Building automation over IP
BACnet/IP
Learn how OTserver uses BACnet ReadProperty requests on UDP 47808 to collect controller identity, firmware, model, location, and vendor evidence.
Read discovery guideOTserver Scanner
Explore how OTserver discovers and parses PROFINET, S7, EtherNet/IP, BACnet, Omron FINS, Niagara Fox, SNMP, and LLDP evidence.
OTserver combines Layer 2 discovery with fixed, read-only identity queries. Each guide below documents the request the scanner sends, the evidence it accepts, the default transport, and the safety boundary implemented in the scanner source code.
ARP first correlates an IPv4 address with a normalized MAC address. Protocol-specific observations then enrich that same asset instead of creating records from changeable IP addresses or device names.
Building automation over IP
Learn how OTserver uses BACnet ReadProperty requests on UDP 47808 to collect controller identity, firmware, model, location, and vendor evidence.
Read discovery guideCIP over industrial Ethernet
See how OTserver sends EtherNet/IP List Identity requests over TCP and UDP to inventory industrial devices without opening a control session.
Read discovery guideLayer 2 topology evidence
See how OTserver reads LLDP MIB neighbor tables through SNMP to create MAC-correlated industrial network topology links.
Read discovery guideBuilding automation station protocol
See how OTserver sends a Niagara Fox hello on TCP 1911 and 4911 to inventory station names, platforms, application versions, and vendor IDs.
Read discovery guideOmron industrial control protocol
Learn how OTserver uses the read-only Omron FINS Controller Data Read command over TCP and UDP 9600 to identify PLC models and versions.
Read discovery guideLayer 2 industrial Ethernet
Learn how OTserver uses read-only PROFINET DCP Identify requests to discover device names, models, MAC addresses, IP settings, and device roles.
Read discovery guideIndustrial control over ISO-on-TCP
See how OTserver reads Siemens S7 system-status lists over TCP 102 to identify PLC hardware, firmware, names, and serial numbers.
Read discovery guideNetwork management
Learn how OTserver uses read-only SNMPv2c or SNMPv3 GET and WALK operations to collect system, interface, entity, IP, and bridge evidence.
Read discovery guide