Connecting PLCs and OPC-UA servers
Connecting PLCs and OPC-UA servers
Point the on-prem connector at a machine's OPC-UA server, Modbus device or fleet broker, then browse its tags and bind them to roles.
Permissions: The Tag map page (/shop-floor/settings/tag-map) needs the DataMagik - Builder role, the Shop Floor license feature and the Shop Floor OT connectivity license feature. Giving a tag a write class additionally needs the OT write license feature. Downloading certificates from /connectors/connector-setup also needs DataMagik - Builder.
How the connection works
An endpoint (shown as a Gateway on bindings) is the address of a machine's server and how the connector agent identifies itself to it. The agent dials this address — the cloud never does — so the URL must resolve on the plant network the agent sits on. Every endpoint belongs to a site, so add a site first under /shop-floor/settings/sites, and install a connector at that site (see Connector setup).
Add an endpoint
- Open
/shop-floor/settings/tag-map, choose the Site, and click Endpoints. The form is headed Add an endpoint. - Choose the Protocol: OPC-UA, Modbus TCP, Modbus RTU (serial) or VDA 5050 (fleet MQTT broker).
- Give it a Name, for example
Cell 3 gateway. - Enter the address under Endpoint URL (described below).
- For OPC-UA, set Security policy, Security mode and Identity; for the other protocols, fill in their own fields.
- Optionally choose a Pinned connector, then click Save endpoint.
Each saved endpoint shows whether it is reachable, its last attempt failed (with the error), or it is not tried yet. Use Edit to change one; its tag bindings stay attached.
Entering the address
The address is entered in parts: Scheme, Host or IP address, Port and, for OPC-UA, Path (optional). Modbus RTU replaces host and port with a Serial port. The Full URL box shows what the parts make, and it is what is saved. Paste a whole URL into Full URL or into Host and the fields fill in.
- OPC-UA:
opc.tcp://, standard port 4840. - Modbus TCP:
modbus://, port 502. Also set Unit id and Poll every (ms). - Modbus RTU:
modbus-rtu:///dev/ttyUSB0ormodbus-rtu://COM3— a serial port on the connector's own machine. Also set Baud rate, Parity, Data bits and Stop bits. - VDA 5050: the fleet's broker,
mqtt://host:1883(ormqtts://, port 8883). Also set Topic prefix (interface name) and Map id the vehicles use.
A line under the address checks it as you type: a green tick with the full URL when it is usable, or what is wrong — a missing host, a host containing spaces, slashes or user names, a port outside 1 to 65535, or a path with spaces.
Server presets
For OPC-UA, the Server buttons fill in the port, path, security and identity a server ships with. The host stays yours.
- Ignition: port 62541, Basic256Sha256 / SignAndEncrypt, username. Sign in with an Ignition user (
opcuauserby default), and approve DataMagik's certificate under Config › Security › Certificates if it is quarantined. - KEPServerEX: port 49320, Basic256Sha256 / SignAndEncrypt, anonymous. In the OPC UA Configuration Manager, enable an endpoint on this network and trust DataMagik's certificate under Trusted Clients.
- FactoryTalk Linx Gateway: port 4990, path
/FactoryTalkLinxGateway1, Basic256Sha256 / SignAndEncrypt, username. Trust DataMagik's certificate in the gateway's OPC UA configuration and sign in with a FactoryTalk user. - Other OPC UA: port 4840, security None, anonymous. Choose the security your server offers.
If the OPC-UA server runs on the same PC as the connector, click Same computer as the connector (127.0.0.1).
Find servers on this host
Enter a host, then click Find servers on this host. The site's connector (or the pinned one) probes a fixed list of the usual OPC-UA ports on that one host — it never scans the network. Each server that answers is listed with the security it Offers and whether it Needs a sign-in. A server that accepts the connection and then closes it is listed too, marked Answered, then closed the connection: it is there, but it has not trusted the connector yet or does not allow an unsecured request — trust DataMagik's certificate on the server (see Certificates below) and choose a secure policy. Choosing a result fills in the URL, picks the strongest security the server offers, and sets the identity; a single result is chosen for you.
Security, identity and pinning
- Security policy: None, Basic128Rsa15, Basic256, Basic256Sha256, Aes128_Sha256_RsaOaep or Aes256_Sha256_RsaPss.
- Security mode: None, Sign or SignAndEncrypt.
- Identity:
anonymousorusername. Username and Password are required when the identity is a username. - Pinned connector: the agent that reaches this gateway. Leave it as Any connector at this site, or pin one. Modbus RTU and VDA 5050 gateways must be pinned.
Certificates
With a secure policy, the gateway must trust the connector's certificate. Open /connectors/connector-setup and click Download Connector; the menu has an OPC-UA certificate authority section.
- Pick a Certificate format: PEM (Linux, KEPServerEX, most OPC UA SDKs), CER (Windows certificate store, Ignition import) or DER (Ignition trusted/certs folder, Siemens, Rockwell).
- Click Download CA certificate. Its Valid until date and SHA-256 fingerprint are shown so you can check the file.
- Import it once into each gateway's trusted certificates — the trust list itself, not the separate issuers store. Every connector of your company is then trusted, so no agent's certificate has to be approved out of quarantine by hand. On Ignition that is
…/com.inductiveautomation.opcua/server/security/pki/trusted/certs. - For a gateway that trusts certificates one by one, download a connector's own certificate from Connector client certificates in the same menu.
Caution: On Ignition, a CA left only in issuer/certs is not a trust anchor. The gateway still quarantines every agent, and the endpoint shows as unreachable rather than as a certificate problem.
Browse and bind tags
- Pick the Endpoint. The Address space is read live from the server — nothing is cached. Folders expand on demand; use Refresh tree to reload. Modbus has nothing to browse, so type the register instead, for example
hr:40:float32. - Click a tag. Under Bind the selected node, choose Bind to: A machine's role (pick the Workcenter and Role) or A signal on equipment (pick the Equipment and a signal name such as
battery). The page warns if the node's datatype cannot serve that role. - Leave Write class at None — read-only unless the tag must be written, then click Bind.
In Current bindings, the Gateway column says which endpoint serves each node. On a site with several gateways, a binding with no gateway is not captured at all.
Signal health
The Signal health column shows each binding as Healthy, Learning, Changes rarely, No samples yet, Frozen since a time (stopped changing while the machine ran) or No value since a time, plus any spikes. Frozen and empty signals are also summarised above the table.