Welcome to the 8th tutorial on our series Mastering Forge.
Our previous article, Mastering Forge #7, provided a guide to log data to different databases.
In this article, we will look at Forge’s reverse connection capabilities. A reverse connection is a feature that allows us to change the order in which the connection is established. They are a great way to avoid complex firewall rules and keep the network safe. This tutorial contains two parts:
- The reverse connection between Forge and an OPC UA server.
- The reverse connection between Forge and an OPC UA client.
If you prefer your tutorials in video format instead, you can watch our video on creating reverse connections on YouTube.
During this tutorial, we’ll be using the following products:
- Prosys OPC UA Forge
- You can download an evaluation version through the request form.
- Prosys OPC UA Simulation Server
- You can download the free version through the product’s request form.
- Prosys OPC UA Browser
- You can download the free version through the product’s request form.
Reverse Connect Forge to a Data Source
To follow this tutorial, create a reverse connection endpoint on Prosys OPC UA Simulation Server.
In this scenario, we want to connect Forge to a data source. In this situation, the connection from Forge to the data source is blocked by a firewall. However, the connection can still be established without touching the firewall settings by configuring a reverse connection address to the data source, bound to Forge’s address and an available TCP/IP port. Then, we configure Forge to listen to that port, and the connection will be ready.
data:image/s3,"s3://crabby-images/3775a/3775ad6e551843effce5c1cc4e67b496728dd7a4" alt="1-explain-figures-reverse-forge-client - Prosys OPC Illustrative figure of reverse connection from Forge to OPC UA server. The standard connection from Forge to OPC UA server is blocked by OPC UA server's firewall, and the reverse connection from OPC UA server to Forge is complete."
1. If you haven’t already, set up Simulation Server to have one reverse endpoint configured and restart it.
data:image/s3,"s3://crabby-images/e6a89/e6a899937a0dfcd66b75296a2f4e18a17b57d599" alt="2 configure-simulation-server - Prosys OPC Screenshot of simulation server UI from the endpoints tab. Reverse connection dialog is open and one reverse address is configured, opc.tcp://10.50.100.248:5555."
2. Navigate to Data Sources > OPC UA Servers and delete the connection to Simulation Server if you have one. We are going to change that connection to a reverse connection.
NOTE: Removing a Data Source will remove all the configurations and mappings related to that Data Source.
data:image/s3,"s3://crabby-images/555c7/555c72e84e9a5f3525798618846877d53fea653b" alt="3 delete-connection-to-simulation-server - Prosys OPC Screenshot of Forge where navigation to OPC UA connections is shown with pink arrows. The first arrow goes to Data Sources, the second to OPC UA Servers. Third arrow shows the remove icon of simulation server connection."
3. Press + Add Reverse Connection.
data:image/s3,"s3://crabby-images/a9d65/a9d6567d58dee8ca6b8ea3f2cf03e24c0aa53929" alt="4 open-reverse-form - Prosys OPC Screenshot of Forge where a pink arrow is pointing to button with text "add reverse connection"."
4. Configure the form:
- Use the IP address configured on Simulation Server. (should be the IP of the SimulationServer machine).
- Configure the port set in the data source’s reverse configurations.
- Select security and authentication. Make sure they are supported on the server.
- Save the form by pressing Add.
data:image/s3,"s3://crabby-images/1ba37/1ba37a2c2421b40a7bc1856bc8c8b9c3b6cea809" alt="5 reverse-connection-form - Prosys OPC Screenshot of a filled Reverse connection form."
5. Trust certificates from both ends to make the connection work (see previous article on managing certificates in Forge).
data:image/s3,"s3://crabby-images/3c286/3c286456432932dfae399237c54b1566123f0645" alt="6 trust-certificates - Prosys OPC Screenshot of Forge from certificates view. Simulation Server's certificate is in trusted certificates list."
data:image/s3,"s3://crabby-images/c5e33/c5e335743383e12806d87c004590797f93927fe1" alt="7 trust-certificate-simulation-server - Prosys OPC Screenshot of Simulation Server's Certificates tab. Forge's certificate is shown as trusted certificate."
6. When both ends trust, the connection will be established.
Reverse Connect Forge to an OPC UA Client
In this scenario, Forge is in a high-security zone, and firewalls block connections. Still, we want to connect to Forge with an OPC UA client. To avoid the firewall, we can configure Forge to create a reverse connection to the client.
data:image/s3,"s3://crabby-images/6a882/6a882e803384d6e73a981c85b3b370a3fd14baba" alt="8-explain-figures-reverse-forge-server - Prosys OPC Illustrative figure of reverse connection from Forge to OPC UA client. The connection from OPC UA client to Forge is blocked by Forge's firewall, and the connection from Forge to the OPC UA client is complete."
1. Navigate to OPC UA Server > Reverse Connections and press + Add Connection.
data:image/s3,"s3://crabby-images/d2abf/d2abf741caaa5b44262d6f23d1db23dd6ba6ead4" alt="9 add-reverse-connection - Prosys OPC Screenshot of Forge. Pink arrows shows the navigation to add new reverse connection. The first pink arrow points to OPC UA Server, the second arrow points to Reverse Connections and the third to button with text Add connection."
2. Configure the endpoint with client details.
- IP address of the OPC UA client
- Port number that is dedicated to this connection in the client machine.
- Press Save.
data:image/s3,"s3://crabby-images/3c53d/3c53d194a7403a2b6f61dfeff848757810e69fc3" alt="10 reverse-connection-form - Prosys OPC Screenshot of Forge's Reverse connection form. Endpoint URL is set to be opc.tcp://10.50.100.248:55557."
3. Open OPC UA Browser and write inv+<configured-endpoint> to the connection address bar.
data:image/s3,"s3://crabby-images/4239e/4239e146831abbee9d2004060bc8fbe64f2125bc" alt="12 connection-with-browser - Prosys OPC Screenshot of Prosys OPC UA Browser. To the connection address is written inv+opc.tcp://10.50.100.248:55557."
4. Configure the connection settings before connecting. Use these buttons to change the security mode and authentication.
data:image/s3,"s3://crabby-images/a3697/a36979904c857b8a29cc1ff51588953aa3c10933" alt="13 change-connection-settings - Prosys OPC Screenshot of Prosys OPC UA Browser. The three icons next to connection address are highlighted with three arrows pointing at them. The first icon is connect icon, the second icon is security settings icon and the third icon is user settings icon."
5. Uncheck the option Show only modes that are supported by the server and select an option supported by Forge.
data:image/s3,"s3://crabby-images/48568/48568eb025a2944c718dc8b42bd18d0bc4f89bd6" alt="14 security-mode-selection - Prosys OPC Screenshot of Security settings. A pink arrow is pointing to checkbox with description "Show only modes that are supported by the server." Security mode Sign&Encrypt is selected and Security policy is Aes128Sha256RsaOaep."
6. The same goes for the authentication settings. With the correct settings, you can establish the connection now.
data:image/s3,"s3://crabby-images/32b24/32b244e678e6f121a2bde9abc87e1b7d4ffb0aff" alt="15 authentication-mode - Prosys OPC Screenshot of User authentication. A arrow is pointing to checkbox with description "Show only User Authentication modes that are supported by the server." Username and Password is selected and user credentials."
7. The connection will be established, and it works similarly to a standard client-server connection. You can browse the Address Space on the left as you usually do.
data:image/s3,"s3://crabby-images/9f22b/9f22b96c67d3ae6701192056efd465c12b8ee56e" alt="16 reverse-connection-established - Prosys OPC Screenshot of Prosys OPC UA Browser which is connected to Forge and the Address space is visible."
Next Steps
This wraps up the article #8 of our Mastering Forge series. Here’s a recap of what we did:
- We connected Forge to Simulation Server using a reverse connection.
- We configured a reverse endpoint in Forge and successfully connected to it using Browser.
Stay tuned for our next tutorial, Mastering Forge #9, where we demonstrate the use of Forge’s Event Generator. You can use it to create event-based messages for batches and other acyclic processes.
To learn more about Forge and its capabilities, you can request a detailed introduction by emailing sales@prosysopc.com or using our contact form. We’d be delighted to provide tailored information about Forge that aligns with your interests and requirements.
Author Info
data:image/s3,"s3://crabby-images/7d7da/7d7daab9ad0e0928d26468714ec0e9a5ccf2bcb7" alt="ProsysOPC-support-Iivo-yrjola - Prosys OPC A headshot of Iivo Yrjölä"
Iivo Yrjölä
Customer Integration & Support, Prosys OPC
Email: iivo.yrjola@prosysopc.com