SCADA / HMI

Version 2026.20

Compatibility

OPC UA client and server for SCADA

Nexus connects out to any conformant OPC UA server and is also an OPC UA server that other systems can connect to. Both come with the base licence.

Two separate things

The opc-ua driver is the client. It connects out to someone else’s server and works with any conformant OPC UA server. It is the default when a device entry has no driver set.

Nexus is also an OPC UA server, which is a different facility. The driver connects out to a server. The Nexus server lets another system connect in to Nexus. You can use either or both.

The client is also the way to reach devices Nexus has no driver for. A third-party OPC UA server in front of the device, or the controller’s own server, gives Nexus a route to it.

Security and certificates

Raylux connects with sign-and-encrypt by default. The security hardening checklist says to leave OPC UA on SignAndEncrypt unless a device genuinely cannot do it.

The usual first failure follows from that. Most servers quarantine an unknown client certificate until an administrator approves it. If an OPC UA device shows as disconnected, look in the server’s rejected-certificates list for Nexus’s certificate and trust it. The reason for a failure is in the tooltip on the device state in the Nexus configuration section.

Setup in brief

Add a device, leave the driver as opc-ua or set it explicitly, set the endpoint, and bind tags in Studio. Like every Nexus device, it carries a name, an endpoint, a port, a fallback pollRateMs, a timeoutMs and a reconnectDelayMs. The name is what tags refer to, so rename a device in the configuration interface rather than by hand in the file, or its tag bindings break. A device holds no address list. It polls exactly the tags bound to it, so adding a tag in Studio starts it scanning without editing the device or restarting Nexus.

The driver table is in the manual under Devices and drivers, What Nexus can talk to.

Scan rates and dropped links

Scan rate comes from the tag group, not the device. A group is direct (a fixed rate), leased (quick while something is watching the tag, slow otherwise) or driven (quick while an expression is true). A fresh gateway ships with default-fast at 250 ms, default-slow at 5000 ms and default-historical at 10 s. A tag goes Stale after its rate times staleMultiplier passes without an update, and returns to Good once it is being read again. A rate faster than the device can answer does not bring data sooner; the poll just falls behind.

A device that stops answering is marked disconnected, and its tags follow the quality rules instead of freezing at their last value. Writes forwarded to a device that has since dropped are not silently discarded. The device list in the Nexus configuration section shows each device’s state, with the reason for a failure in the tooltip. The troubleshooting page covers the usual causes.

Limits

The manual is direct about one gap: OPC UA has not been verified against third-party hardware. Test your specific server before commissioning depends on it. It is listed under known gaps in the hardening guide, and the free trial is the place to do that test.

Licence and trial

OPC UA is included in the base licence, which lists at $995, as both client and server. There is no separate OPC server to license alongside Nexus.

The free trial runs for two hours with every driver unlocked, and you can restart it as often as you like. Point it at the controller on your bench and read a tag before you decide anything.

Next step

Read a tag off your own PLC.

The trial is two hours with every driver unlocked, and restartable as often as you like. Point it at the controller on your bench before you decide anything.