Device properties

Use device properties to define the device information, security, and network settings for a device.
Device properties defined using the electronic data sheet (EDS) for the device cannot be modified. A device can have one or more ports that are added to the policy model.
Some properties may be read-only for:
  • The devices added to the Onboarding Area by Automatic Policy Deployment.
  • The devices that are not added to a secure zone.

Device

The settings that provide the identification parameters of the device.
General
Property
Description
Device Name
The name of the device. The name is required and must be unique.
Generic devices are automatically named
Device
<number>
. Devices selected by catalog number or discovered are already named.
Description
An optional description for the device.
The description of generic devices is empty by default. Devices selected by catalog number or discovered may have an existing description.
Catalog number
If defined using device discovery, the catalog number cannot be changed. Otherwise, choose a catalog number from the list. Choosing a
Rockwell Automation
catalog number automatically completes the Vendor information.
A device without a catalog number is listed as a
Generic Device
.
Vendor
The name of the device's vendor.
If a
Rockwell Automation
/
Allen-Bradley
catalog number was provided, this setting is completed by default and cannot be modified.
Firmware Revision
The firmware revision number of a device.
Required to enable
CIP Security
for a device.
This setting is required to apply
CIP Security
settings to the device ports.
FactoryTalk Policy Manager
automatically assigns the latest firmware revision to devices added using a catalog number or using
Discovery
.
CIP Security capable
Identifies whether a device can use the security settings of the zone.
Select to configure additional
CIP Security
settings for a generic device.
The Catalog Number and firmware revision determine the
CIP Security
capability of a device automatically.
This functionality applies only to NFC-capable devices.
NFC
Property
Description
NFC Settings
Disabled
Do not allow devices that are not in the security policy model to read from or write to the device through NFC.
Read-only
Allow devices that are not in the security policy model to read from the device through NFC.
Read and write
Allow devices that are not in the security policy model to read from or write to the device through NFC.
TIP: If you change NFC settings, an asterisk displays. To apply NFC settings, deploy the security policy model. For more information, see Configure NFC.
USB
Property
Description
Disable CIP Bridging through USB
When selected, it disables inbound and outbound CIP Bridging through the USB port.
When cleared, it enables inbound traffic through the USB port. Outbound traffic is enabled if the device supports it.
This setting is only available for the devices with the
Capable
property enabled. The available options may be restricted by
FactoryTalk Policy Manager
Settings.
This property is read-only for redundant pairs. See Redundancy system.
These settings identify the ports available on the device.
Ports
Property
Description
Port name and number
The name and number of ports available on the device.
Select
Properties
next to the port number to configure port properties, such as the port name, description, EtherNet driver, IP address, and protocols used by the device.
For more information, see Port properties.
TIP: For generic devices, you can manually add ports as needed by selecting
+
next to
Ports
.
IMPORTANT:
These devices may operate in dual mode:
  • CompactLogix
    5380 Controllers
  • Compact GuardLogix
    5380 Controllers
  • ControlLogix®
    5590 Controllers
If a device operates in dual mode, two ports may display in different subnets. Do not add both device ports to the security policy model because
FactoryTalk Policy Manager
does not support this configuration. Add only one device port to the security policy model.

Mobile connectivity

Item
Description
Set PSK
Set a Pre-Shared Key (PSK) and PSK ID for mobile connectivity to manage supported devices through the
mobile application
. See Set PSK for mobile connectivity.
Reset PSK
Reset PSK and PSK ID for supported devices configured for mobile connectivity. See Reset PSK for mobile connectivity.
Properties
Edit Properties
Rename PSK ID for supported devices configured for mobile connectivity. See Rename PSK ID for mobile connectivity.
Delete
Delete PSK and PSK ID from supported devices configured for mobile connectivity. See Delete PSK and PSK ID from a device.

UA Client

Client configuration
Item
Description
Name
OPC UA
client name.
The default
UA Client
tab title changes if you change the
OPC UA
client name.
IP Address
IP address of the
OPC UA
client.
Client credentials
Item
Description
Username
The user name to log on to the
OPC UA
client.
Password
The password to log on to the
OPC UA
client. Applicable only for
Rockwell Automation®
devices with
OPC UA
support.
Set
Set
OPC UA
client credentials. Displays only when
OPC UA
client credentials are not set.
Reset
Reset
OPC UA
client credentials. Displays only when
OPC UA
client credentials are set.
Show Password
Shows the password.
TIP:
OPC UA
client shares its identity with the
OPC UA
server identity. The identity includes the PKI certificate, username, and password.
Client identity certificate
Item
Description
Import file
Imports the
OPC UA
client certificate or Certificate Signing Request (CSR) from a file. Displays only when no certificate is imported.
Export certificate
Exports client certificate to a file. Displays only when a certificate or CSR is imported. Displays only for third-party devices with
OPC UA
support.
Delete imported file
Deletes the imported client certificate or CSR. Displays only when a certificate or CSR is imported.
Policies
Item
Description
Zone
The zone that the
OPC UA
client is assigned to.
Certificate Regeneration Time of Zone CA
Shows when the zone Certificate Authority (CA) regenerated the certificate.

UA Server

Server configuration
Item
Description
Name
OPC UA
server name.
The default
UA Server
tab title changes if you change the
OPC UA
server name.
Server URI
Non-editable
OPC UA
server URI based on the
OPC UA
server certificate.
Discovery Service URL
The URL of the
OPC UA
server discovery service, which exposes a list of
OPC UA
endpoints.
Endpoint URL for Policy Deployment
List of endpoints with the Sign & Encrypt security policy mode or stricter to use for deployment.
Select
Refresh list
to refresh the endpoints list.
For more information, see OPC UA security policy.
Endpoint Security Policy (Encryption for Policy Deployment)
Encryption algorithm for the
OPC UA
server endpoint to use for deployment.
None
Use no encryption for server endpoint deployment.
Aes256
Use the Aes256-Sha256-RsaPss encryption algorithm for server endpoint deployment.
The encryption algorithm may change if you specify a different endpoint in
Endpoint URL for Policy Deployment
.
Endpoint Security Mode
Message security mode and level based on
Endpoint Security Policy
.
Server credentials
Item
Description
Anonymous
Log on as an anonymous user to the
OPC UA
server. Only supported with
Rockwell Automation
devices.
Username
The user name to log on to the
OPC UA
server.
Password
The password to log on to the
OPC UA
server.
Set
Set
OPC UA
server credentials. Displays only when
OPC UA
server credentials are not set.
Reset
Reset
OPC UA
server credentials. Displays only when
OPC UA
server credentials are set.
Show Password
Shows the password.
TIP:
OPC UA
server shares its identity with the
OPC UA
client identity. The identity includes the PKI certificate, username, and password.
Server identity certificate
Item
Description
Import file
Imports the
OPC UA
server certificate or Certificate Signing Request (CSR) from a file. Displays only when no certificate is imported.
Export certificate
Exports server certificate to a file. Displays only when a certificate or CSR is imported.
Delete imported file
Deletes the imported server certificate or CSR. Displays only when a certificate or CSR is imported.
Verify server connection
Verifies connection to the
OPC UA
server.
Policies
Item
Description
Zone
The zone that the
OPC UA
server is assigned to.
Certificate Regeneration Time of Zone CA
Shows when the zone Certificate Authority (CA) regenerated the certificate.
Item
Description
Sharing identity with the client
OPC UA
server shares its identity with the
OPC UA
client identity. The identity includes the PKI certificate, username, and password.

Gateway

Item
Description
Refresh List
Refreshes the list of nodes associated with the gateway.
Properties
Properties
Opens node properties. See Node.
Replace device
Replaces the node device. See Replace a device.
Reset device configuration to factory defaults
Resets node device configuration to factory defaults. See Reset a node.

Node

Item
Description
Back to Policy Gateway
Opens properties of the associated gateway. See Gateway.
Device
Item
Description
Device Name
Device name of the gateway that the node is connected to.
Select
Properties
Properties
to edit gateway properties. See Gateway.
Product Name
Product name of the gateway that the node is connected to.
Product code
Product code of the gateway that the node is connected to.
General
Item
Description
Port Name
Node port name.
Description
Node description.
IP Address
Node IP address.
Policies
Item
Description
Zone
The zone of the associated gateway.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal