Impact67 Pro 54631 Links to Ignition Over Its Own OPC UA Server

Daniel Price7 min read
OPC / OPC UAOther ManufacturerTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

The Murrelektronik Impact67 Pro module 54631 can connect to an Ignition gateway without a PLC because its data sheet lists Ethernet and an onboard OPC UA server. Ignition's built-in OPC UA client connects to that server directly. The work is mostly manual configuration: addressing, port reachability, certificate trust, and tag mapping. Treat the job as four checks along the data path. Each check has a pass or fail reading, and only the last one hands you a working tag.

Which hops carry an Ignition request to the 54631?

In a PLC-based design, the module is a fieldbus I/O device. An IO controller or scanner owns the cyclic process image, and the controller republishes that image to SCADA. With the PLC removed, the path gets shorter. Ignition acts as an OPC UA client and opens a session to the OPC UA server running in the module firmware. Ignition then reads and writes nodes acyclically at its own subscription rate.

Hop Sender Receiver What can stop the request here
1. Physical/L2 Gateway NIC Switch port / module Ethernet port No link LED, wrong port, VLAN mismatch
2. IP Gateway host Module IP stack Module has no address yet, wrong subnet, no route
3. TCP Ignition OPC UA client Module OPC UA listener Server disabled, wrong port, host firewall
4. OPC UA session Ignition client Module server endpoint Security policy mismatch, untrusted certificate, user token rejected
5. Address space Ignition tag Module node Wrong NodeId, output node read-only, no live data

Stock Ignition drivers do not act as a PROFINET IO controller or an EtherNet/IP I/O scanner. If the OPC UA server is missing or disabled on your unit, a direct connection is not possible. In that case you need a PLC or a protocol gateway in the path.

Check 1: Does the module answer on the gateway's subnet?

Test the physical layer first. You need a link LED on the module port and on the switch port. A fieldbus I/O device often does not boot with a usable IP address. A PROFINET device normally waits for its IO controller to assign a name and address through DCP. An EtherNet/IP device typically requests an address through DHCP or BOOTP. Without a PLC, nothing hands the module an address unless you assign one yourself.

  1. Read the fieldbus variant and the default addressing mode from the 54631 label and data sheet.
  2. Assign a permanent static IP in the gateway's subnet. Use the method Murrelektronik documents for the module: its web interface, a DCP tool, or its configuration software.
  3. From the Ignition host, run ping <module-ip>.
Reading Meaning Next
Replies L1 to L3 path is good Check 2
No link LED Cable, connector, or switch port problem Fix cabling, then repeat Check 1
Link up, no reply No address assigned, or a subnet or VLAN mismatch Assign or verify the IP, then check the switch VLAN

Check 2: Is the OPC UA server running and reachable on its port?

A ping reply only proves the IP stack is running. The OPC UA server is a separate firmware service and may ship disabled. Open the module's web interface or configuration tool and confirm three things: the OPC UA server is enabled, the port it listens on, and the endpoint URL it advertises. The IANA-registered OPC UA default port is 4840, but use the port the module reports. Then test TCP from the gateway host itself, not from a laptop:

# Windows gateway host
Test-NetConnection -ComputerName <module-ip> -Port <opcua-port>

# Linux gateway host
nc -zv <module-ip> <opcua-port>
Reading Meaning Next
TCP connect succeeds The listener is up and reachable Check 3
Connection refused The server is disabled or listening on another port Enable the server or correct the port in the module configuration
Timeout A firewall or ACL between the hosts is dropping the traffic Open the port on the host firewall and on any routed segment

Check 3: Why does the Ignition connection fault after endpoint discovery?

OPC UA opens a secure channel before it exchanges any data. The client and server must agree on a security policy and message mode. Each side must also trust the other's application certificate.

Discovery can succeed while the session still fails. This happens because GetEndpoints runs over an unsecured channel, and the certificate check happens later. The advertised endpoint URL can also carry a hostname the gateway cannot resolve. If so, override it with the IP address in the Ignition connection settings.

Connection status in Ignition Mechanism Action
Faulted right after discovery The module has not trusted Ignition's client certificate Move the Ignition certificate to the trusted list on the module
Faulted with a certificate error on the client side The gateway has not trusted the module's server certificate Trust the module certificate in the gateway's OPC client certificate store
Faulted with a user token error The server requires a username and password, or rejects anonymous login Enter the credentials configured on the module
Connected Session established Check 4

Security policy None removes the certificate step. It also sends every read and write in cleartext. Use it only on an isolated I/O segment, and only for commissioning.

Check 4: Do the browsed nodes carry live process data and accept writes?

A connected session only proves that the protocol works. It does not prove the tags hold live data. Browse the connection in the Ignition Designer OPC browser and locate the input, output, and diagnostic nodes the module exposes. Then take these readings:

  • Inputs: Change a physical input and watch the tag value and quality in Ignition.
  • Outputs: Write one output node from a test tag and watch the channel LED on the module.
  • Diagnostics: Pull a sensor or short a channel, and confirm the diagnostic node changes state.

Output ownership is the recurring failure point. In a fieldbus device, the cyclic connection from the IO controller normally owns the output image. With no controller present, the outputs sit in their default or substitute state. They can only change if the OPC UA server grants write access to the process image. Check the module documentation for this. If an output write returns Bad or the LED does not change, the node is read-only in this mode. Look for a configuration switch in the module that enables OPC UA output control. If there is none, a controller is required for outputs even though inputs can be read directly.

Channel and port settings normally travel in the controller's startup parameters. Without a PLC, those parameters never reach the module. Set channel modes, filters, and substitute values through the module's own interface, and store them in the module.

How do I build the connection and prove it end to end?

  1. Set a static IP on the 54631 in the gateway subnet, and confirm the address survives a power cycle.
  2. Enable the OPC UA server in the module, and record its port, endpoint URL, security policies, and authentication mode.
  3. In the Ignition gateway Config section, open OPC Connections and create a new OPC UA connection. Enter opc.tcp://<module-ip>:<opcua-port> and run endpoint discovery.
  4. Select the endpoint with the strongest security policy both sides support. Save the connection, then exchange and trust certificates on both sides.
  5. Wait for the connection status to read Connected. Browse the address space and create OPC tags for inputs, outputs, and diagnostics.
  6. Set the tag group rate to match the process. Every subscribed node adds load on the module's embedded server, so do not poll unused channels.
  7. Configure the channel parameters in the module, then store them.

Verify in this order. Toggle each wired input and confirm Good quality with the correct value. Write each output and confirm the matching LED and field device respond. Force a channel fault and confirm the diagnostic tag reports it.

Finally, remove the module's Ethernet cable for longer than the session timeout. Confirm the tags go to Bad quality, and confirm your alarms fire on that quality change. Reconnect the cable, and confirm the gateway re-establishes the session and all tags return to Good quality without a manual restart.

FAQ

What happens if a PLC is added later as the fieldbus controller for the 54631?

The controller's cyclic connection takes ownership of the output image. OPC UA writes from Ignition are then either rejected or overwritten on the next cycle. Keep Ignition read-only on the module and route any output commands through the PLC.

What happens if the module's IP address changes after a power cycle?

The Ignition OPC UA connection faults, and every tag on it drops to Bad quality. The module usually lost its address because it was set to DHCP, BOOTP, or controller-assigned addressing. Store a permanent static IP in the module and confirm it with a ping after a power cycle.

What happens if I set the OPC UA security policy to None?

The session skips certificate exchange, which makes commissioning faster. However, all reads and writes, including output commands, cross the network unencrypted and unauthenticated. Use None only on an isolated I/O segment, and switch to a signed and encrypted policy before production.

Can Ignition read an Impact67 Pro module if its OPC UA server is disabled?

Not with stock Ignition drivers. They do not act as a PROFINET IO controller or an EtherNet/IP I/O scanner. Enable the module's OPC UA server, or put a PLC or protocol gateway between the module and Ignition.

Back to blog