GreatLight CNC Machining Factory logo
CNC Machining
Rapid Prototyping
Materials
Industries
News
About GL

Get Instant Quote

CNC network integration guide

How to Achieve Access to NAT Networks by CNC Machine Tools

Network Address Translation sits between your CNC controls and the plant network. This guide shows how to reach NAT networks by CNC machine tools without breaking controller warranties or exposing the shop floor. Written for maintenance engineers and controls teams who need a working plan, not a theory lesson.

15 years in CNC127 CNC machinesISO 27001:2022NDA on request
How to achieve access to NAT networks by CNC machine tools on a shop floor
Quick answer

Key takeaways

One public IP is enoughNAT lets dozens of CNC controls share a single routable address through port mapping.
Map ports, not whole subnetsForward only the ports the control actually uses, such as 502 for Modbus TCP or 8193 for FOCAS.
Keep the controller on a private subnetCNC controls stay on 192.168.x.x or 10.x.x.x; only the gateway holds the public address.
Plan for IP conflicts firstTwo machines with the same default IP will stall the whole commissioning day.
Log every changePort maps drift. A simple spreadsheet saves hours when the network is audited.
Why NAT is needed

Why CNC controls sit behind NAT in the first place

Most CNC controls ship with a fixed private address. Fanuc, Siemens, and Mitsubishi controls typically default to something like 192.168.0.1 or 192.168.1.1. If you connect two machines with the same default, neither one talks to the network. NAT solves that by giving each control its own private address behind a gateway that holds one public address.

The alternative is to give every machine a public IP. That works until you have 40 machines and a limited address block. It also puts every control directly on the internet, which most IT departments will refuse. NAT keeps the controllers hidden while still allowing a programmer or a monitoring server to reach them.

There is a second reason. Many CNC controls run old embedded operating systems that have not seen a security patch in years. Leaving them on a flat public network is a liability. A NAT gateway acts as a buffer: inbound traffic only reaches the control if a port map exists for it.

So the goal is not to remove NAT. The goal is to configure it so that the right traffic passes and everything else is dropped. That is what the steps below cover.

  • 1
    Private address per controlEach CNC gets a unique address on the shop subnet.
  • 2
    One public addressThe gateway holds the routable IP and performs translation.
  • 3
    Explicit inbound rulesNo port map means no inbound path to the control.
Before you start

What to gather before touching the gateway

You need four pieces of information before you change a single setting. First, the current IP address and subnet mask of every CNC control you plan to connect. Second, the protocol each control uses for data transfer: FOCAS, Modbus TCP, OPC UA, or simple FTP. Third, the public IP or IP block assigned by your ISP. Fourth, the internal subnet you will use for the machine network.

Write these down in a table before you start. In our experience, the most common commissioning delay is discovering that two machines were configured with the same address months ago and nobody noticed. A quick ping sweep of the machine subnet finds duplicates in under a minute.

Also check the firmware version of each control. Older Fanuc 0i series controls may not support the same Ethernet options as a 31i. If the control only supports FTP for program transfer, your port map will look different from a machine running OPC UA.

Finally, confirm who owns the firewall. In many plants the IT team manages the gateway, and the maintenance team manages the machines. Agree on the change window before you start. A 30-minute window is usually enough for three to five machines.

  • 1
    Machine inventoryModel, control type, current IP, and protocol for each unit.
  • 2
    Gateway accessAdmin credentials and a backup of the current configuration.
  • 3
    Change windowAgreed with IT and production so no job is interrupted.
  • 4
    Rollback planThe old configuration saved to a file before any edit.
Addressing

Designing the private subnet for CNC machine tools

Pick a private range that does not overlap with the office network. Common choices are 10.10.0.0/24 or 192.168.50.0/24. Avoid 192.168.0.0/24 and 192.168.1.0/24 because those are the factory defaults on many controls and will cause conflicts later.

Assign addresses in blocks by machine type. For example, 10.10.0.11 to 10.10.0.30 for milling centers, 10.10.0.31 to 10.10.0.50 for lathes, and 10.10.0.51 to 10.10.0.70 for EDM. This makes troubleshooting faster because the address tells you what kind of machine you are looking at.

Set the subnet mask to 255.255.255.0 for a single shop segment. If you have more than 200 devices, move to a /23 or split into VLANs. Do not use a /16 just because it is easy; large broadcast domains slow down older controls.

Leave the gateway address on the control pointed at the NAT router, not at the office firewall. The control should never see the office network directly. If it does, you have created a routing path that bypasses your port maps.

  • 1
    Avoid default ranges192.168.0.x and 192.168.1.x are already used by many controls.
  • 2
    Group by machine typeAddress blocks make the network self-documenting.
  • 3
    One gateway onlyThe control points at the NAT router, nothing else.
Troubleshooting

Common failures and how to clear them

The most frequent symptom is a control that pings locally but is unreachable from outside. Nine times out of ten the port map points at the wrong private address, or the control's gateway field is still set to the old router. Check both before you change anything else.

A second common failure is a connection that opens and then drops after a few seconds. This usually means the protocol needs more than one port. FTP, for example, uses port 21 for control and a separate data port. If you only mapped 21, the directory listing will fail. Switch the control to passive mode and map the passive port range as well.

Slow transfers on large programs point at duplex mismatch. Set both the control NIC and the switch port to the same speed and duplex, preferably 100 Mbps full duplex for older controls. Auto-negotiation on a 1 Gbps switch often fails with a 10-year-old controller.

If a machine drops off the network after a power cycle, check whether it is set to DHCP. Many controls default to DHCP and pick up a different address after a reboot, which breaks the port map. Set a static address on every machine you map.

  • 1
    Unreachable from outsideWrong private IP in the port map, or wrong gateway on the control.
  • 2
    Connection dropsSecond data port not mapped; switch to passive FTP.
  • 3
    Slow transfersDuplex mismatch; pin both ends to 100 Mbps full duplex.
  • 4
    Address changes after rebootDHCP still enabled; set a static address.
Security

Keeping the shop floor secure while NAT is open

Every port map is a small opening. Keep the list short. If a machine only needs to send programs to a server, it does not need an inbound map at all; outbound connections from the control are enough. Inbound maps should exist only where a server or engineer must initiate the connection.

Use a separate VLAN for the machine network. Traffic between the machine VLAN and the office VLAN should pass through the firewall with explicit rules. This keeps a compromised office laptop from scanning the shop floor directly.

Change default passwords on the NAT router and on any control that supports password protection. Many controls ship with no password at all. At minimum, restrict who can reach the network settings menu.

Keep a log of port maps with an expiry date for temporary ones. A map opened for a two-hour vendor session should be removed the same day. In our own plants we review the map list monthly against the machine inventory.

  • 1
    Prefer outboundIf the control can push data out, no inbound map is needed.
  • 2
    Separate VLANMachine traffic crosses the firewall, not a flat LAN.
  • 3
    Change defaultsRouter and control passwords, every time.
  • 4
    Expire temporary mapsVendor access should not outlive the session.
Implementation

Step by step: reaching NAT networks by CNC machine tools

Follow the order. Skipping the backup step is the most common cause of a lost afternoon.

  • 1
    Back up the gateway configurationExport the current config to a file and store it off the device. If the router supports it, save a second copy on a laptop. This takes two minutes and saves hours if a setting goes wrong.
  • 2
    Set the private address on each controlEnter the IP, subnet mask 255.255.255.0, and the NAT router address as gateway. On Fanuc controls this is under Settings > Network. On Siemens 840D it is in the HMI network menu. Reboot the control after the change.
  • 3
    Verify local reachabilityFrom a laptop on the same subnet, ping each control. Expect replies under 5 ms on a wired shop network. If a ping fails, check the cable, the switch port, and the control's network enable setting before touching the router.
  • 4
    Create port maps on the NAT routerMap only the ports the control uses. Typical values: 502 for Modbus TCP, 8193 for Fanuc FOCAS, 4840 for OPC UA, 21 for FTP. Use a different external port per machine if you only have one public IP, for example 15021 to 10.10.0.11:21.
  • 5
    Restrict source addressesIf the router supports it, limit each port map to the specific server or engineering workstation that needs access. A port map open to 0.0.0.0/0 is an open door. This single setting removes most of the risk.
  • 6
    Test from outside the shop subnetFrom the monitoring server or the engineering VLAN, connect to the control using the public address and mapped port. Confirm you can read a program directory before you try a full transfer.
  • 7
    Document and labelRecord the private IP, public port, protocol, and machine serial in a spreadsheet. Label the switch port. The next person to touch this network will thank you.
Decision table

Which access method fits which machine

Match the method to the control age and the data you need to move.

Machine situationRecommended methodPorts to mapWatch out for
Modern control, OPC UA capableDirect port map to OPC UA4840Certificate setup on both ends
Fanuc with FOCAS libraryPort map to FOCAS8193Client library version must match control
Older control, FTP onlyPassive FTP with mapped range21 plus passive rangeActive mode fails behind NAT
Modbus TCP monitoringPort map to Modbus TCP502Register map differs per control model
Remote support from vendorTemporary port map, disabled afterVendor-specifiedLeaving the map open after the session
Full plant monitoringVPN plus internal routingVPN port onlyVPN concentrator becomes single point
FAQs

Questions engineers ask about CNC NAT setup

Can I reach NAT networks by CNC machine tools without a VPN?

Yes, if you map specific ports on the NAT router and restrict the source addresses that can use them. This works well for a monitoring server on a known IP.

A VPN is the better choice when many users or many machines are involved, or when you need access from outside the plant. The VPN adds one more port to manage but removes the need for a long list of individual maps.

Do I need a public IP for every CNC machine?

No. That is the point of NAT. One public address can serve many controls through port mapping.

The practical limit depends on the router and the number of ports you can map. A single public IP with 20 to 30 mapped machines is common in small plants.

Why does my control lose its address after a reboot?

DHCP is still enabled. Many controls default to DHCP and receive a new address that does not match the existing port map.

Set a static address on every machine you map, and reserve that address in the router so nothing else can take it.

Which ports should I open for Fanuc and Siemens controls?

Fanuc FOCAS typically uses 8193. Siemens 840D often uses 102 for S7 communication and 4840 if OPC UA is enabled.

Always confirm against the control manual for your specific model and firmware. Opening a port that the control does not use adds risk without adding function.

Is it safe to leave a port map open all the time?

It is acceptable if the map is limited to a specific source address and the control has a password. It is not acceptable if the map is open to any source.

For temporary access, create the map, use it, and remove it the same day. A monthly review of the map list catches anything left behind.

Can GreatLight help with machined parts for network hardware?

Yes. We machine enclosures, brackets, heat sinks, and connector housings for networking and industrial equipment. Tolerances run to ±0.005 mm and finishes from Ra 0.2–0.8 μm on request.

Upload a drawing and we return a quotation with a free DFM analysis within 12 hours. Production can start within 24 hours, and parts ship in 3–5 days.

Need machined housings or brackets for your network hardware?

Send us the drawing and we return a quotation with DFM feedback within 12 hours. Tolerances to ±0.005 mm, 100% inspection before shipment.

12-hour quote100% inspectionNo minimum order quantity

Follow us

More from the shop floor

We publish setup notes, tooling trials and inspection data from the factory floor.

FacebookTikTokYouTubeLinkedInInstagramThreadsPinterest

Trusted by engineers and manufacturers worldwide

Tesla Ford Motor Company BYD Auto Denso Magna International Boeing Airbus Medtronic KUKA FANUC