How to connect an OPC UA server to UaExpert and Ignition SCADA step by step: endpoints, security policies, certificates, browsing nodes and first live tags.

To connect OPC UA clients like UaExpert and Ignition to a server, you need the same four things every time: an endpoint URL, a security policy, credentials, and a trusted certificate exchange. Get those four right and any client connects to any server; get one wrong and you stare at "BadSecurityChecksFailed" wondering which layer hates you. This tutorial walks both connections step by step — UaExpert first (the test client every integrator should own), then Ignition — using PLC-Ladder's built-in OPC UA endpoint as the worked example, since it gives you a live server with running logic in one click. The steps transfer unchanged to a Siemens S7-1500's embedded server or a Kepware gateway; only the four values differ.

If OPC UA itself is new to you — servers, nodes, subscriptions — read OPC UA for PLC Programmers first; this post is purely hands-on.

Before You Start: The Four Values

For any OPC UA connection, write these down first. For a simulation exposed from the PLC-Ladder workbench (click Expose to SCADA on a running program), they are:

What Value Where it comes from
Endpoint URL opc.tcp://opc.plcladder.com:4840 Shown when you expose the session
Security policy Basic256Sha256, message mode Sign & Encrypt The only policy the server offers — no anonymous, no unencrypted fallback
Credentials The username + password you set at expose time Your session is isolated from everyone else's
Address space Inputs, Outputs, Timers, Status folders; node IDs like ns=<idx>;s=Conveyor.Inputs.StartButton Named after your program's variables

Two server behaviours worth knowing before you connect, because they're deliberate: inputs are read/write (a client write forces the input, exactly like forcing an I/O point on a real PLC), while outputs are read-only — the server refuses the write, because outputs belong to the logic, not the HMI. Timer presets (PT) and counter presets (PV) are writable, so operator-tunable delays work the way they would on a real panel.

Part 1 — Connecting UaExpert

UaExpert (free from Unified Automation, registration required) is the reference OPC UA client — connect with it first, always, even when Ignition is the real goal, because it isolates server problems from SCADA problems.

1. First launch. UaExpert generates its own application certificate on first run — accept the defaults. This is the client's identity in the certificate exchange.

2. Add the server. Click the + (Add Server) button → Custom Discovery → < Double click to Add Server... > → enter the endpoint URL: opc.tcp://opc.plcladder.com:4840. UaExpert queries the server and lists the endpoints it offers.

3. Pick the right endpoint. Expand the discovered server and you'll see its endpoint(s) with their security policies. Select Basic256Sha256 — Sign & Encrypt. (On servers that also offer None, resist it outside the lab; here you won't get the choice.)

4. Enter credentials. In the server settings, under Authentication, choose Username / Password and enter the ones you set at expose time. Click OK.

5. Connect and trust. Hit the Connect plug icon. UaExpert shows the server's certificate and asks whether to trust it — inspect it, then Trust Server Certificate and continue. This dialog is the certificate half of every OPC UA setup; wherever you see a connection fail silently on another server, an untrusted certificate on one side or the other is the first suspect.

6. Browse and subscribe. The Address Space panel (left) now shows your program's tree: open Inputs, Outputs, Timers. Drag a few nodes into the Data Access View — values appear with timestamps and quality, updating live as the simulation scans. Toggle an input in the workbench and watch UaExpert's value flip within the sampling interval.

7. Prove the write rules. Double-click an input's Value cell, set it true — the input forces, and your ladder rung responds. Now try the same on an output: the server refuses (you'll get a Bad_ status such as access-denied). That refusal is the correct behaviour, and seeing it once in UaExpert saves a confused support ticket later when an Ignition tag "won't write."

That's a complete, verified connection. Keep UaExpert open as your second opinion whenever SCADA behaves oddly.

Part 2 — Connecting Ignition

Ignition's OPC UA client lives in the Gateway, not the Designer — tags come later.

1. Open the Gateway web page (usually http://localhost:8088) → Config → under OPC Client, OPC Connections → Create new OPC Connection → type OPC UA Connection.

2. Endpoint and discovery. Enter opc.tcp://opc.plcladder.com:4840 and let Ignition discover the endpoints. Select the Basic256Sha256 / Sign & Encrypt endpoint, same as UaExpert.

3. Name and credentials. Give the connection a name like PLCLadder, and under authentication enter the session username and password.

4. Certificates. Save the connection. If its status shows Faulted with a certificate/trust error, that's the same trust step UaExpert surfaced as a dialog: open the certificate management page for OPC UA client connections in the Gateway (menu location varies slightly by Ignition version — look for quarantined/rejected certificates), mark the server's certificate as trusted, and the connection flips to Connected within a few seconds. One free-plan note: the session allows one exposed connection at a time, so disconnect UaExpert before Ignition connects, or the second client will be refused — that's the session limit, not a fault.

5. Browse into tags. Open the Designer → Tag Browser → the OPC browser icon → your PLCLadder connection → the same Inputs / Outputs / Timers tree appears. Drag the nodes you need into your tag folder; they become Ignition tags with live values and quality.

6. Build the screen. Drop a Perspective (or Vision) toggle on a view, bind it to an input tag; bind an LED/label to an output tag. Press the toggle: the write forces the input, the simulated logic runs, the output changes, Ignition shows it — your operator screen is now driving compiler-checked logic, before any physical PLC exists. This is the honest pitch of simulation-backed OPC UA: HMI development and logic development stop waiting for each other.

7. One behaviour to remember: if you later edit the program in the workbench, the endpoint reloads the new logic but node IDs stay the same, so your Ignition tags keep working — add tags for new variables, but don't rebuild the tree.

Troubleshooting: The Five Usual Suspects

  1. BadSecurityChecksFailed / connection drops at handshake → wrong security policy selected, or a certificate not yet trusted on one side. Re-pick Basic256Sha256 Sign & Encrypt and check both trust stores.
  2. BadUserAccessDenied on connect → credentials. There is no anonymous fallback here, by design.
  3. Second client refused → the one-session limit (free plan). Disconnect the other client.
  4. Write fails on an output tag → correct behaviour; outputs are read-only. Force the input that drives it instead.
  5. No route / timeout → port 4840 outbound blocked by a corporate firewall; test from another network to confirm, then ask IT for the port.

The habit to take away generalizes to every server you'll ever commission: UaExpert first, four values written down, certificates trusted deliberately, writes tested against access rights before the SCADA screens are built. Next in this series, the wider picture of what PLCs and SCADA exchange and over which protocols — and if you haven't yet, expose one of the FBD example circuits and watch Ignition drive a flasher you built in two minutes.