Oil & Gas
Connecting remote wellhead or pad SCADA systems back to a central historian across corporate and field networks, without opening the wide port ranges DCOM requires at every remote site.
An OPCNet Broker Server Side sits next to the OPC DA, HDA, or AE server and wraps its calls for transmission. No change to the underlying OPC server.
Wrapped calls travel across the network via the OPC tunnel using a single configurable TCP port, through firewalls, NAT, DMZs, and WAN links, encrypted and authenticated in transit.
An OPCNet Broker Client Side on the receiving OPC Client machine unwraps the calls and presents them to the local OPC client exactly as a native OPC connection would.
| Capability | DCOM | ONB: OPCNet Broker |
|---|---|---|
| Configuration | Manual DCOM configuration on every machine: security settings, user permissions, user accounts sharing | Deployed and configured in a few clicks. No DCOM configuration required |
| Firewall & Port Handling | Requires opening a wide, often dynamic range of ports, multiplying security exposure Requires opening a well known TCP port number | Single port open in the firewall, port number configurable Tracks client/server communication through a single TCP port, minimizing security holes |
| NAT, DMZ & Proxy Traversal | Not designed for NAT traversal; typically breaks across firewalls, DMZs and proxies | Navigates NAT, DMZ, firewalls and proxies natively |
| Security & Compliance | Relies on the native Windows security model. No built-in encryption | IEC 62443-aligned; built-in data encryption and user authentication |
| Call Timeout Handling | Fixed, mandatory 6-minute call timeout after a communication failure | Configurable call timeout parameters, so activities restart far faster after a glitch |
| Network Efficiency | No native data compression | Built-in data compression, reducing bandwidth costs and network strain |
| Recovery After Disruption | Manual intervention typically required after a network glitch | Automatic OPC reconnection and data recovery after communication glitches |
| Redundancy | No native redundancy management; requires custom engineering | Built-in servers redundancy management (active-active, active-passive) |
| Cross-Domain Connectivity | Difficult across domains without established trust relationships | Connects OPC components across different domains, LAN and WAN |
| Ongoing Maintenance | Prone to breaking after Windows/security updates; requires repeated DCOM tuning | Easy to deploy and maintain, via a graphical user interface |
Connecting remote wellhead or pad SCADA systems back to a central historian across corporate and field networks, without opening the wide port ranges DCOM requires at every remote site.
Bridging OPC servers between pit-level control systems and plant-level historians across segmented, often firewalled network zones.
Keeping validated, unmodified OPC Classic systems in place while satisfying cyber security policies that restrict or prohibit DCOM traffic on the network.
Linking remote treatment or pumping sites to a central SCADA/historian over WAN or VPN links where DCOM’s dynamic ports are impractical to manage.
It replaces DCOM with a reliable TCP-based communication layer that operates through a single configurable port, and secures the OPC traffic with data encryption and user authentication, simplifying connectivity, and improving resilience.
Yes, OPCNet Broker is completely transparent to existing OPC applications. It acts as a proxy, allowing any OPC DA, HDA, or AE client to connect to remote servers without requiring application modifications or updates.
OPCNet Broker ensures communication integrity through data encryption, user authentication, application whitelisting, and the Tag Security add-on, while aligning with ISA/IEC 62443 industrial cybersecurity principles.
OPCNet Broker supports communication across firewalls, NAT devices, different domains, VPNs, and DMZ configurations. It only requires a single TCP port to be opened, simplifying firewall configuration.
OPCNet Broker is optimized for minimal latency and high throughput, making it suitable for real-time industrial applications.
Most installations can be completed in under 30 minutes using the configuration wizard and the graphical configuration interface. No complex DCOM settings or registry modifications are required.
ONB (OPCNet Broker®) tunnels OPC DA, HDA and AE data without DCOM's manual configuration, fixed port ranges and 6-minute timeout, adding built-in encryption, authentication, compression and automatic reconnection. ONB establishes secure OPC communications through a single TCP port.
OPCNet Broker is used across oil & gas, petrochemical, chemical, metals & mining, pharmaceutical, food & beverage, power & utilities, water & wastewater, desalination, manufacturing, automotive, pulp & paper, and building automation sites to securely bridge OPC systems across network boundaries and enable reliable industrial data exchange.
OPC UA solves the same cross network problem natively, since it is built on TCP/IP from the ground up with no DCOM dependency. Tunneling is the practical path for organizations that need to keep existing OPC Classic (DA/HDA/AE) servers and clients running, secure the OPC traffic without a full migration to OPC UA.
Yes. OPCNet Broker secures OPC Classic communication in the interim, and Integration Objects also offers OPC UA Wrapper and OPC UA Universal Server for organizations planning a phased move to OPC UA.
Comprehensive technical specifications and features overview
See the OPC product in action with real-world examples
Step-by-step installation and configuration guide
Industrial Network Security with OPC Tunneling