Setting up an OPC UA client to an S7-1516-3 PN/DP, TIA V17, OPC UA server enabled on the CPU, endpoint opc. removed link From a laptop on the plant subnet UaExpert connects, browses, reads, no complaints.
From the KEPServerEX host on the office subnet, 10.10.2.40, the OPC UA Client driver gives BadConnectionClosed, and UaExpert on the same box says connection refused, straight away, no timeout.
I trusted the office box's certificate in the CPU as well, set the policy to None for a test and rebooted the CPU, same every time. IT says the office to plant rule is in place because Kepware already talks S7 to that CPU on port 102 from the same host. Is the CPU refusing anything that isn't on its own subnet? Or is 4840 a separate rule from 102 and IT have only ever done the one?
What does the CPU's certificate list say about the office client, trusted or rejected? An untrusted cert gets bounced fast too, might be that. And is the office host's cert the same one you trusted, or did Kepware make a new one when you changed the policy?