{"id":2088,"date":"2026-09-17T12:54:36","date_gmt":"2026-09-17T12:54:36","guid":{"rendered":"https:\/\/integrationobjects.com\/blog\/?p=2088"},"modified":"2026-09-17T13:13:55","modified_gmt":"2026-09-17T13:13:55","slug":"what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications","status":"publish","type":"post","link":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/","title":{"rendered":"What Is OPC Tunneling? The Complete Guide to DCOM-Free OPC Communications"},"content":{"rendered":"<p>OPC tunneling is a method for moving OPC Classic data (DA, HDA, and AE) across a network by replacing DCOM with a single, configurable TCP\/IP connection. When implemented right, it removes the dynamic port ranges, domain-trust requirements, and long timeout windows that make DCOM unreliable across firewalls, adds a security layer and lets OPC clients and servers communicate as if they were on the same machine.<\/p>\n  \r\n    \r\n<div id=\"wpj-jtoc\" class=\"wpj-jtoc wpj-jtoc--main --jtoc-the-content --jtoc-theme-original-v3 --jtoc-title-align-left --jtoc-toggle-icon --jtoc-toggle-position-right --jtoc-toggle-1 --jtoc-has-numeration --jtoc-header-as-toggle --jtoc-headings-full-row-clickable --jtoc-text-hover-soft --jtoc-has-custom-styles --jtoc-is-unfolded --jtoc-animate --jtoc-align-left\" >\r\n  <!-- TOC -->\r\n        <div class=\"wpj-jtoc--toc wpj-jtoc--toc-inline \" >\r\n              <div class=\"wpj-jtoc--header\">\r\n        <div class=\"wpj-jtoc--header-main\">\r\n                    <div class=\"wpj-jtoc--title\">\r\n                        <span class=\"wpj-jtoc--title-label\">Table of contents<\/span>\r\n          <\/div>\r\n                                <div class=\"wpj-jtoc--toggle-wrap\">\r\n                                                          <div class=\"wpj-jtoc--toggle-box\">\r\n                  <div class=\"wpj-jtoc--toggle\"><\/div>\r\n                <\/div>\r\n                          <\/div>\r\n                  <\/div>\r\n      <\/div>\r\n            <div class=\"wpj-jtoc--body\">\r\n            <nav class=\"wpj-jtoc--nav\">\r\n        <ol class=\"wpj-jtoc--items\"><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--1--><\/span>        <a href=\"#what-is-opc-tunneling\"  rel=\"nofollow\"  title=\"What is OPC tunneling?\" data-numeration=\"1\">What is OPC tunneling?<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--2--><\/span>        <a href=\"#why-dcom-breaks-down-across-networks\"  rel=\"nofollow\"  title=\"Why DCOM breaks down across networks\" data-numeration=\"2\">Why DCOM breaks down across networks<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--3--><\/span>        <a href=\"#how-opc-tunneling-works\"  rel=\"nofollow\"  title=\"How OPC tunneling works\" data-numeration=\"3\">How OPC tunneling works<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--4--><\/span>        <a href=\"#what-a-robust-tunneling-solution-should-provide\"  rel=\"nofollow\"  title=\"What a robust tunneling solution should provide\" data-numeration=\"4\">What a robust tunneling solution should provide<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--5--><\/span>        <a href=\"#opc-tunneling-vs-opc-ua\"  rel=\"nofollow\"  title=\"OPC tunneling vs. OPC UA\" data-numeration=\"5\">OPC tunneling vs. OPC UA<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--6--><\/span>        <a href=\"#when-to-use-opc-tunneling\"  rel=\"nofollow\"  title=\"When to use OPC tunneling\" data-numeration=\"6\">When to use OPC tunneling<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--7--><\/span>        <a href=\"#choosing-a-tunneling-solution\"  rel=\"nofollow\"  title=\"Choosing a tunneling solution\" data-numeration=\"7\">Choosing a tunneling solution<\/a>\r\n                    <\/div><\/li><li class=\"wpj-jtoc--item --jtoc-h2\">\r\n        <div class=\"wpj-jtoc--item-content --jtoc-h2\" data-depth=\"2\">\r\n                                        <span class=\"jtoc--num\"><!--8--><\/span>        <a href=\"#frequently-asked-questions-on-opc-tunneling\"  rel=\"nofollow\"  title=\"Frequently asked questions on OPC tunneling\" data-numeration=\"8\">Frequently asked questions on OPC tunneling<\/a>\r\n                    <\/div><\/li><\/ol>      <\/nav>\r\n          <\/div>\r\n      <\/div>\r\n    <\/div>\r\n\n<h2>What is OPC tunneling?<\/h2>\n<p>OPC Classic, the family of OPC standards that mainly includes OPC DA (Data Access), OPC HDA (Historical Data Access), and OPC AE (Alarms and Events), was built in the 1990s around Microsoft Windows. Microsoft&#8217;s Component Object Model (COM) and DCOM as its distributed extension, were the natural choice as it was the dominant Microsoft technology for creating standardized, language-independent software interfaces on Windows. COM was designed for applications talking to each other on the same machine and DCOM for applications communication within the same tightly managed Windows domain. It was never designed for the firewall-separated, security-conscious networks that define modern industrial environments and where an OT network and an IT network are deliberately kept apart.<\/p>\n<p>OPC tunneling closes DCOM gaps without replacing OPC Classic itself. The tunneling software can be considered as a small piece of software installed on both the machine hosting the OPC server and the machine hosting the OPC client. Each tunneling component connects to its local OPC application using ordinary COM, exactly as if the OPC client and server were on the same computer. The 2 tunneling components then exchange data with each other over a single <a href=\"https:\/\/integrationobjects.com\/blog\/verify-tcp-port-is-open-to-establish-opcnet-broker-communications\/\">TCP\/IP connection<\/a>, typically encrypted, that can pass cleanly through a firewall or NAT. From the point of view of the OPC client and the OPC server, nothing has changed: neither application is aware that a tunnel, rather than a direct DCOM link, is carrying the data across the network.<\/p>\n<p>This matters because the installed base of OPC DA, HDA, and AE systems in operating plants is enormous, and most of it is not being replaced any time soon. Tunneling gives that installed base a secure, modern, firewall-friendly way to keep working across network boundaries in a secure way and without touching the client or server software itself.<\/p>\n<h2>Why DCOM breaks down across networks<\/h2>\n<p>To understand why OPC tunneling exists, it is important to first understand the limitations of DCOM and the challenges of configuring it when an OPC connection must cross a network boundary.<\/p>\n<ol>\n<li>DCOM uses dynamic port allocation: a client first contacts the server&#8217;s DCOM endpoint mapper on TCP port 135, which then hands back a randomly assigned high-numbered port, typically somewhere in the 49152\u201365535 range, for the actual data exchange. A firewall separating two networks has exactly two options: open that entire dynamic range, which most security teams will not accept, or block OPC Classic traffic entirely, which defeats the purpose of connecting the systems at all.<\/li>\n<li>DCOM also expects matching Windows user accounts or a shared Windows domain on both the client and server machines, which is difficult to maintain when the two networks are administered separately.<\/li>\n<li>It has a hardcoded connection timeout of around six minutes, so a brief network interruption can leave an OPC client appearing to hang, sometimes requiring a manual restart to recover.<\/li>\n<li>And because DCOM predates modern network security practice, it has no built-in encryption: data crosses the network in the clear unless additional network measures are layered on top.<\/li>\n<li>A Windows security update, first released in 2021, tightened DCOM&#8217;s authentication requirements (<a href=\"https:\/\/integrationobjects.com\/blog\/windows-dcom-server-security-feature-bypass\/\">Microsoft&#8217;s KB5004442 update in 2021<\/a>), and working OPC Classic connections that relied on older, looser settings stop functioning until they&#8217;re rebuilt or at least reconfigured.<\/li>\n<li>DCOM&#8217;s vulnerabilities are well documented, both inside and outside the process control community: any port or service it opens becomes a target hackers can probe with off-the-shelf exploit scripts.<\/li>\n<li>Getting DCOM to work reliably when the client and server are on separate machines is a leading source of support escalations. Configuration can take days or even weeks, often requiring expert assistance and a trial-and-error approach to identify the correct settings. .<\/li>\n<li>DCOM cannot traverse Network Address Translation (NAT). Because DCOM relies on RPC endpoint negotiation and dynamically assigned ports, NAT can disrupt endpoint resolution and subsequent RPC connections.<\/li>\n<\/ol>\n<p style=\"text-align: center;\"><a class=\"wp-block-button__link has-luminous-vivid-orange-background-color has-background no-border-radius\" style=\"display: block; color: black !important; width: max-content; margin: 20px auto;\" href=\"https:\/\/integrationobjects.com\/blog\/what-is-dcom\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>What is DCOM<\/strong><\/a><\/p>\n<h2>How OPC tunneling works<\/h2>\n<p>At a technical level, an OPC tunneling deployment pairs two components: one installed on the machine hosting the OPC server, the other on the machine hosting the OPC client. Each component connects to its local OPC application over ordinary COM &#8211; exactly as if the OPC client and the OPC server were on the same machine &#8211; and registers itself locally as the counterpart the client or server is expecting to talk to.<\/p>\n<p>The two components exchange data over a single, secure TCP connection that crosses the firewall. In a typical reference architecture, the server-side component listens on a configured port and the client-side component initiates the connection to it, so only that one port ever needs to be opened &#8211; a sharp contrast to DCOM\u2019s wide, dynamic port range. Rather than keeping an independent mirror of the server&#8217;s data, each component acts as a transparent relay: when the OPC client issues a read, write, or subscription request, the tunnel forwards it across the connection to the real OPC server in real-time and relays the response back.<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_2089\" aria-describedby=\"caption-attachment-2089\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-2089\" src=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/OPC_Tunneling_Diagrams.pdf-1024x597.png\" alt=\"Diagram of OPC tunneling architecture showing OT and IT networks connected through a single TCP port across a firewall \" width=\"640\" height=\"373\" srcset=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/OPC_Tunneling_Diagrams.pdf-1024x597.png 1024w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/OPC_Tunneling_Diagrams.pdf-300x175.png 300w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/OPC_Tunneling_Diagrams.pdf-768x448.png 768w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/OPC_Tunneling_Diagrams.pdf-1536x896.png 1536w, https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/OPC_Tunneling_Diagrams.pdf.png 1600w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><figcaption id=\"caption-attachment-2089\" class=\"wp-caption-text\">How OPC tunneling routes OPC Classic data across a firewall without DCOM<\/figcaption><\/figure>\n<h2>What a robust tunneling solution should provide<\/h2>\n<p>Not every tunneling implementation offers the same level of security or reliability. Whichever solution you evaluate, look for the following as baseline requirements rather than optional extras:<\/p>\n<ol>\n<li>A single, user-configurable TCP port, rather than a fix or well-known port<\/li>\n<li>Configurable data encryption paired with secure user authentication, password-based or tied to Windows accounts, rather than relying on default, unauthenticated settings<\/li>\n<li>User authentication and, ideally, role- or tag-level access control<\/li>\n<li>Configurable timeout parameters for fast break detection, well under DCOM&#8217;s multi-minute timeout<\/li>\n<li>Automatic reconnection allowing the two tunneling components to reestablish communications after network glitches without requiring user intervention<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><a class=\"wp-block-button__link has-luminous-vivid-orange-background-color has-background no-border-radius\" style=\"display: block; color: black !important; width: max-content; margin: 20px auto;\" href=\"https:\/\/integrationobjects.com\/blog\/common-opc-tunneling-issues-how-to-solve-them\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Common OPC Tunneling issues<\/strong><\/a><\/p>\n<h2>OPC tunneling vs. OPC UA<\/h2>\n<p>OPC UA solves the same cross-network problem, but from a different direction. Rather than adding a transport layer on top of OPC Classic, OPC UA was designed from the ground up on TCP\/IP, with security, authentication, and firewall-friendly communication built into the protocol itself in order to replace OPC Classic. Where both the OPC server and every OPC client involved support OPC UA, a direct UA connection is generally the cleanest long-term architecture, and the recommended path for new deployments.<\/p>\n<p>In practice, that condition is not often met. A large share of installed OPC DA servers won&#8217;t be replaced soon; some client applications only ever shipped with DA support. Tunneling and OPC UA are not mutually exclusive. They address different stages of the industrial connectivity journey. For existing OPC Classic environments, <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-tunneling\/opcnet-broker-da-hda-ae\">OPCNet Broker\u00ae DA HDA AE<\/a> eliminates DCOM from remote OPC DA, HDA and AE communications, providing secure and reliable connectivity across networks, firewalls and NAT. For organizations looking to modernize their architecture, <a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-unified-architecture\/opc-ua-wrapper\">OPC UA Wrapper<\/a> provides a bridge between legacy OPC Classic systems and OPC UA, enabling a gradual migration without replacing existing OPC infrastructure. For new and unified architectures, our <a href=\"https:\/\/integrationobjects.com\/sioth\/opc-ua-universal-server\">OPC UA Universal Server<\/a> provides a modern OPC UA layer for secure, standardized IT\/OT connectivity. Together, these products allow organizations to address today&#8217;s OPC Classic connectivity challenges while establishing a practical path toward OPC UA modernization.<\/p>\n<p style=\"text-align: center;\"><a class=\"wp-block-button__link has-luminous-vivid-orange-background-color has-background no-border-radius\" style=\"display: block; color: black !important; width: max-content; margin: 20px auto;\" href=\"https:\/\/integrationobjects.com\/blog\/what-is-opc-ua\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>See our guide on OPC UA<\/strong><\/a><\/p>\n<h2>When to use OPC tunneling<\/h2>\n<ol>\n<li><strong>OPC DA across a firewall or NAT<\/strong><\/li>\n<\/ol>\n<p>This is the scenario tunneling was built for. An OPC DA server sits on one network segment; a historian, SCADA system, or analytics platform sits on another, separated by a firewall. DCOM cannot cross that firewall without opening an unacceptable port range. Tunneling solves it with a single, configurable TCP connection between the two endpoints &#8211; one port to open, instead of DCOM\u2019s wide dynamic range.<\/p>\n<ol start=\"2\">\n<li><strong>Cross-domain or workgroup environments.<\/strong><\/li>\n<\/ol>\n<p>Where OT and IT networks are administered separately &#8211; a common pattern in plants that keep operational systems out of the corporate Windows domain &#8211; <a href=\"https:\/\/integrationobjects.com\/blog\/dcom-settings-for-opc-communications\/\">DCOM&#8217;s requirement<\/a> for matching user accounts becomes an ongoing maintenance burden, especially after password rotations or Windows updates. Tunneling authenticates independently of the underlying Windows accounts.<\/p>\n<ol start=\"3\">\n<li><strong>Collecting OPC data from multiple remote sites.<\/strong><\/li>\n<\/ol>\n<p>When OPC servers sit at remote sites connected over WAN, cellular, or VPN links, DCOM&#8217;s timing assumptions break down almost immediately; the latency alone is often enough to cause failures. Tunneling, built on ordinary TCP, tolerates WAN latency and can secure data transfer from several remote sites into a single data set on a central endpoint.<\/p>\n<ol start=\"4\">\n<li><strong>Recovering from a Windows security update that broke a working DCOM connection.<\/strong><\/li>\n<\/ol>\n<p>Every time Microsoft tightens DCOM&#8217;s security requirements, some previously working OPC Classic network connections stop functioning until reconfigured. Moving to tunneling removes OPC networking from that maintenance cycle.<\/p>\n<h2>Choosing a tunneling solution<\/h2>\n<p>Use the checklist above as a starting point for evaluating any tunneling product: ask specifically about port configuration, encryption, authentication granularity, communication time out.<\/p>\n<p><a href=\"https:\/\/integrationobjects.com\/sioth-opc\/sioth-opc-tunneling\/opcnet-broker-da-hda-ae\">Integration Objects&#8217; OPCNet Broker\u00ae<\/a> is built around these same principles. It tunnels OPC DA, HDA, and AE data over a single configurable TCP port, with data encryption, user authentication, and tag-level access control with its Tag Security add-on, and configurable communication timeouts. If your environment matches one of the scenarios above &#8211; particularly OPC DA crossing a firewall, NAT, network segmentation or DMZ &#8211; it&#8217;s worth a closer look.<\/p>\n<p style=\"text-align: center;\"><a class=\"wp-block-button__link has-luminous-vivid-orange-background-color has-background no-border-radius\" style=\"display: block; color: black !important; width: max-content; margin: 20px auto;\" href=\"https:\/\/integrationobjects.com\/blog\/step-by-step-setting-up-opcnet-broker-in-15-minutes\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>See the step-by-step OPCNet Broker\u00ae setup guide<\/strong><\/a><\/p>\n<h2 style=\"margin: 16.0pt 0in 7.5pt 0in;\">Frequently asked questions on OPC tunneling<\/h2>\n<style>#sp-ea-2091 .spcollapsing { height: 0; overflow: hidden; transition-property: height;transition-duration: 300ms;}#sp-ea-2091.sp-easy-accordion>.sp-ea-single {margin-bottom: 10px; border: 1px solid #e2e2e2; }#sp-ea-2091.sp-easy-accordion>.sp-ea-single>.ea-header a {color: #444;}#sp-ea-2091.sp-easy-accordion>.sp-ea-single>.sp-collapse>.ea-body {background: #fff; color: #444;}#sp-ea-2091.sp-easy-accordion>.sp-ea-single {background: #eee;}#sp-ea-2091.sp-easy-accordion>.sp-ea-single>.ea-header a .ea-expand-icon { float: left; color: #444;font-size: 16px;}.sp-easy-accordion .sp-ea-single .ea-header a{\r\n  display: block;\r\n    text-decoration: none;\r\n    cursor: pointer;\r\n    font-weight: 600;\r\n    color: #444;\r\n    font-size: 16px;\r\n    line-height: 1;\r\n  box-shadow: none;}<\/style><div id=\"sp_easy_accordion-1789649548\"><div id=\"sp-ea-2091\" class=\"sp-ea-one sp-easy-accordion\" data-ea-active=\"ea-click\" data-ea-mode=\"vertical\" data-preloader=\"\" data-scroll-active-item=\"\" data-offset-to-scroll=\"0\"><div class=\"ea-card ea-expand sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20910\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20910\" aria-controls=\"collapse20910\" href=\"#\" aria-expanded=\"true\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-minus\"><\/i> Does OPC tunneling require any changes to the OPC client or server software? <\/a><\/h3><div class=\"sp-collapse spcollapse collapsed show\" id=\"collapse20910\" data-parent=\"#sp-ea-2091\" role=\"region\" aria-labelledby=\"ea-header-20910\"> <div class=\"ea-body\"><p>No. The tunneling application installs alongside the existing OPC client and server and connects to each of them locally through standard COM. Neither application needs to be reconfigured or replaced.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20911\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20911\" aria-controls=\"collapse20911\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Can OPC tunneling work over the internet, or only on a local network? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20911\" data-parent=\"#sp-ea-2091\" role=\"region\" aria-labelledby=\"ea-header-20911\"> <div class=\"ea-body\"><p>It works over any TCP\/IP network, including wide-area networks, cellular connections, and VPNs. For internet-facing connections specifically, data encryption and authentication should always be enabled.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-20912\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse20912\" aria-controls=\"collapse20912\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Is OPC tunneling actually secure? <\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse20912\" data-parent=\"#sp-ea-2091\" role=\"region\" aria-labelledby=\"ea-header-20912\"> <div class=\"ea-body\"><p>When implemented with data encryption, authentication, and access control, tunneling is materially more secure than an unencrypted DCOM connection, which has no built-in encryption at all. Security depends on how the specific solution is configured, not on tunneling as a concept alone.<\/p><\/div><\/div><\/div><script type=\"application\/ld+json\">{ \"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"@id\": \"sp-ea-schema-2091-6aae7bc006a09\", \"mainEntity\": [{ \"@type\": \"Question\", \"name\": \"Does OPC tunneling require any changes to the OPC client or server software? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"No. The tunneling application installs alongside the existing OPC client and server and connects to each of them locally through standard COM. Neither application needs to be reconfigured or replaced.\" } },{ \"@type\": \"Question\", \"name\": \"Can OPC tunneling work over the internet, or only on a local network? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"It works over any TCP\/IP network, including wide-area networks, cellular connections, and VPNs. For internet-facing connections specifically, data encryption and authentication should always be enabled.\" } },{ \"@type\": \"Question\", \"name\": \"Is OPC tunneling actually secure? \", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"When implemented with data encryption, authentication, and access control, tunneling is materially more secure than an unencrypted DCOM connection, which has no built-in encryption at all. Security depends on how the specific solution is configured, not on tunneling as a concept alone.\" } }] }<\/script><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>OPC tunneling is a method for moving OPC Classic data (DA, HDA, and AE) across a network by replacing DCOM with a single, configurable TCP\/IP<\/p>\n","protected":false},"author":1,"featured_media":2090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185],"tags":[49],"class_list":["post-2088","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opc-tunneling","tag-opcnet-broker"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What Is OPC Tunneling? Complete Guide<\/title>\n<meta name=\"description\" content=\"OPC tunneling replaces DCOM with a secure, firewall-friendly TCP connection for OPC Classic data. Learn how it works, when to use it, and how to choose a solution.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Is OPC Tunneling? Complete Guide\" \/>\n<meta property=\"og:description\" content=\"OPC tunneling replaces DCOM with a secure, firewall-friendly TCP connection for OPC Classic data. Learn how it works, when to use it, and how to choose a solution.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/\" \/>\n<meta property=\"og:site_name\" content=\"OPC Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Integration.Objects.OPC\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T12:54:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-17T13:13:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/What-Is-OPC-Tunneling-The-Complete-Guide-to-DCOM-Free-OPC-Communication.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1248\" \/>\n\t<meta property=\"og:image:height\" content=\"832\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"OPCBlogAdmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@IntegObjects\" \/>\n<meta name=\"twitter:site\" content=\"@IntegObjects\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"OPCBlogAdmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Is OPC Tunneling? Complete Guide","description":"OPC tunneling replaces DCOM with a secure, firewall-friendly TCP connection for OPC Classic data. Learn how it works, when to use it, and how to choose a solution.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/","og_locale":"en_US","og_type":"article","og_title":"What Is OPC Tunneling? Complete Guide","og_description":"OPC tunneling replaces DCOM with a secure, firewall-friendly TCP connection for OPC Classic data. Learn how it works, when to use it, and how to choose a solution.","og_url":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/","og_site_name":"OPC Blog","article_publisher":"https:\/\/www.facebook.com\/Integration.Objects.OPC\/","article_published_time":"2026-09-17T12:54:36+00:00","article_modified_time":"2026-09-17T13:13:55+00:00","og_image":[{"width":1248,"height":832,"url":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/What-Is-OPC-Tunneling-The-Complete-Guide-to-DCOM-Free-OPC-Communication.png","type":"image\/png"}],"author":"OPCBlogAdmin","twitter_card":"summary_large_image","twitter_creator":"@IntegObjects","twitter_site":"@IntegObjects","twitter_misc":{"Written by":"OPCBlogAdmin","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/","url":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/","name":"What Is OPC Tunneling? Complete Guide","isPartOf":{"@id":"https:\/\/integrationobjects.com\/blog-\/#website"},"primaryImageOfPage":{"@id":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/#primaryimage"},"image":{"@id":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/#primaryimage"},"thumbnailUrl":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/What-Is-OPC-Tunneling-The-Complete-Guide-to-DCOM-Free-OPC-Communication.png","datePublished":"2026-09-17T12:54:36+00:00","dateModified":"2026-09-17T13:13:55+00:00","author":{"@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/6efbaf488a07e418b93ff77f00af386b"},"description":"OPC tunneling replaces DCOM with a secure, firewall-friendly TCP connection for OPC Classic data. Learn how it works, when to use it, and how to choose a solution.","breadcrumb":{"@id":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/#primaryimage","url":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/What-Is-OPC-Tunneling-The-Complete-Guide-to-DCOM-Free-OPC-Communication.png","contentUrl":"https:\/\/integrationobjects.com\/blog\/wp-content\/uploads\/2026\/09\/What-Is-OPC-Tunneling-The-Complete-Guide-to-DCOM-Free-OPC-Communication.png","width":1248,"height":832,"caption":"What Is OPC Tunneling? Complete Guide"},{"@type":"BreadcrumbList","@id":"https:\/\/integrationobjects.com\/blog\/what-is-opc-tunneling-the-complete-guide-to-dcom-free-opc-communications\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/integrationobjects.com\/blog-\/"},{"@type":"ListItem","position":2,"name":"What Is OPC Tunneling? The Complete Guide to DCOM-Free OPC Communications"}]},{"@type":"WebSite","@id":"https:\/\/integrationobjects.com\/blog-\/#website","url":"https:\/\/integrationobjects.com\/blog-\/","name":"OPC Blog","description":"OPC and related technologies news from Integration Objects","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/integrationobjects.com\/blog-\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/6efbaf488a07e418b93ff77f00af386b","name":"OPCBlogAdmin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/integrationobjects.com\/blog-\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f2d787c3c48eb147d5b4d0c9d05c6f35a5946c7dc40af2eedbe64030e99ea299?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f2d787c3c48eb147d5b4d0c9d05c6f35a5946c7dc40af2eedbe64030e99ea299?s=96&d=mm&r=g","caption":"OPCBlogAdmin"}}]}},"_links":{"self":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/comments?post=2088"}],"version-history":[{"count":3,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2088\/revisions"}],"predecessor-version":[{"id":2094,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/posts\/2088\/revisions\/2094"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/media\/2090"}],"wp:attachment":[{"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/media?parent=2088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/categories?post=2088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/integrationobjects.com\/blog\/wp-json\/wp\/v2\/tags?post=2088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}