GreatLight CNC Machining Factory logo
CNC Machining
Rapid Prototyping
Materials
Industries
News
About GL

Get Instant Quote

Industrial Networking Guide

Monitoring of Equipment Data: Managing Communication Between Network Segments

Cell networks, OT VLANs and the IT backbone rarely share one cable, yet the monitoring of equipment data has to cross all three. This guide shows machine builders and plant engineers how to segment, route and verify that traffic without exposing a CNC control to the wrong subnet. Read the five steps, then check the readiness table before you touch a switch config.

Cell VLAN designOPC UA routingMTConnect agentsEdge buffering
CNC Machine Monitoring Guide for monitoring of equipment data across network segments
Quick answer

Key takeaways

Segment by function, not by vendorOne VLAN per machine cell keeps broadcast traffic out of the monitoring path.
Route, do not bridgeA Layer 3 hop between OT and IT stops a flat network from turning one fault into a plant-wide outage.
Push data, pull statusMachines push process values to an edge node; the MES pulls status on its own schedule.
Buffer at the edgeA local store of 24–72 hours of tag history covers a dropped uplink without losing data.
Why segments exist

Why the monitoring of equipment data crosses segment boundaries

A CNC control talks to its servo drives over a deterministic fieldbus. The MES that wants cycle counts, spindle load and alarm codes sits on a different subnet, usually on a different floor. Between them are at least two boundaries: the machine cell and the plant OT backbone. The monitoring of equipment data has to cross both without letting the fieldbus timing degrade.

Most plants start flat. Every machine, HMI, camera and office PC shares one broadcast domain. That works at 20 nodes. At 200 nodes the broadcast traffic from a single misconfigured device can stall the polling loop, and a technician with a laptop on the wrong address can reach a spindle drive. Segmentation is not a security project bolted on later; it is what keeps the data path predictable.

The practical goal is narrow. Keep real-time control traffic inside the cell. Move only the tags the monitoring layer needs across the boundary. Give each boundary a device that can log, filter and buffer, so a lost uplink delays data instead of losing it.

  • 1
    Control stays localFieldbus and safety traffic never leaves the cell switch.
  • 2
    Monitoring traffic is one-way by defaultEdge node reads from the cell, writes only to the historian.
Protocols

Choosing the protocol that fits each segment hop

Inside the cell, most controls expose data over Modbus TCP, PROFINET, EtherNet/IP or a vendor SDK. These are fast and simple but they assume a trusted network. Do not route them across the plant backbone. Terminate them at an edge node that sits on the cell VLAN.

On the edge node, convert to a monitoring protocol. OPC UA with a subscription model is the usual choice for multi-vendor plants because it carries data types and timestamps. MTConnect suits shops that mostly run CNC machines and want a read-only HTTP stream. MQTT fits sites with intermittent links, since it tolerates reconnects better than a persistent session.

The rule is one conversion per boundary. If you bridge Modbus TCP straight to the IT VLAN, every historian poll hits the control. If you convert once at the edge, the control sees one client and the historian sees one server. That single change cuts control CPU load and makes firewall rules readable.

  • 1
    Fieldbus inside the cellModbus TCP, PROFINET, EtherNet/IP stay on the cell VLAN.
  • 2
    OPC UA or MTConnect across the boundaryOne conversion at the edge node, not at the control.
  • 3
    MQTT for unstable linksSet keepalive 30–60 s and a clean session flag.
Addressing and timing

Addressing, polling rates and the numbers that matter

Poll interval is the first number to fix. Cycle counts and machine state are fine at 1–5 s. Spindle load trends want 100–500 ms. Vibration or tool-wear signals may need 10–20 ms, and those should stay inside the cell because a routed path adds jitter you cannot control.

Address the edge node twice: one leg on the cell VLAN, one leg on the OT VLAN. Use a /24 per cell so the third octet maps to the cell number. Reserve the low range for infrastructure and start machine addresses at .50. Document it before the first switch config, not after.

Time is the quiet failure mode. If the edge node timestamps with its own clock and the historian timestamps again, event order breaks. Run one NTP source per plant, point controls and edge nodes at it, and let the historian use the edge timestamp. A 200 ms offset is enough to scramble a fault sequence.

  • 1
    1–5 sMachine state, cycle count, part counter.
  • 2
    100–500 msSpindle load, axis current, feed override.
  • 3
    10–20 msVibration and tool-wear signals inside the cell only.
Failure modes

What breaks when segments talk badly

The first symptom is usually stale data, not an alarm. A dashboard shows a machine running when it stopped 20 minutes ago. That happens when the edge node keeps its last value after the subscription drops, so check the quality flag before the value.

The second is a broadcast storm that reaches the control. One looped cable in a cell with no spanning-tree guard floods every port. The control misses its fieldbus cycle and faults out. Port security and BPDU guard on access ports stop this before it starts.

The third is a firewall rule that is too wide. Someone opens a whole subnet to make a pilot work, and it never gets closed. Keep rules per service and port. OPC UA uses 4840/tcp, MTConnect 5000/tcp or 80/tcp, MQTT 8883/tcp for TLS. Review the rule set each quarter.

  • 1
    Stale value with good qualityCheck the timestamp, not just the number.
  • 2
    Loop without guardEnable BPDU guard and port security on access ports.
  • 3
    Wide firewall ruleOpen single ports, not subnets, and review quarterly.
Step by step

Step by step: five moves to get segmented data flowing

  • 1
    Map the cell before you configure anythingList every device, its protocol, its IP and whether it is control or monitoring. Mark which tags the monitoring layer actually needs. Expect 10–20 tags per machine, not 500. Anything you cannot name a use for, leave inside the cell.
  • 2
    Build one VLAN per cellUse a /24, for example 10.20.5.0/24 for cell 5. Put the control, HMI and edge node on it. Keep fieldbus traffic local. Set the cell switch as the only gateway so no device can route out on its own.
  • 3
    Put the edge node on two legsOne interface on the cell VLAN, one on the OT VLAN. Disable IP forwarding between them. The node reads from the cell and writes to the historian, nothing else. Give it a 24–72 hour local buffer for tag history.
  • 4
    Route OT to IT through a firewall, not a routerAllow only the monitoring ports outbound: 4840/tcp for OPC UA, 8883/tcp for MQTT TLS, 5000/tcp for MTConnect. Log every denied packet for the first two weeks. That log is your rule-tuning list.
  • 5
    Verify with a timestamp, not a screenshotStop a machine and confirm the state changes in the historian within one poll interval. Pull the uplink for 5 minutes and confirm the buffer fills and replays. Check that no control responds to a ping from the IT VLAN.
Readiness check

Segment readiness before you route monitoring traffic

Use this table to judge whether a cell is ready to join the plant monitoring path.

ItemReady whenStill risky when
Cell VLANOne /24 per cell, documentedMachines share the office subnet
Edge nodeTwo legs, no IP forwardingOne NIC bridging both networks
Protocol hopOne conversion at the edgeModbus TCP polled from IT
Time sourceSingle plant NTP, edge timestamp usedEach device uses its own clock
Firewall rulesNamed ports, quarterly reviewWhole subnet opened for a pilot
Buffer depth24–72 hours of tag historyNo local storage on the edge
VerificationState change seen within one pollChecked once during install
FAQs

Questions engineers ask about segmented equipment data

Can we run the monitoring of equipment data over the same cable as PROFINET?

Physically yes, logically no. PROFINET is a real-time protocol with its own timing expectations. Sharing a cable with HTTP or OPC UA traffic is fine if the switch supports priority tagging and you keep monitoring traffic under about 20 percent of link bandwidth.

The safer design terminates PROFINET at the cell switch and lets only the edge node read from it. That keeps the fieldbus cycle independent of whatever the historian is doing.

Do we need OPC UA if every machine already speaks MTConnect?

Not for the CNC machines. If the whole cell is MTConnect, keep it and skip the extra layer. The problem starts when you add a robot, a press or a vision system that has no MTConnect agent.

At that point one OPC UA server on the edge node can normalize everything into one model. Adding it early saves a rewrite later, but it is not required on day one.

How do we handle a machine that only has a serial port?

Use a serial-to-Ethernet gateway on the cell VLAN. Set it to a fixed baud rate and a fixed IP, and poll it at 1 s or slower. Never route raw serial over the plant network.

If the control exposes only a screen with no port, the practical option is a camera or a current sensor on the spindle, and that data stays inside the cell.

What poll rate is too fast for a routed path?

Anything below 50 ms should stay inside the cell. A routed hop adds queueing jitter that grows with network load, and you cannot bound it without strict priority everywhere.

For tool-wear and vibration, collect at the cell level and send a 1 s aggregate across the boundary. You keep the detail locally and the trend remotely.

How do we prove the segments are actually isolated?

Run a port scan from the IT VLAN against a control IP. You should get a timeout, not a refusal. Then check the firewall deny log for the attempt.

Repeat from the cell VLAN and confirm the control answers only on its documented ports. Do this after every switch or rule change, not just at handover.

Need machined parts that fit your monitoring setup?

Send us your drawings and we will return a quote with free DFM analysis within 12 hours. Sensor brackets, edge enclosures, panel plates and mounting hardware, machined to ±0.005 mm and inspected before shipment.

12-hour quote100% inspectionNo minimum order quantity

Follow GreatLight

More machining and monitoring notes

We publish setup notes, tooling trials and inspection data from the factory floor.

FacebookTikTokYouTubeLinkedInInstagramThreadsPinterest

Trusted by engineers and manufacturers worldwide

Tesla Ford Motor Company BYD Auto Denso Magna International Boeing Airbus Medtronic KUKA FANUC