Skip to Main Content
Centre d’assistance Cognex
Logo

DataMan Setup Tool Connection Drops over WLAN due to Firewall Deep Packet Inspection

When connecting to Cognex DataMan scanners over WLAN, the DataMan Setup Tool may successfully discover the device but fail to establish an online configuration session. In the described case, the root cause was not an MTU mismatch or scanner firmware issue, but Deep Packet Inspection (DPI) performed by a firewall in the WLAN path, which terminated the TCP session.

20/01/2026

Details

Affected Products

  • Cognex DataMan, Ethernet connected
  • DataMan Setup Tool
  • WLAN-based network connections

Symptoms

  • Scanner is reachable via Ping over WLAN
  • Scanner is visible in DataMan Setup Tool discovery
  • Connection attempt fails when opening the online configuration
  • TCP session is reset shortly after initiation
  • Connection works reliably over wired LAN, but not over WLAN

 

Technical Background

Communication Overview

  • Discovery:
    • Protocol: UDP
    • Port: 1069
  • Configuration / Online connection:
    • Protocol: TCP
    • Default Port: 44444 (DM3xx series)

In the reported scenario:

  • MTU tests showed identical MTU values for LAN and WLAN.
  • ICMP traffic (Ping) was successful over both interfaces.
  • UDP discovery traffic was not blocked.
  • The TCP session on port 44444 was consistently reset during setup over WLAN.

 

Root Cause

A Check Point firewall was deployed between the client PC and the DataMan camera for WLAN traffic.

  • The firewall accepted the packets according to the security policy.
  • However, Deep Packet Inspection (DPI) dropped the connection.
  • Both client and camera received TCP packets with the RST flag.
  • These reset packets were generated by the firewall, not by the camera.


The firewall classified the traffic as invalid because:

  • The DataMan Setup Tool uses the HTTP method RESUME during the connection process.
  • According to RFC 9110 (HTTP/1.1 Semantics), the standardized HTTP methods are:
    • GET, HEAD, POST, PUT, DELETE, CONNECT, OPTIONS, TRACE
  • RESUME is not RFC-compliant, and therefore the firewall terminated the session during inspection.

This behavior made it appear as if the camera itself was rejecting the connection.
 

Resolution

The issue was resolved by excluding the DataMan communication port from Deep Packet Inspection:

  • DPI was disabled for traffic to the camera on:
    • TCP port 44444
  • After excluding this port from application-level inspection, the DataMan Setup Tool connections over WLAN worked reliably.

Recommendations

If DataMan scanners are reachable over WLAN but fail to connect in the Setup Tool:

  1. Verify basic connectivity:
    • Ping test
    • MTU consistency between LAN and WLAN
  2. Confirm discovery via UDP port 1069 works.
  3. Check whether a firewall, WLAN controller, or security appliance is present in the WLAN path.
  4. Inspect firewall logs for:
    • TCP resets
    • Application inspection / DPI drops

Exclude DataMan configuration ports (e.g. TCP 44444) from:

Deep Packet Inspection

Application-layer protocol enforcement


Additional Notes

  • No general issues are currently known with DataMan 3xx devices, WLAN, and current firmware versions.
  • If LAN connections work reliably while WLAN connections fail, the root cause is very likely network-side inspection or policy enforcement.

Ressources connexes