and totaled 148 W — comfortably under budget. The worst-case total is 319.5 W, and even moving the two PTZs to a separate bt switch leaves 217.5 W of worst-case demand against a 190 W pool. That site ran fine for eight months, because worst case never arrived all at once — until a cold, moonless December night when the IR and the heaters aligned. The math predicted the outage to within a week.
Cold-Weather PTZ Heater Surge: The Silent Killer
This is the failure mode that generates the "only in winter" tickets. An outdoor PTZ with a heater and blower kit can idle at 12 W in July and demand 45 to 60 W in January when the heater, the blower, the IR ring, and the pan motor all run at once. Many outdoor PTZs are 802.3bt (PoE++) devices for exactly this reason — and plugging one into a PoE+ port "works" for nine months of the year. The camera boots, streams, pans. Then the first hard freeze arrives, the heater kicks in, the camera tries to draw past the 25.5 W the port will deliver, and either the camera brownouts and reboots or the switch sheds the port. The customer replaces the camera. It happens again. The camera was never the problem.
The fix is boring: read the camera's cold-weather max draw line (it is usually buried under "power consumption, heater on"), and put every heater-equipped device on a true 802.3bt port budgeted at its winter number. If the switch cannot do bt, a midspan bt injector on that one run is far cheaper than a winter of truck rolls.
PoE Budget Deployment Audit
Run this table for every PoE switch carrying cameras. It takes twenty minutes per switch and it has paid for itself on every site I have applied it to:
| Audit line | How to check | Red flag |
|---|---|---|
| Sum of worst-case device draws | Camera datasheets, "max / heater on / IR on" figures | Sum > 80% of switch PoE pool |
| Allocation vs consumption mode | Switch PoE settings (static class-based vs dynamic) | Class-based allocation full while actual draw is low |
| Per-port class match | Each device's class vs port capability (af/at/bt) | Any heater/PTZ device on an at port |
| Live PoE telemetry | Switch CLI/GUI per-port power readout, checked at night in winter | Any port within 10% of its class ceiling |
| Port priority configuration | PoE priority settings per port | Critical cameras left at default priority |
| PSU thermal environment | Closet/enclosure temperature | Switch in a sealed 45°C enclosure — PSU derating applies |
| Cable runs near 100 m | Patch documentation or TDR | Long runs + high-draw devices = voltage drop margin gone |
The single most valuable line is the live telemetry one. Managed switches report actual per-port wattage; almost nobody looks at it after commissioning. A five-minute check on a cold January night tells you more than any spreadsheet.
Why Cheap Switches Lie About Wattage
"Lie" is strong; "advertise optimistically" is fair. A budget 8-port switch marketed as "PoE+, 120 W" may share one power supply between system electronics and PoE, so the deliverable PoE pool is more like 95 W. Some deliver full wattage only across half the ports. Some derate sharply above 40°C ambient — which is precisely the temperature inside the sealed outdoor cabinet where surveillance switches get installed. And unmanaged budget units give you no telemetry at all, so the first symptom of an oversubscribed budget is a camera dropping, with nothing in any log. This is why I standardize on managed PoE switches with per-port power readouts for surveillance work — NETGEAR's managed lines are a habitual pick for me here because the per-port PoE telemetry and priority controls are exposed plainly in the interface and the published PoE pool numbers have matched what I measure in the field. Whatever brand you run, the requirement is the same: a stated PoE pool that survives measurement, per-port telemetry, and configurable port priority so the intercom and the entrance camera win over the parking lot fill light when the budget gets tight.
PoE, PoE+, PoE++ — What Actually Gets Delivered
The standards ladder, with the numbers that matter: 802.3af (PoE) sources 15.4 W at the port and guarantees 12.95 W at the device after cable losses. 802.3at (PoE+) sources 30 W, delivers 25.5 W. 802.3bt Type 3 sources 60 W and delivers 51 W; Type 4 sources 90 W and delivers 71.3 W. Two field notes on that ladder. First, the delivered number is the only one that belongs in your camera math — the source number is marketing. Second, negotiation is real: a bt camera on an at port does not get 25.5 W "mostly" — it gets a hard ceiling, and devices differ in how gracefully they degrade. Some PTZs disable their heater and log it; some just brown out. You find out which kind you own in January.
Cable Run Length and Voltage Drop
The difference between sourced and delivered power is resistive loss in the cable, and it scales with run length and cable quality. A full 100 m run of marginal cable can eat 4 to 5 W on a high-draw device — that is the entire safety margin on a PoE+ port feeding a 22 W camera. Copper-clad aluminum (CCA) cable, still sold in bargain spools, has meaningfully higher resistance than solid copper and has no place in a PoE plant; I have traced brownout tickets to CCA patch segments more than once. Rules: solid-copper Cat6 minimum for new camera runs, keep high-draw devices under 70 m where the pathway allows it, and when a long run to a heated PTZ is unavoidable, budget the port as if the camera drew 10 percent more than its datasheet max.
The UPS Behind the Switch Is Part of the Budget
One more layer the spreadsheet usually skips: the PoE budget is only as good as the power feeding it. A fully loaded 380 W PoE switch pulls 450 W or more from the wall including its own electronics and conversion losses, and the small UPS someone specced "for the network closet" three years ago may be sized for the old switch. When utility power blips, an undersized UPS delivers a brownout instead of a bridge — and PoE controllers respond to input sag by shedding ports, which looks exactly like the winter camera-reboot pattern but strikes in any season. Size the UPS at the switch's maximum input draw plus 25 percent, check its battery date (runtime degrades meaningfully by year three), and if the recorder shares the same UPS, do the math for both. A camera network that rides through a two-second utility flicker without a single dropped stream is a sizing decision, not luck.
Sizing for Future Camera Additions
Every surveillance estate grows. The two-year pattern is nearly universal: an incident happens somewhere the cameras don't cover, and two or four cameras get added to the nearest switch — which was sized to 95 percent because that saved $200 at bid time. Size every camera switch with 25 to 30 percent of its PoE pool unallocated at day one, and leave physical ports free in the same proportion. On a quoted project this is a line-item argument you will win exactly once: adding headroom at purchase costs tens of dollars per port; adding a second switch, its uplink, its power, and its truck roll in year two costs twenty times that.
Deployment takeaway: Budget PoE at worst-case draw — heater on, IR on, dusk, January — never at typical draw, and load the switch pool to no more than 80 percent of nameplate. Put every heater-equipped outdoor camera on a true 802.3bt port budgeted at its cold-weather max, set PoE port priorities so critical views survive a budget crunch, use solid-copper Cat6 on all camera runs, and leave 25-30 percent of pool and ports free for the cameras year two will add. On Monday morning: log into every camera switch, pull the live per-port PoE readout, and compare each port against its class ceiling — any port within 10 percent is your next winter outage, findable in February for free instead of in a January truck roll.
Where This Fits in a Deployment Program
PoE budgeting sits at the seam between the camera schedule and the network design, and it is the seam most projects staple together last. Treat the power audit above as a standing deliverable — run it at commissioning, then re-run it the first cold week of every winter — and the "random reboot" ticket class disappears from your queue. The switching, cabling, and power gear this article leans on lives in the Infrastructure catalog, and NETGEAR networking covers the managed PoE lines with the per-port telemetry that makes the audit possible — see all NETGEAR products for bt-capable options when the PTZ math demands them. If you have a camera estate with a winter reboot history, send over the switch models, camera list, and run lengths — happy to help you rebuild the power budget against worst-case numbers before the next freeze does it for you.