0%
OPCNet Broker® DA HDA AE Overview

OPCNet Broker® DA HDA AE is an all-in-one OPC tunneling product

  • Eliminates DCOM configuration headaches.
  • Provides secure and encrypted communications.
  • Supports OPC Data Access, Historical Data Access, and Alarms and Events.
  • Works seamlessly across firewalls and segmented networks.
  • Enables reliable remote OPC connectivity in minutes, not hours
OPCNet Broker system architecture enabling secure OPC DA, HDA, and AE data exchange across distributed sites
OPC Tunneling Explained

What Is OPC Tunneling?

OPC tunneling replaces DCOM-based OPC Classic communication with a secure, single-port TCP/IP connection between an OPC client and an OPC server. It removes DCOM’s dynamic port ranges, matching-credential requirements, and per-machine security configuration, which are the issues that make DCOM notoriously difficult to open across firewalls, domains, and WANs. OPCNet Broker® applies this approach to OPC DA, HDA, and AE traffic, acting as a transparent gateway that existing OPC clients and servers connect to without modification.
  1. Step 01

    Wrap

    An OPCNet Broker Server Side sits next to the OPC DA, HDA, or AE server and wraps its calls for transmission. No change to the underlying OPC server.

  2. Step 02

    Transmit

    Wrapped calls travel across the network via the OPC tunnel using a single configurable TCP port, through firewalls, NAT, DMZs, and WAN links, encrypted and authenticated in transit.

  3. Step 03

    Unwrap

    An OPCNet Broker Client Side on the receiving OPC Client machine unwraps the calls and presents them to the local OPC client exactly as a native OPC connection would.

How ONB® compares to native DCOM communications


CapabilityDCOM ONB: OPCNet Broker
Configuration Manual DCOM configuration on every machine: security settings, user permissions, user accounts sharing  Deployed and configured in a few clicks. No DCOM configuration required
Firewall & Port Handling  Requires opening a wide, often dynamic range of ports, multiplying security exposure
  Requires opening a well known TCP port number
  Single port open in the firewall, port number configurable
  Tracks client/server communication through a single TCP port, minimizing security holes
NAT, DMZ & Proxy Traversal  Not designed for NAT traversal; typically breaks across firewalls, DMZs and proxies  Navigates NAT, DMZ, firewalls and proxies natively
Security & Compliance  Relies on the native Windows security model. No built-in encryption  IEC 62443-aligned; built-in data encryption and user authentication
Call Timeout Handling  Fixed, mandatory 6-minute call timeout after a communication failure  Configurable call timeout parameters, so activities restart far faster after a glitch
Network Efficiency  No native data compression  Built-in data compression, reducing bandwidth costs and network strain
Recovery After Disruption  Manual intervention typically required after a network glitch  Automatic OPC reconnection and data recovery after communication glitches
Redundancy  No native redundancy management; requires custom engineering  Built-in servers redundancy management (active-active, active-passive)
Cross-Domain Connectivity  Difficult across domains without established trust relationships  Connects OPC components across different domains, LAN and WAN
Ongoing Maintenance  Prone to breaking after Windows/security updates; requires repeated DCOM tuning  Easy to deploy and maintain, via a graphical user interface
Use Cases

Who Uses OPC Tunneling?

Any industrial site running OPC Classic (DA, HDA, or AE) systems that needs to communicate across a network, through a firewall, a plant-to-cloud gateway, a remote site link, or a segmented control network. Some use case examples are listed below:
  1. Oil & Gas

    Connecting remote wellhead or pad SCADA systems back to a central historian across corporate and field networks, without opening the wide port ranges DCOM requires at every remote site.

  2. Mining & Minerals

    Bridging OPC servers between pit-level control systems and plant-level historians across segmented, often firewalled network zones.

  3. Pharmaceutical

    Keeping validated, unmodified OPC Classic systems in place while satisfying cyber security policies that restrict or prohibit DCOM traffic on the network.

  4. Water & Desalination

    Linking remote treatment or pumping sites to a central SCADA/historian over WAN or VPN links where DCOM’s dynamic ports are impractical to manage.

OPCNet Broker® DA HDA AE Features

Core Capabilities

  • DCOM-Free Architecture: Eliminates DCOM dependencies, security vulnerabilities and configuration complexities 
  • Full OPC Support: Full compatibility with OPC DA 2.05a/3.0, OPC HDA 1.2, and OPC AE 1.1 specifications 
  • Cross-Network Connectivity: Seamless communications across firewalls, domains, NAT and wide-area networks 
  • Plug-and-Play Setup: Deploy OPC tunnels in minutes with intuitive installation wizard and configuration tools 

Security & Compliance

  • Data encryption for all OPC data transmission 
  • User Authentication: User access control with Windows authentication integration 
  • ISA/IEC 62443 Compliance: Meets industrial cybersecurity standard requirements for critical infrastructure 
  • Network Segmentation Support: Secure communications across DMZ and isolated network zones using a single TCP port 

Performance & Reliability

  • High-Speed Data Transfer: Optimized for real-time industrial data
  • Connection Redundancy: Automatic failover and reconnection capabilities for OPC Servers 
  • Resource Optimization: Lightweight footprint with minimal system resource usage 

Management & Monitoring

  • Intuitive end user interface for managing multiple OPC tunnels 
  • Comprehensive logging for connection status monitoring, tracking client/server communications, and troubleshooting 
  • Configurable communication timeouts  
00
%
Fewer OPC Communications Issues


00
+
Successful Deployments


00
%
Uptime Guarantee


Full OPC Support

OPC Support

OPC DA
OPC DA Tunneling

Secure tunneling for OPC DA servers.

  • Full compliance with the OPC DA specification (2.05a and 3.0)
  • Address-space browsing and tag translation from the source server
  • Read, write, and subscriptions with full value, quality, and timestamp fidelity
OPC HDA
OPC HDA Tunneling

Historical data tunneling

  • Full compliance with the OPC HDA specification
  • Support for both raw and aggregated (processed) data
  • Standard HDA aggregates (average, min/max, interpolative, time-average, count, etc.)
  • Raw, processed, and read-at-time queries with end-to-end timestamp/quality fidelity
OPC AE
OPC AE Tunneling

Event and alarm tunneling.

  • Full compliance with the OPC AE specification
  • Support of alarm acknowledgement across the tunnel
  • Condition, tracking, and simple event handling with area/source browsing
  • Event filtering and condition-state refresh for a complete, accurate alarm picture
Frequently Asked Questions

It replaces DCOM with a reliable TCP-based communication layer that operates through a single configurable port, and secures the OPC traffic with data encryption and user authentication, simplifying connectivity, and improving resilience.

 Yes, OPCNet Broker is completely transparent to existing OPC applications. It acts as a proxy, allowing any OPC DA, HDA, or AE client to connect to remote servers without requiring application modifications or updates. 

OPCNet Broker ensures communication integrity through data encryption, user authentication, application whitelisting, and the Tag Security add-on, while aligning with ISA/IEC 62443 industrial cybersecurity principles. 

OPCNet Broker supports communication across firewalls, NAT devices, different domains, VPNs, and DMZ configurations. It only requires a single TCP port to be opened, simplifying firewall configuration. 

OPCNet Broker is optimized for minimal latency and high throughput, making it suitable for real-time industrial applications. 

 Most installations can be completed in under 30 minutes using the configuration wizard and the graphical configuration interface. No complex DCOM settings or registry modifications are required.

ONB (OPCNet Broker®) tunnels OPC DA, HDA and AE data without DCOM's manual configuration, fixed port ranges and 6-minute timeout, adding built-in encryption, authentication, compression and automatic reconnection. ONB establishes secure OPC communications through a single TCP port.

OPCNet Broker is used across oil & gas, petrochemical, chemical, metals & mining, pharmaceutical, food & beverage, power & utilities, water & wastewater, desalination, manufacturing, automotive, pulp & paper, and building automation sites to securely bridge OPC systems across network boundaries and enable reliable industrial data exchange.

OPC UA solves the same cross network problem natively, since it is built on TCP/IP from the ground up with no DCOM dependency. Tunneling is the practical path for organizations that need to keep existing OPC Classic (DA/HDA/AE) servers and clients running, secure the OPC traffic without a full migration to OPC UA.

Yes. OPCNet Broker secures OPC Classic communication in the interim, and Integration Objects also offers OPC UA Wrapper and OPC UA Universal Server for organizations planning a phased move to OPC UA.

Resources & Documentation

OPCNet Broker® DA HDA AE Resources

Product Datasheet

Comprehensive technical specifications and features overview

Related Blogs

See the OPC product in action with real-world examples

User Guide

Step-by-step installation and configuration guide

Whitepaper

Industrial Network Security with OPC Tunneling