OPC UA
Plan OPC UA server, client, and security designs to support reliable data
exchange and maintainable integrations.
Scope and planning
Define the required data, clients, access needs, and security requirements before configuring an OPC UA connection.
Publish, import, and synchronize only the nodes that support the application.
Limiting the node scope reduces system load and simplifies maintenance.
Plan endpoint, node identifier, certificate, and network designs together. A consistent design supports reliable connections and integration changes.
Commissioning readiness
When commissioning a secure OPC UA connection, system integrators can confirm that the client and server meet these readiness conditions.
- The client can reach the server endpoint. For network access guidance, see Configure the firewall for an OPC UA server.
- The server publishes and the client imports the nodes that the application requires.
- The client and server use aligned security modes and policies.
- A trusted certificate and key pairs support the connection.
- The connection status confirms the connection.
Capacity and data flow
Base sampling, publishing, connection, and subscription settings on expected workload and data criticality.
Balance responsiveness, network traffic, and server load. Monitor connection status and revise the design when workload changes.
Related guidance
For server address space, capacity, and endpoint security guidance, see OPC UA server best practices.
For client connections, data monitoring, and node scope guidance, see OPC UA client best practices.
For certificate, identity, and security guidance, see OPC UA security and certificates.
Provide Feedback