Which request is the gateway refusing, and at which hop?
The message Insufficient privileges to view this page is not a network fault. The browser reached the gateway's web server, and the gateway checked your credentials against its system user source. The login either succeeded with an account that lacks the configuration role, or the session reached a protected page without that role. A wrong password produces a login failure. This message means authentication completed and the role check refused you.
After a gateway backup is restored onto a new PC, the new machine uses the laptop's users, roles, and passwords. A later reinstall can replace or keep that configuration depending on how the install was done. Either way, the credentials you type may no longer match the account that holds the admin role. The fix for the login is to reset the gateway password through the Gateway Control Utility and log in with admin / password.
The missing tags in the Designer are a separate problem on a separate path. Follow the packet for each:
| Path | Hops | Where it stops in this failure |
|---|---|---|
| Gateway web login | Browser → gateway web server → system user source → role check | Role check (privileges error) |
| Designer tag browse | Designer → gateway → tag provider | Tag provider empty or inaccessible |
| Tag value | Tag → OPC UA connection → OPC UA server → Allen-Bradley driver → NIC → Ethernet → PLC | OPC UA connection faulted, or PLC unreachable from the new PC |
Check 1: Can any account open the gateway Configure section?
Take the reading at the gateway web page, from the new PC itself. Using the local machine removes firewall and IP questions from the first test.
| Reading | Meaning | Next step |
|---|---|---|
| Login rejected as invalid | Credentials do not exist in the active user source | Reset the password (resolving procedure, step 1) |
Login accepted, then Insufficient privileges to view this page
|
The account exists but lacks the gateway configuration role | Reset the password (resolving procedure, step 1) |
| Laptop's original admin credentials work | The restored user source is intact | Go to Check 2 |
| Gateway page does not load at all | Gateway service stopped, or port blocked | Start the service from the Gateway Control Utility, then repeat Check 1 |
The Designer authenticates against the same user source and applies its own role requirement. An account that cannot configure the gateway often cannot open projects or browse tags either. Clear this branch before you judge anything the Designer shows.
Check 2: What did the backup actually carry to the new PC?
The transfer method decides what exists on the new gateway. A project export from the Designer and a full gateway backup are different payloads.
| Item | Gateway backup (Gateway Control Utility or gateway web page) | Project export (Designer) |
|---|---|---|
| Projects (windows, scripts) | Yes | Yes |
| Users, roles, user sources | Yes | No |
| Device connections (Allen-Bradley driver, PLC IP) | Yes | No |
| OPC UA connections | Yes | No |
| Tag providers and tags | Yes | Check your version; tags may need a separate export |
| License activation | No, it is bound to the machine | No |
If only a project export moved, the Designer shows no tags because the new gateway has no device and no tag definitions. Re-take a full gateway backup from the laptop and restore it. If a full backup was restored and then Ignition was reinstalled, open the gateway's project list. An empty list means the reinstall wiped the restore, and you need to restore again after the password reset. Restore onto the same or a newer Ignition version than the laptop ran. A backup from a newer gateway will not restore onto an older install.
Check 3: Can the new PC reach the PLC at layer one and layer three?
Check layer one first. An OPC UA connection or device fault on a machine that was just moved is most often a cabling or addressing problem.
- Confirm link LEDs on the PC NIC and the switch port that faces the PLC network.
- Read the NIC's IP and subnet mask. The address must sit in the PLC's subnet, or a route to it must exist.
- Ping the PLC IP that is configured in the gateway's Allen-Bradley device connection. That IP came across in the backup and still points to the laptop's plant network.
- Read the device status on the gateway's device connections page.
| Ping result | Device status | Meaning | Next step |
|---|---|---|---|
| No reply | Not connected | Physical, addressing, or firewall fault | Fix the NIC address or cabling, then repeat the ping |
| Reply | Not connected | Wrong PLC IP or slot in the device settings, or the wrong driver type | Correct the device settings against the PLC's actual address |
| Reply | Connected | The driver side is healthy | Go to Check 4 |
A desktop PC that is staged in the office before it ships to site will never connect to the PLC. That is expected, and it is not a configuration fault. Verify the device connection only once the PC sits on the PLC network.
Check 4: Why is the OPC UA connection in a faulted state?
Tags do not read the driver directly. They read through an OPC UA client connection to the gateway's own OPC UA server. The Allen-Bradley driver runs behind that server. If that loopback connection faults, every OPC tag goes bad even when the PLC answers pings.
| Cause | What to read | Correction |
|---|---|---|
| Endpoint URL references the laptop's hostname or IP | The endpoint field in the OPC UA connection settings | Point it to the local host on the new PC |
| Connection authenticates with a gateway username/password that changed or no longer exists | The authentication fields in the OPC UA connection settings | Enter credentials that are valid on the new gateway |
| Server certificate is not trusted on the new machine | The gateway's OPC UA certificate/security pages | Trust the certificate, then reconnect |
| OPC UA server module is missing or not running | The Modules page | Install or restart the module |
| Gateway is unlicensed or in trial mode | The Licensing page | Activate the license on the new PC, or reset the trial |
A password reset can break a loopback connection that authenticates with gateway credentials. Recheck this connection after every credential change.
Resolving branch: how do I recover access and restore tag quality?
- On the new PC, open the Gateway Control Utility and run its password reset function. Restart the gateway service if the utility prompts you to.
- Browse to the gateway on the local machine and log in with
admin/password. - Change the admin password immediately, and record it where site staff can find it.
- Open the project list. If it is empty or incomplete, restore the full gateway backup that you took from the laptop. The restore replaces users, so repeat steps 1–3 if the laptop credentials are unknown.
- Activate the license on the new PC.
- Edit the Allen-Bradley device connection so the PLC IP and path match the site PLC.
- Edit the OPC UA connection. Set a local endpoint, set valid credentials, and trust the certificate if the gateway prompts for it.
- Launch the Designer, log in as admin, and open the project.
Verification: Confirm that the OPC UA connection status reads Connected and that the device status reads Connected on the gateway status pages. Then open the Tag Browser in the Designer and expand the tag provider. Pick a tag whose PLC value you can change, such as a spare integer. Write a new value from the PLC programming software and confirm that the tag updates with Good quality in the Designer.
FAQ
Does resetting the Ignition gateway password delete my projects or tags?
No. The Gateway Control Utility password reset only restores the admin / password login. Projects, devices, and tags stay in place. Afterwards, recheck any OPC UA connection that authenticates with gateway credentials.
Can I restore an Ignition gateway backup onto a different PC?
Yes. A full gateway backup carries projects, users, devices, and OPC UA connections to the new machine. Install the same or a newer Ignition version, re-activate the license on the new PC, and update the PLC IP and OPC UA endpoint afterwards.
Does a Designer project export include device connections and users?
No. A project export carries project resources only. Device connections, OPC UA connections, and users travel only in a full gateway backup, so a project-only transfer leaves the Designer with no tags.
Can the OPC UA connection fault even though I can ping the PLC?
Yes. Tags read through a loopback OPC UA connection to the gateway's own server. A stale endpoint hostname, changed credentials, an untrusted certificate, or a stopped module will fault the connection while the PLC still answers pings.
How do I confirm the moved gateway is really reading the PLC?
Check that both the device status and the OPC UA connection status read Connected. Then change a spare PLC value and confirm that the matching tag in the Designer Tag Browser updates with Good quality.