Windows Deployment for OTserver Otter

Prerequisites

Use Windows 10 or newer. Download otserver-otter.exe from a tested Otter release into a dedicated directory. Keep otter.json beside the executable and restrict access to it because it can contain scan and upload credentials.

Windows ARP discovery needs no additional driver. For active PROFINET DCP, install Npcap separately. Otter does not bundle or install it during a scan; the GUI’s Download Npcap link opens the download site. Without Npcap, Microsoft pktmon provides passive PROFINET observation, requires Administrator rights, and cannot transmit DCP Identify.

Select the physical adapter by its interface name or GUID and use that adapter’s actual MAC address. Otter verifies the source MAC before active DCP and never creates a TAP adapter or Windows Network Bridge.

Inspect the scanner

From the directory containing the downloaded executable, run:

1
2
3
.\otserver-otter.exe --version
.\otserver-otter.exe doctor
.\otserver-otter.exe interfaces

Confirm that doctor reports the Npcap active PROFINET backend as available when active DCP is required. Run Otter as Administrator if adapter access is denied or you use the pktmon fallback.

To build from source instead, clone the Otter repository and run cargo build --locked --release --target x86_64-pc-windows-msvc with Rust and the MSVC C++ build tools installed. The executable is then in target\x86_64-pc-windows-msvc\release; run the inspection and scan commands from that directory.

Windows scan

1
2
3
4
5
6
.\otserver-otter.exe scan `
  --target 192.168.1.0/24 `
  --interface '<interface name or GUID>' `
  --source-mac 00:11:22:33:44:55 `
  --output .\scan.otserver.json `
  --ack-authorized

Replace the example target, interface, and MAC with the authorized network and selected adapter’s values. Disable protocols individually with flags such as --no-profinet; disabling PROFINET alone does not disable the ARP sweep. Keep the explicit --ack-authorized flag in every manual or scheduled scan.

The Windows GUI also edits SNMP and OPC UA settings, direct-upload details, and executable-adjacent otter.json. It can add named configurations by cloning the selected one, then run the selected configuration or all configurations sequentially. A stopped scan writes valid partial output when possible.

Verify the result

1
.\otserver-otter.exe validate .\scan.otserver.json

Inspect the export warnings before importing. Scan exit code 0 means all configured scans completed, 2 means at least one valid output is partial, and 1 means a configuration, scan, or upload failed. Configure direct upload and Windows Task Scheduler after a manual scan succeeds.

Plan scanner placement in a plant or read the PROFINET guide.