Is your CNC machine tool connected to the internet?
A CNC machine tool connected to a network is really three links stacked on top of each other: the controller, the shop network, and the route to the outside world. This page explains how each link works, what data actually moves across it, and the point where a machine should stay offline. Written for engineers and buyers who have to sign off on the network plan.

In this article
- 1
- 2
- 3
- 4
- 5
- 6
What happens when a CNC machine tool connected to the internet sends data
A CNC controller does not speak internet. It speaks fieldbus and serial: FANUC FOCAS, Siemens 840D, Mitsubishi MELDAS, Heidenhain, or a plain RS-232 port on an older mill. The first job of any connectivity project is to translate those local protocols into something a server can read. That translation usually happens on a small industrial PC bolted to the side of the electrical cabinet, not inside the controller itself.
That box is called an edge gateway. It polls the machine every 100 ms to 1 s, reads spindle load, axis position, program number, alarm codes and cycle state, then republishes the data as MTConnect, OPC UA or MQTT. The polling interval matters. Sub-second polling gives you waveform-level detail for vibration studies, while a 1 s interval is enough for dashboards and OEE tracking.
From the gateway, data travels over Ethernet to a shop switch, then to a plant server, and only after that does it cross a router to the internet. Each hop adds a place where data can be lost or leaked. Count the hops before you draw the network diagram. Most troubleshooting calls come down to a mislabeled VLAN on one of those hops.
One practical detail: older controllers with only RS-232 output cap out near 19.2 kbaud. You cannot stream high-frequency data through that port no matter how good the gateway is. In those cases the gateway buffers a summary every few seconds instead of raw samples.
- 1Fieldbus firstFOCAS, PROFINET or Modbus TCP stays inside the cabinet.
- 2Edge translationGateway converts to MTConnect, OPC UA or MQTT.
- 3Serial ceilingRS-232 tops out near 19.2 kbaud, so summarize instead.
- 4Count the hopsController, switch, server, router, cloud.
What data is worth moving off the machine
Not every signal deserves a network cable. Divide machine data into three buckets: process data, asset data and part data. Process data covers spindle speed, feed override, axis load and coolant state. It changes every second and is only useful for live monitoring. Asset data covers runtime hours, alarm history, servo current trends and maintenance counters. It changes slowly and is what predictive maintenance models actually consume.
Part data is the third bucket, and it is the one that touches your customer. Program files, tool offsets, probe results and inspection records belong here. When a job is traceable, part data has to be versioned and tied to a serial number. That is a document-control problem more than a network problem, but the network is how the record travels.
A common mistake is to push all three buckets to the cloud at full rate. The bandwidth is rarely the limit. The limit is the human who has to read the dashboard. Teams that dump everything usually stop looking at it within a month. Pick 8 to 12 tags per machine and make those reliable.
For job shops running one to ten machines, the honest answer is that a shared network folder for programs plus a spreadsheet of run hours covers 80% of the value. Full MTConnect infrastructure starts to pay back when you have 15 or more machines, or when a customer contract requires traceable records.
- 1Process dataFast-changing signals for live monitoring only.
- 2Asset dataSlow counters that feed maintenance models.
- 3Part dataPrograms, offsets and inspection records tied to serials.
- 4Tag discipline8 to 12 reliable tags beat 200 noisy ones.
Where the internet boundary should sit
The safest architecture puts a boundary between the machine network and everything else. Machines live on their own VLAN. The gateway has one interface on that VLAN and one on the business network. Nothing on the machine VLAN can reach a browser, an email client or a USB stick. This is the same segmentation logic used for building control systems, and it costs almost nothing to set up.
Remote access is the part that gets shops in trouble. Opening an inbound port to a controller is a bad idea, and it is also unnecessary. A VPN with per-user credentials, or a reverse-tunnel agent that dials out from the gateway, gives the OEM or the integrator access without exposing the controller to port scans. Log every session. If your machine builder asks for a public IP address, ask why.
Outbound-only connections are the default we recommend. The gateway initiates the session, the cloud answers, and no inbound rule exists on the firewall. That single design choice removes most of the attack surface while keeping remote diagnostics and OTA parameter updates working.
Physical access still matters. A shop-floor USB port bypasses every firewall rule you wrote. Disable autorun, scan removable media at a kiosk, and keep a written policy for program transfer. Network security with an open USB port is decoration.
- 1Machine VLANNo route to business network or internet.
- 2Dual-homed gatewayOne leg on machine VLAN, one on plant LAN.
- 3Outbound onlyReverse tunnel instead of inbound port forwarding.
- 4USB policyMost breaches walk in through the shop door.
When a CNC machine tool connected to the internet is the wrong choice
Some machines should stay offline, and that is a defensible engineering decision, not a lack of ambition. A legacy controller running an unsupported operating system cannot be patched. If the vendor no longer ships security fixes, adding a network card turns a stable machine into a permanent liability. Run it on a standalone PC with a USB stick and document the exception.
Safety circuits are a second boundary. Emergency stop, light curtain and door interlock logic should never depend on network state. If a packet drop can delay a stop signal, the design is wrong. Keep safety on hardwired or dedicated safety-bus paths and let the network only observe.
A third case is high-value or export-controlled work. If the part geometry itself is sensitive, the CAD file and the post-processor output are the assets worth protecting. A machine that only receives G-code from a local server and never talks outbound is easier to defend than one with a live cloud link.
The practical rule: connect for visibility, not for control. Monitoring, alarm push and program distribution are low-risk wins. Remote start, remote parameter writes and remote axis motion raise the consequence of a single credential leak by a large margin. Decide which list you are on before you buy hardware.
- 1Unpatchable OSKeep offline and transfer by controlled media.
- 2Safety logicHardwired or safety bus, never general network.
- 3Sensitive geometryLocal server only, no outbound path.
- 4Visibility vs controlRead is cheap, write is expensive when it fails.
What connectivity changes on the machining side
On the production floor, the visible benefit is program distribution. Instead of walking a USB stick to each machine, the operator pulls the released revision from a server. Version control stops the classic failure where two machines run two different revisions of the same job. For shops running aluminum and stainless parts at ±0.005 mm, that alone can remove a recurring scrap source.
The second benefit is tool life tracking. Cutting 17-4PH or Inconel loads the tool differently than 6061. If spindle load and cycle count are logged, tool changes move from a fixed schedule to a condition-based one. On titanium and nickel alloys this often extends usable tool life without risking a scrapped part.
The third benefit is quoting feedback. Real cycle times from a machine running the actual program beat any estimate. After a few hundred jobs, the shop has its own cost model. That is a genuine competitive advantage, and it does not require a cloud subscription.
None of this replaces inspection. Data tells you a machine ran; it does not tell you the bore is in tolerance. Keep 100% inspection before shipment in place, and treat network data as a process signal, not a quality record.
- 1Program controlOne released revision, pulled by the operator.
- 2Tool lifeCondition-based changes on hard alloys.
- 3Cycle time dataReal times feed a real cost model.
- 4Inspection staysNetwork data is a process signal, not QC.
Connectivity options by machine age and data need
Pick the row that matches your controller and what you need to read.
| Machine situation | Best link | Data you get | Watch out for |
|---|---|---|---|
| Pre-2005 control, RS-232 only | Serial-to-Ethernet device server | Program transfer, cycle start counts | Baud ceiling near 19.2 kbaud |
| 2010s control with Ethernet | Edge gateway on machine VLAN | Spindle load, alarms, OEE tags | Firmware option may be locked |
| New machine, vendor cloud ready | Outbound reverse tunnel | Full telemetry plus remote diagnostics | Vendor account owns your data |
| Unsupported OS, no patches | Stay offline, controlled media | Manual logs only | USB is now your attack path |
| Safety or interlock circuit | Hardwired or safety bus | None over general network | Never route E-stop through TCP |
| Sensitive geometry, ITAR-style | Local server, no outbound route | Program distribution inside plant | Air-gap policy must be audited |
The call we would make
If you need visibility, connect the machine with an outbound-only gateway on an isolated VLAN. If you need remote control of axis motion or parameters, keep that path off the public internet and require a named VPN session with logging. Read-only is worth the cable. Write access is worth a written policy first.
Questions engineers ask next
Does connecting a CNC machine void the warranty?
It depends on the builder. Some controllers ship with the Ethernet option disabled and enabling it requires a paid license key. Others allow read-only protocols like FOCAS or MTConnect without any change to the warranty.
Ask the builder in writing before you touch the network settings. If the answer is unclear, connect the gateway to the diagnostic port only and leave the main control path alone.
Can we use Wi-Fi instead of a cable run?
For monitoring data, yes. A stable industrial access point with a dedicated SSID works fine, and the gateway buffers through short dropouts.
For program transfer on large surfacing files, wired Ethernet is safer. A dropped Wi-Fi session mid-transfer can leave a partial program on the controller. If you must go wireless, verify the file hash after transfer.
What protocol should we standardize on?
MTConnect is the most common read-only choice for machine monitoring and has broad controller support. OPC UA is better when you also need to talk to PLCs and SCADA on the same plant.
MQTT is lightweight and travels well over slow links, which suits remote sites. Many gateways can publish two of these at once, so you are not locked in.
How much bandwidth does one machine need?
Monitoring tags are tiny. A gateway publishing 50 tags at 1 Hz uses well under 100 kbit/s, so a shared 10 Mbit/s link handles dozens of machines.
The bandwidth question only becomes real if you stream high-frequency vibration or power quality data. That is normally done locally at the edge, with only the analysis result uploaded.
Who owns the data collected from our machines?
Read the contract, not the brochure. Some vendor platforms claim a license to machine telemetry and use it for benchmarking across customers.
If that is not acceptable, run your own gateway and your own database. The hardware cost is modest and you keep control of the retention and export policy.
Is a firewall enough to secure the machine network?
A firewall is one layer. You also need VLAN separation, per-user VPN credentials, session logging and a removable media policy.
Patch the gateway itself. It is a small Linux or Windows machine and it is often the least maintained computer on the shop floor.
Send us the drawing and the network question
We machine prototypes and production parts from one piece to 10,000+, with DFM feedback inside 12 hours and 100% inspection before shipment. If your project needs traceable process data, tell us on the quote form.
12-hour quote100% inspectionNDA on request