0%

Industrial Network Security with OPC Tunneling

OPC is the backbone of multi-vendor industrial connectivity, but OPC Classic's dependence on Microsoft COM/DCOM makes remote communication difficult to configure and risky to expose. This Integration Objects whitepaper by Fulvio Roveta makes the case for OPC tunneling as the practical alternative, and describes how OPCNet Broker DA HDA AE moves process data securely through firewalls without DCOM.

The paper first establishes where DCOM stops working. Deployment is straightforward when OPC client and server sit on the same machine, and manageable on two machines inside the same process control network. The problems begin when a process control network has to reach an enterprise or business network. Security is the first category: DCOM needs many ports for host discovery, name resolution, service requests, authentication and data transfer, with Port 135 open for the initial handshake plus a dynamically allocated range above 1024, and every port and service is a target for viruses, worms and port-scanning exploit toolkits. DCOM also cannot work across Network Address Translation, and because callbacks open a new port with reversed client and server roles, a default firewall configuration will typically block them. Robustness is the second: DCOM can take up to three minutes to fail an activation request as it tries each available network protocol in turn. Set-up complexity is the third, and the paper notes that most OPC vendor support calls trace to DCOM and Windows Security configuration, which can take weeks over a WAN or with NT services.

The solution section describes a two-licence architecture with a gateway on the server side and one on the client side, acting as .NET peers communicating over .NET Remoting and redirecting COM calls to .NET and back. Clients need only the server IP address and listening port, taken from a configuration file, and bidirectional communication runs over a single port. TCP channel with a binary formatter is recommended for best performance, with security barriers set via SSPI. Capabilities covered include process control and SCADA network security down to tag level, client/server communication tracking, user authentication, data encryption, automatic reconnection, configurable timeouts, message queueing and compression.

A worked configuration shows communication between domains behind separate firewalls, and a final section addresses OPC over VSAT satellite links - security exposure, rain fade and sun outages, and how single-port operation, encryption and automatic reconnection mitigate them.

You May Also Like

The Ultimate Resource.

whitepaper
Unlocking the Full Potential of Mobile Equipment Telemetry in Mining .

This white paper provides a practical roadmap for integrating telemetry data into core business processes, covering essential factors like cross-functional collaboration, data governance, and system integration. Key applications include predictive maintenance, operator performance insights, and real-time fleet […]

Read more
Webinar
A Game Changer: Introducing AI in IT/OT integration and Industrial Cybersecurity.

Uncover how Artificial Intelligence (AI) is not just a technology but a game-changer, reshaping the dynamics of IT-OT integration and discover how AI is revolutionizing industrial cybersecurity.

Watch webinar
Blog Post
Archive OPC UA Alarms & Conditions Data using OPC Easy Archiver & OPC UA Proxy.

Do you need to collect OPC UA Alarms & Conditions data coming in from different OPC UA Servers? You can easily combine OPC Easy Archiver

Read Full Blog