Monitoring of Equipment Data: Managing Communication Between Network Segments
Cell networks, OT VLANs and the IT backbone rarely share one cable, yet the monitoring of equipment data has to cross all three. This guide shows machine builders and plant engineers how to segment, route and verify that traffic without exposing a CNC control to the wrong subnet. Read the five steps, then check the readiness table before you touch a switch config.

In this article
- 1
- 2
- 3
- 4
- 5
- 6
- 7
Key takeaways
Why the monitoring of equipment data crosses segment boundaries
A CNC control talks to its servo drives over a deterministic fieldbus. The MES that wants cycle counts, spindle load and alarm codes sits on a different subnet, usually on a different floor. Between them are at least two boundaries: the machine cell and the plant OT backbone. The monitoring of equipment data has to cross both without letting the fieldbus timing degrade.
Most plants start flat. Every machine, HMI, camera and office PC shares one broadcast domain. That works at 20 nodes. At 200 nodes the broadcast traffic from a single misconfigured device can stall the polling loop, and a technician with a laptop on the wrong address can reach a spindle drive. Segmentation is not a security project bolted on later; it is what keeps the data path predictable.
The practical goal is narrow. Keep real-time control traffic inside the cell. Move only the tags the monitoring layer needs across the boundary. Give each boundary a device that can log, filter and buffer, so a lost uplink delays data instead of losing it.
- 1Control stays localFieldbus and safety traffic never leaves the cell switch.
- 2Monitoring traffic is one-way by defaultEdge node reads from the cell, writes only to the historian.
Choosing the protocol that fits each segment hop
Inside the cell, most controls expose data over Modbus TCP, PROFINET, EtherNet/IP or a vendor SDK. These are fast and simple but they assume a trusted network. Do not route them across the plant backbone. Terminate them at an edge node that sits on the cell VLAN.
On the edge node, convert to a monitoring protocol. OPC UA with a subscription model is the usual choice for multi-vendor plants because it carries data types and timestamps. MTConnect suits shops that mostly run CNC machines and want a read-only HTTP stream. MQTT fits sites with intermittent links, since it tolerates reconnects better than a persistent session.
The rule is one conversion per boundary. If you bridge Modbus TCP straight to the IT VLAN, every historian poll hits the control. If you convert once at the edge, the control sees one client and the historian sees one server. That single change cuts control CPU load and makes firewall rules readable.
- 1Fieldbus inside the cellModbus TCP, PROFINET, EtherNet/IP stay on the cell VLAN.
- 2OPC UA or MTConnect across the boundaryOne conversion at the edge node, not at the control.
- 3MQTT for unstable linksSet keepalive 30–60 s and a clean session flag.
Addressing, polling rates and the numbers that matter
Poll interval is the first number to fix. Cycle counts and machine state are fine at 1–5 s. Spindle load trends want 100–500 ms. Vibration or tool-wear signals may need 10–20 ms, and those should stay inside the cell because a routed path adds jitter you cannot control.
Address the edge node twice: one leg on the cell VLAN, one leg on the OT VLAN. Use a /24 per cell so the third octet maps to the cell number. Reserve the low range for infrastructure and start machine addresses at .50. Document it before the first switch config, not after.
Time is the quiet failure mode. If the edge node timestamps with its own clock and the historian timestamps again, event order breaks. Run one NTP source per plant, point controls and edge nodes at it, and let the historian use the edge timestamp. A 200 ms offset is enough to scramble a fault sequence.
- 11–5 sMachine state, cycle count, part counter.
- 2100–500 msSpindle load, axis current, feed override.
- 310–20 msVibration and tool-wear signals inside the cell only.
What breaks when segments talk badly
The first symptom is usually stale data, not an alarm. A dashboard shows a machine running when it stopped 20 minutes ago. That happens when the edge node keeps its last value after the subscription drops, so check the quality flag before the value.
The second is a broadcast storm that reaches the control. One looped cable in a cell with no spanning-tree guard floods every port. The control misses its fieldbus cycle and faults out. Port security and BPDU guard on access ports stop this before it starts.
The third is a firewall rule that is too wide. Someone opens a whole subnet to make a pilot work, and it never gets closed. Keep rules per service and port. OPC UA uses 4840/tcp, MTConnect 5000/tcp or 80/tcp, MQTT 8883/tcp for TLS. Review the rule set each quarter.
- 1Stale value with good qualityCheck the timestamp, not just the number.
- 2Loop without guardEnable BPDU guard and port security on access ports.
- 3Wide firewall ruleOpen single ports, not subnets, and review quarterly.
Step by step: five moves to get segmented data flowing
- 1Map the cell before you configure anythingList every device, its protocol, its IP and whether it is control or monitoring. Mark which tags the monitoring layer actually needs. Expect 10–20 tags per machine, not 500. Anything you cannot name a use for, leave inside the cell.
- 2Build one VLAN per cellUse a /24, for example 10.20.5.0/24 for cell 5. Put the control, HMI and edge node on it. Keep fieldbus traffic local. Set the cell switch as the only gateway so no device can route out on its own.
- 3Put the edge node on two legsOne interface on the cell VLAN, one on the OT VLAN. Disable IP forwarding between them. The node reads from the cell and writes to the historian, nothing else. Give it a 24–72 hour local buffer for tag history.
- 4Route OT to IT through a firewall, not a routerAllow only the monitoring ports outbound: 4840/tcp for OPC UA, 8883/tcp for MQTT TLS, 5000/tcp for MTConnect. Log every denied packet for the first two weeks. That log is your rule-tuning list.
- 5Verify with a timestamp, not a screenshotStop a machine and confirm the state changes in the historian within one poll interval. Pull the uplink for 5 minutes and confirm the buffer fills and replays. Check that no control responds to a ping from the IT VLAN.
Segment readiness before you route monitoring traffic
Use this table to judge whether a cell is ready to join the plant monitoring path.
| Item | Ready when | Still risky when |
|---|---|---|
| Cell VLAN | One /24 per cell, documented | Machines share the office subnet |
| Edge node | Two legs, no IP forwarding | One NIC bridging both networks |
| Protocol hop | One conversion at the edge | Modbus TCP polled from IT |
| Time source | Single plant NTP, edge timestamp used | Each device uses its own clock |
| Firewall rules | Named ports, quarterly review | Whole subnet opened for a pilot |
| Buffer depth | 24–72 hours of tag history | No local storage on the edge |
| Verification | State change seen within one poll | Checked once during install |
Questions engineers ask about segmented equipment data
Can we run the monitoring of equipment data over the same cable as PROFINET?
Physically yes, logically no. PROFINET is a real-time protocol with its own timing expectations. Sharing a cable with HTTP or OPC UA traffic is fine if the switch supports priority tagging and you keep monitoring traffic under about 20 percent of link bandwidth.
The safer design terminates PROFINET at the cell switch and lets only the edge node read from it. That keeps the fieldbus cycle independent of whatever the historian is doing.
Do we need OPC UA if every machine already speaks MTConnect?
Not for the CNC machines. If the whole cell is MTConnect, keep it and skip the extra layer. The problem starts when you add a robot, a press or a vision system that has no MTConnect agent.
At that point one OPC UA server on the edge node can normalize everything into one model. Adding it early saves a rewrite later, but it is not required on day one.
How do we handle a machine that only has a serial port?
Use a serial-to-Ethernet gateway on the cell VLAN. Set it to a fixed baud rate and a fixed IP, and poll it at 1 s or slower. Never route raw serial over the plant network.
If the control exposes only a screen with no port, the practical option is a camera or a current sensor on the spindle, and that data stays inside the cell.
What poll rate is too fast for a routed path?
Anything below 50 ms should stay inside the cell. A routed hop adds queueing jitter that grows with network load, and you cannot bound it without strict priority everywhere.
For tool-wear and vibration, collect at the cell level and send a 1 s aggregate across the boundary. You keep the detail locally and the trend remotely.
How do we prove the segments are actually isolated?
Run a port scan from the IT VLAN against a control IP. You should get a timeout, not a refusal. Then check the firewall deny log for the attempt.
Repeat from the cell VLAN and confirm the control answers only on its documented ports. Do this after every switch or rule change, not just at handover.
Need machined parts that fit your monitoring setup?
Send us your drawings and we will return a quote with free DFM analysis within 12 hours. Sensor brackets, edge enclosures, panel plates and mounting hardware, machined to ±0.005 mm and inspected before shipment.
12-hour quote100% inspectionNo minimum order quantity