Heidenhain codes
HeidenhainParameterIntermediate30-120 minutes

130-07E3

HEIDENHAIN 130-07E3 - Non-secure connection detected from

Non-secure connection detected from

An LSV2 connection to the control was established without encryption. For improved IT security, LSV2 now requires an SSH tunnel by default, and plain connections are deprecated and may be removed in future software versions.

Root Cause Summary

The TNC control detected an incoming network connection using an insecure/unencrypted protocol that does not meet the security policy configured in the control. This is a security protection feature to prevent unauthorized or vulnerable connections. The alarm identifies both the connection type (%1) and originating address (%2) for security auditing.

Safety

  • Refer to Heidenhain service manual
  • Ensure qualified technician performs repairs

Causes and Fixes

  1. 1

    Identify connection source

    Note the %2 parameter in the alarm message which shows the source IP address attempting the connection. Verify this is an authorized device on your network.

    The alarm remains in the error log for security audit purposes even after acknowledgment - useful for tracking unauthorized access attempts

  2. 2

    Update browser/application connection

    Change the connection URL from http://[control-ip] to https://[control-ip]. Update any bookmarks, DNC configurations, or automated scripts to use the secure protocol.

    Modern browsers may cache the HTTP connection attempt - clear browser cache or use Ctrl+Shift+R to force refresh

  3. 3

    Verify security settings

    Access MOD function (if not locked) > Network Settings > Security. Check the setting 'Enforce secure connections' and verify if this aligns with your shop requirements.

    Modifying security settings requires appropriate access rights and may be password protected by machine tool builder

  4. 4

    Accept security certificate

    If using HTTPS for first time, the browser will prompt about self-signed certificate. Accept and add exception to allow the TNC's certificate for secure communication.

    The TNC uses a self-signed certificate by default. For production environments, consider installing a proper SSL certificate via MOD > Certificate Management

DIY Feasiblehigh confidence

Call a technician if:

  • ·SSH tunnel configuration fails repeatedly
  • ·Critical production systems cannot establish secure connections
  • ·Network security modifications required

Prevention

  • Regularly audit all LSV2 connections for security compliance
  • Plan migration to secure protocols before allowUnsecureLsv2 deprecation
  • Implement network monitoring for unauthorized connection attempts
  • Maintain inventory of all systems accessing TNC via LSV2

Common Mistakes

  • Permanently disabling security features for convenience
  • Ignoring the deprecation warning for future NC software versions
  • Not coordinating with IT/OT teams for network security changes
  • Failing to test secure connections before disabling unsecure access

Seeing Multiple Alarms?

Seeing another alarm with this one? Enter the code.

Get machine-aware diagnosis

AxisMD logs alarms against your actual machines, tracks patterns, and gives AI context your manual doesn't have.

Start free

Was this guide helpful?

Always verify with your machine manual or a certified technician before performing service procedures.