Overview VPN

A VPN connection can optionally be activated on the controller. With this, the controller connects to the uni-PRO VPN server. Via this VPN connection, the uni-PRO APP can connect to the controller without port forwarding.

For the user this means: the visualisation of the installation can also be reached when away from home, without having to set up or open anything on the router and without the controller being accessible from the internet.

The VPN connection is disabled by default. To activate the VPN, call up the web interface of the controller; the connection can be activated under the VPN menu item.

In addition, the serial number of the controller has to be linked to a user name and a password so that the APP and the Studio can connect to the controller via VPN. See VPN connection (linking a controller).

Table of contents


Before the APP or the Studio can connect to a controller via the VPN, the serial number of the controller has to be linked to a user name and a password. There are two ways to create and delete this link:

Both ways create the same link, so a link created in the browser can also be deleted in the Studio and vice versa.

VPN connection Web

The link is created in any browser, a Studio is not required for this. Call up the following page:

https://online.uni-pro.at/unipro_register_app/

The page offers the three sections "Neue Registrierung" (new registration), "Registrierung löschen" (delete registration) and "Registrierung ändern" (change registration). The serial number of the controller is always entered manually here, it can be read in the Studio under Controller - Controller information or in the web interface of the controller.

New registration

Serial number, password, repeat password and e-mail have to be entered. "Registrieren" creates the link.

The e-mail address has to actually exist here. After the registration the message "Bestätigungsemail gesendet" (confirmation e-mail sent) is displayed and an e-mail containing a link is sent to the given address. The link is only valid and the connection via VPN is only possible once this link has been clicked. If the e-mail is not in the inbox, please also check the spam folder.

A new connection with this e-mail address and password can then be created and used in the APP or in the Studio.

Delete registration

Serial number, password and e-mail of the existing link have to be entered. "Löschen" removes the link and "Verknüpfung gelöscht" (link deleted) is displayed. Afterwards a connection via VPN is no longer possible with these credentials.

Change registration

Password and e-mail address of an existing link can be changed here without deleting and creating it again. Under "Daten alt" (old data) enter serial number, password and e-mail of the existing link, under "Daten neu" (new data) the new password, the repetition of the new password and the new e-mail address. "Ändern" applies the data and "Daten erfolgreich geändert" (data changed successfully) is displayed.

Messages

VPN connection Studio

The dialog is opened via the menu Controller - VPN connection.

Note: The VPN link via the Studio is only available for business customers. All other users create the link in the browser, see VPN connection Web.

Login

After the dialog has been opened the input fields are still hidden, the message "Please log in to use this function" is displayed. Use the button to the right of the message to log in. Business customers can request the user name and password for this login from the support, these are not the credentials of a VPN link.

The icon of the button shows the login status: white = not logged in, green = logged in, red = wrong user name or password. The input fields are only displayed after a successful login. The credentials used last are stored and suggested the next time the dialog is opened, they then only have to be confirmed.

The purpose of the login is to verify the user. For this reason the user name entered for the link does not have to be confirmed.

Creating a link

"Create connection" creates the link on the server, on success the message "Serial number linked successfully" is displayed. A new connection with this user name and password can then be created and used immediately.

Deleting a link

To delete a link, enter serial number, user name and password of the existing link and press "Delete connection". Only this one link is deleted. Afterwards a connection via VPN is no longer possible with these credentials, a connection attempt is rejected with an error message.

Messages

Data protection and data storage

Where the data of an installation is stored and who has access to it is a legitimate question for operators and IT managers. The following sections summarise where the servers of the VPN service are operated, which data is processed there and to what extent the controller depends on external services at all.

Server location and operator

The uni-PRO VPN service is operated at a European provider. All servers used for it are located exclusively in data centres within the European Union and are therefore fully subject to the General Data Protection Regulation (GDPR). No data is processed or stored in third countries outside the EU.

The VPN service is optional

The VPN connection is disabled on delivery. It has to be switched on deliberately in the web interface of the controller and can be switched off there again at any time. The decision whether the service is used is therefore entirely up to the operator of the installation.

Remote access can alternatively be realised with a private VPN of your own or with a port forwarding in the router. In this case the uni-PRO VPN service is not required and the communication between APP and controller does not leave your own infrastructure. This does not change the functionality of the installation in any way: program, operation and visualisation are identical, regardless of how the connection is established.

No dependency on cloud services

The controller works completely on its own. The project, all programs, switching times, parameters, states and recordings are stored locally on the controller and are also processed there. There is no user account in a cloud without which the installation would not work, and no part of the control logic is moved to an external server.

If the internet connection fails or the VPN service is not reachable, the installation continues to run unchanged. Only remote access from outside the building is not possible during this time, operation within the local network remains fully available. Permanently doing without the VPN service does not affect the operation of the installation either.

The only exception are those function blocks that deliberately use an external service, for example for weather data, energy prices, voice assistants or the connection of third-party devices via the portals of their manufacturers. These blocks are created and configured in the project on purpose. If they are not used, there is no connection to the services concerned either.

Which data is processed on the server

Only the link itself is stored on the server, that is serial number of the controller, user name and password. This information is required in order to assign a connection request of the APP to the correct controller and to authorise it.

No installation data is stored on the server: neither the project nor the visualisation, neither measured values nor recordings or statistics are held there. The VPN server only provides the encrypted transport path between APP and controller.

All data held on the server is stored exclusively in encrypted form. Not even we as the provider of the service have access to this data - it can neither be viewed nor evaluated nor passed on to third parties. For this reason a forgotten password cannot be read out or sent to you by the support either; in such a case the link is deleted and created again.

Access and control

Access via the VPN is only possible with the credentials of the link, that is with the user name and the password that were assigned when the link was created. These credentials are defined by the operator.

The link can be deleted at any time and without asking anyone, see Delete registration or Deleting a link. Access via the VPN is then blocked immediately and permanently. Together with switching off the VPN connection in the web interface of the controller, the operator keeps full control over whether and for how long remote access to the installation is possible.

Technical information

The following sections are intended for technicians and IT managers. They describe the ports used, the network requirements and how to proceed when troubleshooting. This information is not required in order to use the installation.

VPN connection controller

The VPN integrated in the controller connects to the uni-PRO VPN server via port 30001. Several VPN servers are used here. The responsible VPN server depends on the serial number of the controller.  The controller must be able to connect to external servers; these must not be blocked by a firewall.

VPN connection APP

When setting up a new VPN connection on the APP, it connects via port 10003 to the uni-PRO server for authentication and to determine the responsible VPN server. When the connection is established, it then connects directly to the determined VPN server, also via port 10003.

Port forwarding

In the local network, the APP connects to the controller via port 10001. If you want to set up port forwarding to the controller, this port must be entered in the router for the controller. The Studio also uses this port.

If a different incoming port is to be used for port forwarding on the router, this can be specified on the APP after the IP address, separated by a colon. For example "17.18.19.10:1234". On the router, the incoming port 1234 must be forwarded to the controller's 10001.

Important: The controller should never be directly accessible from the Internet. We recommend using the integrated VPN connection. If this is not possible, we recommend using a private VPN.

NTP server

For time functions and the VPN connection, the controller requires the exact time. Therefore, a reachable NTP server should be set in the web interface of the controller. The default is pool.ntp.org, NTP port 123. Alternatively, this can also be switched to a local NTP server in the network.

Tips for troubleshooting the VPN connection

The VPN connection must be activated in the web interface of the controller; by default this is switched off. Under "Test Internet Connection" all queries must be green. If this is not the case, it can have the following causes:


Important: Please note the disclaimer when using the VPN service.