Configure the run-time node firewall
- Last UpdatedJan 16, 2025
- 2 minute read
Important: The firewall rules must be added to the node to which the OPC UA Server Service is deployed.
To configure the run-time node firewall
On the run-time node(s) where the OPC UA Server Service is deployed, open the Windows firewall and configure it as follows:
-
In the Windows Search bar, open Windows Firewall.
-
Select Advanced Settings and create an Inbound Rule.

-
Select "New Rule." The Rule Wizard opens.
-
Select Program for the Rule Type and select Next.
-
Browse to the OPC UA Server location. If System Platform was installed in the default location, the path should be:
C:\Program Files (x86)\Common Files\ArchestrA\Services\OPCUAService

-
Select "ArchestrA.OPCUA.ServiceHost.exe" and then select Open.
This adds the file path to the wizard. Select Next.
-
On the Action dialog box, select the option "Allow the connection" and then select Next.
-
The wizard will ask when the rule applies.
-
For Domain environments: Select Domain and Private. We recommend that you deselect Public.
-
For Workgroup environments: Select Public. The Domain and Private settings have no affect in a Workgroup environment.

-
-
Finally, provide a name for this rule (for example, "OPC UA Server"). If you will be configuring multiple OPC UA services from Application Server, be sure to use names that differentiate each service from the others.
-
Now, check that the new rule has been added to the list of InBound Rules in the Windows Firewall and that it is enabled.

-
Verify that you can connect to the run-time node from the OPC UA client node by repeating the Firewall test.