OPC UA

Plan OPC UA server, client, and security designs to support reliable data exchange and maintainable integrations.

Scope and planning

Define the required data, clients, access needs, and security requirements before configuring an OPC UA connection.
Publish, import, and synchronize only the nodes that support the application. Limiting the node scope reduces system load and simplifies maintenance.
Plan endpoint, node identifier, certificate, and network designs together. A consistent design supports reliable connections and integration changes.

Commissioning readiness

When commissioning a secure OPC UA connection, system integrators can confirm that the client and server meet these readiness conditions.
  • The client can reach the server endpoint. For network access guidance, see Configure the firewall for an OPC UA server.
  • The server publishes and the client imports the nodes that the application requires.
  • The client and server use aligned security modes and policies.
  • A trusted certificate and key pairs support the connection.
  • The connection status confirms the connection.

Capacity and data flow

Base sampling, publishing, connection, and subscription settings on expected workload and data criticality.
Balance responsiveness, network traffic, and server load. Monitor connection status and revise the design when workload changes.

Related guidance

For server address space, capacity, and endpoint security guidance, see OPC UA server best practices.
For client connections, data monitoring, and node scope guidance, see OPC UA client best practices.
For certificate, identity, and security guidance, see OPC UA security and certificates.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal