01先搞懂一件事:OPC 到底装在谁身上
01First Things First: Where Does OPC Actually Live?
新手最大的困惑就是“PLC 这边要怎么设置 OPC”。答案分两种情况:
The biggest beginner question is “how do I configure OPC on the PLC side?” The answer depends on which OPC you use:
情况 A —— OPC UA:现代 PLC(如西门子 S7-1200/1500 固件 V2.0 以上)自己内部就带了一个 OPC UA 服务器,你要做的只是在博途(TIA Portal)里打个勾、下载进去。PLC 本身就是服务器。
情况 B —— OPC DA:PLC 里没有 OPC DA 这个东西。OPC DA 服务器是一个装在 Windows 电脑上的软件(比如 KEPServerEX、西门子 SIMATIC NET),它通过 PLC 原本的通信协议(S7 协议、Modbus 等)去读 PLC,再把数据以 OPC DA 标准接口提供给上位机。
Case A — OPC UA: Modern PLCs (e.g. Siemens S7-1200/1500, firmware V2.0+) have an OPC UA server built in. All you do is tick a checkbox in TIA Portal and download. The PLC itself is the server.
Case B — OPC DA: There is no OPC DA inside the PLC. An OPC DA server is software installed on a Windows PC (e.g. KEPServerEX, Siemens SIMATIC NET). It reads the PLC using the PLC's native protocol (S7 protocol, Modbus, etc.) and exposes the data through the standard OPC DA interface.
记住一句话:OPC 永远遵循“服务器—客户端”模式。PLC(或电脑上的服务器软件)是服务器,负责提供数据;HMI、SCADA、报表软件是客户端,负责取数据。所有的“设置”,本质上都是围绕“把服务器开起来、把要提供的数据放进去、让客户端连上”这三件事。
Remember one rule: OPC always follows the server–client model. The PLC (or the server software on a PC) is the server that provides data; HMIs, SCADA and reporting tools are clients that consume it. All “configuration” boils down to three things: start the server, put data in it, and connect a client.
02一张图看懂 OPC 在整个系统里的位置
02Where OPC Sits in the System — at a Glance
两张图合起来看,你就明白了整个逻辑:PLC 用“母语”(各自厂家的协议)干活,OPC 服务器做“翻译”,上位软件只学“普通话”(OPC 标准接口)。这样换 PLC 品牌时,只需换翻译(服务器配置),上位软件一行代码都不用改。
Put together, the logic is clear: PLCs work in their “native language” (vendor protocols), the OPC server acts as the “translator”, and higher-level software only needs to speak the “common language” (the OPC standard interface). Switching PLC brands means only changing the translator (server configuration) — the client software needs no changes at all.
03实战一:S7-1200/1500 开启自带 OPC UA(7 步)
03Hands-on 1: Enable the Built-in OPC UA Server on S7-1200/1500 (7 Steps)
软件环境:TIA Portal V16 及以上;硬件:S7-1500(固件 V2.0+)或 S7-1200(固件 V4.4+)。这是目前最推荐的入门路线,不用买任何额外软件。
Environment: TIA Portal V16 or later; hardware: S7-1500 (firmware V2.0+) or S7-1200 (firmware V4.4+). This is the recommended beginner path — no extra software to buy.
在 CPU 属性里激活 OPC UA 服务器
Activate the OPC UA server in the CPU properties
打开设备组态,选中 CPU,在下方属性区找到 常规 → OPC UA → 服务器 → 常规,勾选 “激活 OPC UA 服务器”(Activate OPC UA server)。页面下方会自动显示服务器地址,格式是 opc.tcp://PLC的IP:4840(4840 是 OPC UA 的国际标准端口)。
Open the device configuration, select the CPU, and in the properties area go to General → OPC UA → Server → General, then tick "Activate OPC UA server". The server address appears below, in the format opc.tcp://<PLC-IP>:4840 (4840 is the standard OPC UA port).
设置安全策略(只留最安全的一项)
Configure security policies (keep only the strongest)
在 OPC UA → 服务器 → 安全 页面,有一份安全策略清单。学习调试阶段可以勾选 “No security”(无安全)让连接最省事;但正式运行时必须只保留 “Basic256Sha256 - Sign & Encrypt”(签名并加密),其余全部取消勾选。这就是 OPC UA 比 DA 安全的核心原因。
On the OPC UA → Server → Security page there is a list of security policies. During learning/debugging you may tick "No security" for the simplest connection; in production, keep only "Basic256Sha256 - Sign & Encrypt" and untick everything else. This built-in security is a core reason UA beats DA.
准备要对外提供的数据(建 DB 块)
Prepare the data to expose (create a DB)
OPC UA 对外暴露的是 PLC 里的变量。新建一个数据块(比如 DB1,取名 opc_data),在里面建好要共享的变量:开关量用 Bool、整数用 Int、模拟量用 Real、字符串用 String。注意:DB 块属性里要取消“优化的块访问”或在接口中正确映射,保证变量可被 OPC 访问。
OPC UA exposes PLC variables. Create a data block (e.g. DB1 named opc_data) and define the variables to share: Bool for digital signals, Int for integers, Real for analog values, String for text. Note: make sure the variables are accessible to OPC (check the DB's access attributes / interface mapping).
新建服务器接口(Server Interface)
Create a server interface
在项目树展开 OPC UA 通信(OPC UA communication)→ 服务器接口(Server interfaces),双击 “新增服务器接口”(Add new server interface),类型选 “Interface” 确定。这个接口就是“你想让客户端看到的数据目录”。
In the project tree, expand OPC UA communication → Server interfaces and double-click "Add new server interface"; choose type "Interface". This interface defines the data catalog visible to clients.
把变量拖进接口
Drag the variables into the interface
打开刚建的接口,右侧“OPC UA elements”窗口会列出项目数据,直接把 DB1 拖进左侧接口表格即可。拖进去之后,客户端就能看到名为 opc_data 的节点及其下所有变量。
Open the new interface. The right-hand "OPC UA elements" window lists your project data — simply drag DB1 into the interface table on the left. Clients will then see a node named opc_data with all its variables beneath it.
编译并下载到 PLC
Compile and download to the PLC
保存项目 → 编译(检查无错误)→ 下载到设备。下载完成后,PLC 的 OPC UA 服务器就开始运行了——只要 PLC 在 RUN 状态,它就在 4840 端口等待客户端连接。至此,PLC 侧的设置全部完成。
Save → compile (check for errors) → download to the device. Once downloaded, the PLC's OPC UA server is running — as long as the PLC is in RUN, it listens on port 4840 for clients. The PLC-side setup is now complete.
用 UaExpert 客户端验证(免费工具)
Verify with the UaExpert client (free tool)
在电脑上安装免费的官方测试客户端 UaExpert(Unified Automation 公司出品)。点击工具栏“+”添加服务器,在 Custom Discovery 下输入服务器地址 opc.tcp://PLC的IP:4840,展开后选中端点,认证方式与第 2 步的策略对应(调试期选 Anonymous + None),点 OK 连接。
Install the free test client UaExpert (by Unified Automation) on your PC. Click "+" in the toolbar to add a server; under Custom Discovery enter the server address opc.tcp://<PLC-IP>:4840, expand it and select the endpoint. Match the authentication to Step 2 (use Anonymous + None while debugging), then click OK.
04实战二:用 KEPServerEX 跑 OPC DA(4 步)
04Hands-on 2: OPC DA with KEPServerEX (4 Steps)
适用场景:PLC 不带 OPC UA(老 PLC、三菱、欧姆龙、国产 PLC 等),或者上位软件只支持 OPC DA。这时服务器软件装在电脑上,PLC 侧不用做任何 OPC 设置。
Use this when the PLC has no OPC UA (older PLCs, Mitsubishi, Omron, domestic Chinese PLCs, etc.) or when the client software only supports OPC DA. The server software lives on a PC; no OPC settings are needed on the PLC at all.
新建通道(Channel)——选协议
Create a Channel — pick the protocol
打开 KEPServerEX,新建通道,选择与你 PLC 匹配的驱动,比如西门子选 Siemens TCP/IP Ethernet,三菱选对应的三菱驱动,通用场景选 Modbus TCP/IP。
Open KEPServerEX, create a channel, and choose the driver matching your PLC — e.g. Siemens TCP/IP Ethernet for Siemens, the Mitsubishi driver for Mitsubishi, or Modbus TCP/IP for generic cases.
新建设备(Device)——填 PLC 地址
Create a Device — enter the PLC address
在通道下新建设备,填入 PLC 的 IP 地址、机架/槽号(西门子需要)等参数。软件此时就开始按扫描周期轮询 PLC。
Create a device under the channel, entering the PLC's IP address and rack/slot (required for Siemens). The software now starts polling the PLC on its scan cycle.
建标签(Tag)——映射 PLC 地址
Create Tags — map PLC addresses
在设备下新建静态标签:给标签起名字,并填入 PLC 内存地址(如西门子的 DB1.DBW0、三菱的 D100、Modbus 的 40001),选好数据类型。标签名会成为客户端看到的 Item ID,格式是 通道名.设备名.标签名。
Create static tags under the device: give each tag a name, enter the PLC memory address (e.g. DB1.DBW0 for Siemens, D100 for Mitsubishi, 40001 for Modbus), and pick a data type. Clients will see the tag as an Item ID in the format Channel.Device.Tag.
用自带的 OPC Quick Client 验证
Verify with the built-in OPC Quick Client
KEPServerEX 自带测试客户端 OPC Quick Client,点开就能自动列出所有标签并实时显示值、时间戳、质量。看到 Quality 显示 “Good”、数值在跳动,就说明 OPC DA 服务器已经正常对外服务了。
KEPServerEX ships with a test client, OPC Quick Client. Open it to auto-list all tags with live value, timestamp and quality. If Quality shows "Good" and values are changing, your OPC DA server is serving data correctly.
05连不上怎么办?排查清单
05Can't Connect? Troubleshooting Checklist
按从上到下的顺序排查,90% 的问题在前四条。
Check top to bottom — 90% of problems are in the first four rows.
| 现象 / 检查项 | 排查方法 | Symptom / Check | What to do |
|---|---|---|---|
| 完全连不上 | 先 ping PLC的IP,不通就查网线、IP 网段、子网掩码 |
Cannot connect at all | First ping <PLC-IP>; if it fails, check cabling, IP subnet and subnet mask |
| 能 ping 通但连不上 | 用端口测试工具(如 telnet 或 Test-NetConnection)测 4840 端口是否开放;查电脑防火墙是否放行 | Ping works, connection doesn't | Test whether port 4840 is open (telnet or Test-NetConnection); check the PC firewall |
| UaExpert 找不到服务器 | 确认 TIA 里已勾选激活、项目已下载、PLC 在 RUN 状态 | UaExpert can't find the server | Confirm the server is activated in TIA, the project was downloaded, and the PLC is in RUN |
| 报证书 / 安全错误 | 客户端与服务器安全策略必须一致;首次连接时客户端证书需在服务器侧设为“信任”(Trusted);调试期可临时用 No security 排除法定位 | Certificate / security errors | Client and server security policies must match; on first connect, the client certificate must be set to "Trusted" on the server side; temporarily use No security to isolate the issue |
| 连上了但看不到变量 | 检查变量是否已拖进服务器接口、DB 块访问属性是否正确、接口是否随项目下载 | Connected but no variables visible | Check that variables were dragged into the server interface, DB access attributes are correct, and the interface was downloaded with the project |
| 数值不刷新 / Quality 不是 Good | 质量位为 Bad 说明链路或地址有问题;检查 PLC 地址是否写错、PLC 侧该变量是否存在 | Values frozen / Quality not Good | Bad quality means a link or address problem; check the PLC address spelling and that the variable exists in the PLC |
| OPC DA 跨机连不上 | DCOM 配置问题:两台电脑的用户名密码需一致或在 DCOMCNFG 里放开权限;防火墙放行 135 端口及动态端口段 | OPC DA fails across PCs | DCOM issue: matching user accounts/passwords on both PCs or loosen permissions in DCOMCNFG; allow port 135 plus the dynamic port range in the firewall |
5.1 服务器到底起来没有?五层验证法
5.1 Is the Server Actually Up? Five-Layer Verification
从近到远逐层验证,每层排除一类问题。口诀:诊断缓冲区看"启没启",端口测试看"听没听",UaExpert 发现看"答没答",ServerStatus 看"跑没跑",读变量看"对不对"。
Verify layer by layer, from the PLC outward — each layer rules out one class of problems.
| 层 | 方法 | 通过标准 | Layer | Method | Pass criteria |
|---|---|---|---|---|---|
| ① PLC 记录 | 在线与诊断 → 诊断缓冲区,找 OPC UA 条目 | 有 "OPC UA server started" 记录;失败时会写明原因(许可证、配置无效等) | ① PLC log | Online & Diagnostics → Diagnostics buffer, look for OPC UA entries | An "OPC UA server started" entry; failures are logged with reasons (license, invalid config, etc.) |
| ② 网络端口 | PowerShell 执行 Test-NetConnection 192.168.0.10 -Port 4840 | TcpTestSucceeded : True = 服务器已在监听。"拒绝"是服务器没起,"超时"是防火墙,两者方向不同 |
② Network port | PowerShell: Test-NetConnection <PLC-IP> -Port 4840 | TcpTestSucceeded : True = server is listening. "Refused" means server down; "timed out" means firewall — different directions |
| ③ 协议应答 | UaExpert → Custom Discovery 输入 opc.tcp://PLC的IP:4840 双击刷新 | 能列出端点 = 服务器活着且协议栈正常应答,网络问题彻底排除 | ③ Protocol reply | UaExpert → Custom Discovery: enter opc.tcp://<PLC-IP>:4840 and refresh | An endpoint list appears = server alive and answering; all network issues ruled out |
| ④ 服务器心跳 | 连接后展开 Root → Objects → Server → ServerStatus → State | State = Running (0);旁边的 CurrentTime 每秒在跳。此节点是 OPC UA 标准强制要求,任何品牌服务器都有 | ④ Server heartbeat | After connecting, expand Root → Objects → Server → ServerStatus → State | State = Running (0); CurrentTime ticks every second. This node is mandatory in the UA standard — every vendor's server has it |
| ⑤ 业务变量 | 把 DB 里的变量(如 opc_var1)拖进 Data Access View | Quality = Good 且数值实时刷新 = 全链路正常,可交付。Quality 为 Bad 则回查接口与变量映射 | ⑤ Business data | Drag your DB variables (e.g. opc_var1) into the Data Access View | Quality = Good with live updates = full chain OK. Bad quality → recheck interface and variable mapping |
"状态更改为 关断 / Shutdown" → 服务器停了,查 5.2 六个原因;
"状态更改为 Starting" → 正在启动,等 1~2 分钟再验证;
"状态更改为 Running" → 服务器正常运行;
"会话状态更改为 Created / Activated" → 有客户端正在连接 / 已成功连接;
"激活最低级别安全策略 None" → 提示当前开放了无加密端点,仅可用于调试,投运前要关掉。
"Status changed to Shutdown" → server stopped; check the six causes in 5.2;
"Status changed to Starting" → server is booting; wait 1–2 minutes and verify again;
"Status changed to Running" → server running normally;
"Session status changed to Created / Activated" → a client is connecting / has connected successfully;
"Lowest security policy None activated" → an unencrypted endpoint is open; debugging only — disable before production.
5.2 勾选了激活、下载后服务器却没起来:六个常见原因
5.2 Activated but the Server Won't Start After Download: Six Common Causes
| 原因(按概率排序) | 说明与处理 | Cause (most likely first) | Explanation & fix |
|---|---|---|---|
| ① 没选运行系统许可证 | 只勾选激活不够。还需在 CPU 属性 → 运行系统许可证 → OPC UA 选择类型:小型(CPU 1511/1512/1513、ET 200SP)、中型(1515/1516)、大型(1517/1518)。不选则配置不完整,服务器起不来 |
① Runtime license type not selected | Ticking "Activate" alone is not enough. Under CPU properties → Runtime licenses → OPC UA select the type: Small (CPU 1511/1512/1513, ET 200SP), Medium (1515/1516), Large (1517/1518). Without it the configuration is incomplete and the server won't start |
| ② 下载后 PLC 没回到 RUN | 硬件下载会把 PLC 切到 STOP,下完没切回 RUN 服务器就不工作——服务器只在 RUN 状态运行 | ② PLC not back in RUN after download | A hardware download switches the PLC to STOP; if you don't switch back to RUN, the server stays off — it only runs in RUN mode |
| ③ 下载不完整 | OPC UA 服务器配置属于硬件组态的一部分。只下载程序块(软件)不会带下去。必须"编译全部 → 下载硬件和软件(完整下载)" | ③ Incomplete download | The OPC UA server configuration is part of the hardware configuration. Downloading only blocks (software) won't transfer it. Always "compile all → download hardware and software" |
| ④ 没等服务器重启完 | 对 PLC 做任何下载,OPC UA 服务器都会重启,需要几十秒。下载后等 1~2 分钟再测端口,别下完就测 | ④ Server still rebooting | Any download to the PLC reboots the OPC UA server, taking tens of seconds. Wait 1–2 minutes after download before testing the port |
| ⑤ 安全策略一项都没勾 | 安全策略清单全空时,服务器激活了也提供不了任何端点。调试期至少勾 "No security" | ⑤ No security policy ticked | With an empty policy list the activated server offers no usable endpoint. Tick at least "No security" for debugging |
| ⑥ 固件不支持 | S7-1500 需固件 V2.0+,S7-1200 需 V4.4+。在"在线与诊断 → 常规"查固件版本,太低就升级 | ⑥ Firmware too old | S7-1500 needs firmware V2.0+, S7-1200 needs V4.4+. Check under Online & Diagnostics → General; update if below |
5.3 重新激活 OPC UA 的标准流程(5 步)
5.3 Standard Procedure to Re-activate OPC UA (5 Steps)
思路:先彻底清掉旧配置,再干净地开一次。
Idea: wipe the old configuration first, then enable it cleanly.
关闭并下载(清除旧配置)
Deactivate and download (clear old config)
常规 → OPC UA → 服务器 → 常规,取消勾选 "Activate OPC UA server" → 编译 → 下载。让 PLC 清掉残留的可能损坏的服务器配置。
Under General → OPC UA → Server → General, untick "Activate OPC UA server" → compile → download. This clears any leftover, possibly corrupted server configuration from the PLC.
逐项检查后重新激活
Re-activate after checking every item
重新勾选激活,并确认三件事:运行系统许可证已按 CPU 型号选择;安全策略至少勾了一项(调试期 No security);Server addresses 里的 IP 是网线实际所插网口的地址。
Tick "Activate" again and confirm three things: the runtime license matches your CPU model; at least one security policy is ticked (No security for debugging); the IP in Server addresses belongs to the port your cable is actually plugged into.
完整编译、完整下载
Full compile, full download
编译选择"全部重建",确认 0 错误(OPC UA 相关警告也要处理);下载选择硬件和软件完整下载,不能只下程序块。
Compile with "rebuild all", confirm 0 errors (handle OPC UA-related warnings too); download hardware and software — never blocks only.
让 PLC 干净重启一次
Give the PLC a clean restart
下载完成后将 PLC 切到 STOP 再切回 RUN;更彻底的做法是断电 10 秒再送电——服务器随 PLC 启动过程初始化。
After download, switch the PLC to STOP and back to RUN; even better, power it off for 10 seconds — the server initializes during PLC startup.
等待并按五层验证法确认
Wait, then confirm with the five-layer method
等 1~2 分钟,再按 5.1 的顺序验证:诊断缓冲区 → Test-NetConnection → UaExpert 发现端点 → ServerStatus = Running → 变量 Quality = Good。
Wait 1–2 minutes, then verify per Section 5.1: diagnostics buffer → Test-NetConnection → UaExpert endpoint discovery → ServerStatus = Running → variable Quality = Good.
06OPC UA 和 OPC DA 到底怎么选
06OPC UA vs OPC DA: Which to Choose
| 对比项 | OPC DA | OPC UA | Aspect | OPC DA | OPC UA |
|---|---|---|---|---|---|
| 服务器在哪 | 只能装在 Windows 电脑上 | PLC 内置 / 电脑 / Linux / 云端都可以 | Where the server runs | Only on a Windows PC | Built into PLC / PC / Linux / cloud |
| 底层技术 | 微软 COM/DCOM | 面向服务架构,标准 TCP 端口 4840 | Underlying tech | Microsoft COM/DCOM | Service-oriented architecture, standard TCP port 4840 |
| 安全性 | 基本没有,靠 Windows 配置 | 内建证书、签名、加密 | Security | Essentially none; relies on Windows settings | Built-in certificates, signing, encryption |
| 跨电脑/跨网 | DCOM 配置繁琐,过防火墙困难 | 一个固定端口,防火墙友好 | Across PCs / networks | Tedious DCOM config, firewall-hostile | One fixed port, firewall-friendly |
| 数据形态 | 扁平标签列表 | 可浏览的地址空间,带类型和语义 | Data shape | Flat tag list | Browsable address space with types and semantics |
| 怎么选 | 仅用于维护已有的老系统 | 新项目一律选 UA | Recommendation | Only for maintaining legacy systems | Always choose UA for new projects |
07名词速查
07Glossary
- 服务器(Server)
- 提供数据的一方。UA 场景可以是 PLC 本身;DA 场景是电脑上的软件(如 KEPServerEX)。
- 客户端(Client)
- 取数据的一方:HMI、SCADA、UaExpert、MES 等。
- 标签 / 变量(Tag / Variable)
- 一个数据点,比如“电机转速”。DA 里叫 Item,UA 里叫节点(Node)。
- 质量(Quality)
- 每个数据点附带的可信度标志,Good 表示数据可信,Bad 表示链路或地址有问题。看数据时永远先看质量。
- 服务器地址 / 端点(Endpoint)
- 客户端连接用的地址,格式
opc.tcp://IP:4840,在 TIA 的 OPC UA 服务器页面可以查到。 - 安全策略(Security Policy)
- 加密算法组合。生产环境用 Basic256Sha256 - Sign & Encrypt;No security 只能用于调试。
- 证书(Certificate)
- UA 客户端和服务器的“身份证”,首次连接需互相信任。
- 地址空间(Address Space)
- UA 服务器对外展示的数据目录树,客户端可像浏览文件夹一样浏览。
- DCOM
- OPC DA 跨电脑通信依赖的微软老技术,配置繁琐——DA 被 UA 取代的主因。
- Server
- The party providing data. In UA scenarios it can be the PLC itself; in DA scenarios it is software on a PC (e.g. KEPServerEX).
- Client
- The party consuming data: HMI, SCADA, UaExpert, MES, etc.
- Tag / Variable
- A single data point, e.g. "motor speed". Called an Item in DA and a Node in UA.
- Quality
- A trust flag attached to every data point: Good means trustworthy, Bad means a link or address problem. Always check quality before trusting a value.
- Server address / Endpoint
- The address clients connect to, in the format
opc.tcp://IP:4840; found on the OPC UA server page in TIA. - Security Policy
- A named set of encryption algorithms. Use Basic256Sha256 - Sign & Encrypt in production; No security is for debugging only.
- Certificate
- The "ID card" of UA clients and servers; both sides must trust each other on first connection.
- Address Space
- The data directory tree a UA server exposes; clients browse it like folders.
- DCOM
- The legacy Microsoft technology OPC DA relies on for cross-PC communication; tedious to configure — the main reason DA was superseded by UA.