OTserver Scanner

Supported Industrial Protocols and Asset Discovery

Explore how OTserver discovers and parses PROFINET, S7, EtherNet/IP, BACnet, Omron FINS, Niagara Fox, SNMP, and LLDP evidence.

OTserver combines Layer 2 discovery with fixed, read-only identity queries. Each guide below documents the request the scanner sends, the evidence it accepts, the default transport, and the safety boundary implemented in the scanner source code.

ARP first correlates an IPv4 address with a normalized MAC address. Protocol-specific observations then enrich that same asset instead of creating records from changeable IP addresses or device names.

Building automation over IP

BACnet/IP

Learn how OTserver uses BACnet ReadProperty requests on UDP 47808 to collect controller identity, firmware, model, location, and vendor evidence.

Read discovery guide

CIP over industrial Ethernet

EtherNet/IP

See how OTserver sends EtherNet/IP List Identity requests over TCP and UDP to inventory industrial devices without opening a control session.

Read discovery guide

Layer 2 topology evidence

LLDP

See how OTserver reads LLDP MIB neighbor tables through SNMP to create MAC-correlated industrial network topology links.

Read discovery guide

Building automation station protocol

Niagara Fox

See how OTserver sends a Niagara Fox hello on TCP 1911 and 4911 to inventory station names, platforms, application versions, and vendor IDs.

Read discovery guide

Omron industrial control protocol

Omron FINS

Learn how OTserver uses the read-only Omron FINS Controller Data Read command over TCP and UDP 9600 to identify PLC models and versions.

Read discovery guide

Layer 2 industrial Ethernet

PROFINET DCP

Learn how OTserver uses read-only PROFINET DCP Identify requests to discover device names, models, MAC addresses, IP settings, and device roles.

Read discovery guide

Industrial control over ISO-on-TCP

Siemens S7

See how OTserver reads Siemens S7 system-status lists over TCP 102 to identify PLC hardware, firmware, names, and serial numbers.

Read discovery guide

Network management

SNMP

Learn how OTserver uses read-only SNMPv2c or SNMPv3 GET and WALK operations to collect system, interface, entity, IP, and bridge evidence.

Read discovery guide