EtherNet/IP and CIP Explained: Explicit and Implicit Messaging, RPI, EDS Files and DLR

On this page

EtherNet/IP (“Ethernet Industrial Protocol”) applies the Common Industrial Protocol (CIP) to standard Ethernet and TCP/IP. It is managed by ODVA and is widely used with Rockwell Automation (Allen-Bradley) controllers, as well as by many robot, drive, valve and I/O manufacturers, particularly in North America.

EtherNet/IP and CIP Explained: Scanner & adapter, Implicit messaging, Explicit messaging, EDS files & keying, DLR rings, CIP Safety & Motion
EtherNet/IP carries the Common Industrial Protocol over standard Ethernet.

This guide explains how EtherNet/IP communicates, how connections are configured, and what causes most field problems.

CIP: the common layer

CIP is an object-oriented application protocol. Devices are modelled as collections of objects (identity, assemblies, parameters, connection manager) with attributes and services. The same CIP application layer runs over several networks:

Network Physical layer
EtherNet/IP Standard Ethernet, TCP/IP and UDP/IP
DeviceNet CAN-based fieldbus
ControlNet Coaxial/fibre scheduled network
CompoNet Bit-level device network

Because the application layer is the same, devices and routing between these networks behave consistently, which helps when migrating older DeviceNet or ControlNet systems.

Roles: scanners and adapters

Role Also called Example
Scanner Originator PLC that opens connections to devices
Adapter Target Remote I/O, drive, valve manifold

A device can be both, for example a PLC that exchanges data with another PLC.

Explicit vs implicit messaging

Type Transport Use Characteristics
Explicit messaging TCP (port 44818) Configuration, diagnostics, occasional reads/writes, HMI and SCADA access Request/response; not time-critical
Implicit (I/O) messaging UDP (port 2222) Cyclic real-time I/O data Connection-based; produced at a set interval without requests

Implicit messaging uses CIP connections established by the scanner (with a Forward Open request over TCP). Once established, data flows cyclically in both directions.

EtherNet/IP Explicit vs Implicit Messaging: Explicit (Request/response (TCP), Configuration, diagnostics); Implicit (I/O) (Cyclic at the RPI (UDP), Scanner to adapter)
Connection timeouts are a multiple of the RPI.

RPI and connection timeouts

  • The RPI (requested packet interval) defines how often data is produced on a connection, for example 5 ms, 10 ms or 50 ms.
  • If no data arrives within the timeout (RPI × a timeout multiplier), the connection faults and devices go to their configured fault state.
  • Set RPIs according to application needs: faster RPIs increase network and device load. Many devices also have limits on how fast and how many connections they support.

Connection types

Connection Purpose
Exclusive owner The scanner that controls the device’s outputs
Input only Another scanner receives inputs without controlling outputs
Listen only Receives inputs, but only while an owner connection exists

Unicast and multicast

Implicit data from an adapter can be sent multicast (useful when several scanners consume the same data) or unicast (to one scanner). Multicast without proper switch configuration floods the network:

  • Use managed switches with IGMP snooping and an IGMP querier when multicast is used.
  • Prefer unicast where only one consumer needs the data; modern configurations often default to it.

See Industrial Network Design for OT Engineers.

EDS files and electronic keying

  • An EDS (Electronic Data Sheet) describes a device’s identity, parameters and connection options for the engineering tool.
  • Many controllers use Add-On Profiles or similar vendor mechanisms for richer integration.
  • Electronic keying checks that the connected device matches the configured one (vendor, product type, product code, major/minor revision). Choosing “exact match” prevents accidental use of a different device; “compatible module” allows compatible replacements; disabling keying should be a conscious decision.

Device Level Ring (DLR)

DLR is ODVA’s ring redundancy technology for devices with two Ethernet ports and embedded switches. One device acts as the ring supervisor; if the ring breaks, traffic is redirected quickly. Only one active supervisor per ring (with backups configured as needed). Monitor ring status so a broken ring is repaired before a second fault occurs.

Safety, motion and security extensions

  • CIP Safety: safety communication over EtherNet/IP with certified devices and safety controllers. See Functional Safety.
  • CIP Motion: drive and motion control over EtherNet/IP, often using time synchronisation (CIP Sync, based on IEEE 1588).
  • CIP Security: adds device authentication, integrity and confidentiality using TLS and DTLS. Check which devices support it; combine it with network segmentation.

Troubleshooting

Symptom Likely causes Checks
Connection faults (timeouts) RPI too fast for device or network, network congestion, multicast flooding, cabling faults Device and switch diagnostics, RPI settings, IGMP configuration, port error counters
Connection rejected Electronic keying mismatch, wrong assembly instance or size, device already owned by another scanner Compare configuration with device identity and EDS; check other owners
Duplicate IP warnings Two devices or a laptop with the same IP IP register, device address switches, BOOTP/DHCP settings
Intermittent I/O drops on many devices Unmanaged switches with multicast, bad cables, EMC, overloaded switch Replace with managed switches, enable IGMP snooping, test cables
DLR fault Broken ring segment, two supervisors Ring diagnostics, supervisor configuration
HMI/SCADA slow but I/O fine Explicit messaging load, too many tags polled Optimise polling, reduce tag counts, use connected messaging where supported

Frequently asked questions

Is EtherNet/IP the same as Ethernet?

No. Ethernet is the physical and data link technology. EtherNet/IP is an industrial application protocol (CIP) that runs over standard Ethernet and TCP/IP, which is why it can share infrastructure with other Ethernet traffic when the network is designed correctly.

What ports does EtherNet/IP use?

TCP port 44818 for explicit messaging and UDP port 2222 for implicit I/O messaging, with the standard allowing additional ports for some features (for example TLS/DTLS for CIP Security).

What is RPI in EtherNet/IP?

The requested packet interval is the rate at which cyclic I/O data is produced on a connection. The connection faults if data is not received within the timeout, which is a multiple of the RPI.

Key takeaways

  • EtherNet/IP carries CIP over Ethernet: explicit messaging for configuration and diagnostics, implicit messaging for cyclic I/O.
  • RPI and connection timeouts define real-time behaviour; set them deliberately.
  • Multicast needs managed switches with IGMP snooping; use unicast where possible.
  • EDS files and electronic keying protect configuration consistency; DLR provides ring redundancy.

Before you apply this in a plant: this article is for education. Always check the current edition of the relevant standards, the manufacturer's documentation for your exact product and version, and your site's procedures. Safety-related work needs qualified personnel. See our editorial policy.

Written by Bhargava Reddy Kapireddy

Bhargava has 16 years of hands-on experience with MES, SCADA, DCS, PLC and industrial data systems across power generation, oil and gas, pharmaceuticals and process manufacturing. He founded MFG Tech Hub to share practical, vendor-neutral automation knowledge.

More about the author → How we write and review articles