When importing an autonomous forklift or AGV fleet from China, warehouse IT teams often want to know exactly how the central control system communicates with vehicles, servers and external networks.
The important question is not simply whether the system uses a "cloud protocol." Different Chinese AGV suppliers may deploy fleet control software on a local server, a private cloud, a supplier-hosted cloud platform, or a hybrid architecture.
For an enterprise IT team, the more important questions are:
Where does the AGV data go? What connections are required? Can outbound traffic be blocked? And who controls remote maintenance access?
There is no single cloud protocol used by all Chinese AGV manufacturers.
A fleet control system may use standard enterprise networking technologies such as TCP/IP, HTTPS/TLS, WebSocket or MQTT, depending on the software architecture and the functions being implemented.
Some systems may also use:
REST APIs
Industrial Ethernet
TCP or UDP communication
Web-based management interfaces
Database connections
VPN tunnels for remote support
Message-based communication between fleet components
The exact protocol should be confirmed from the supplier's network architecture rather than inferred from the country where the AGV was manufactured.
Either architecture is possible.
The fleet management and scheduling software can run on infrastructure controlled by the warehouse operator.
This architecture can make network isolation, firewall rules, backup policies and access control easier to manage from an enterprise IT perspective.
Fleet data or selected operational information may be processed by infrastructure hosted by the supplier or a third-party cloud provider.
In this case, the buyer should understand where the servers are located, what information is transmitted and which external services are required.
Critical fleet control can remain on a local server while selected functions, such as remote diagnostics, software updates or reporting, use an external connection.
Do not assume that an AGV manufactured in China must use AWS, Alibaba Cloud, or a server located in China. Require the supplier to provide the actual deployment architecture for the quoted system.
Before approving an AGV fleet on an enterprise network, the IT team should identify every category of information that can leave the local environment.
Depending on the system, this may include:
Vehicle status
Battery status
Fault codes
Navigation information
Fleet statistics
Task history
Warehouse map information
Software version information
Remote diagnostic information
System logs
The exact data set varies by supplier and software version. The buyer should request a documented data-flow diagram rather than relying on a general statement such as "the system is secure."
Potentially, but blocking traffic by country or IP address should only be done after the complete network architecture has been identified.
A typical local AGV deployment may contain several different communication paths:
AGV-to-Wi-Fi communication
AGV-to-fleet-server communication
Fleet server-to-WMS communication
Fleet server-to-database communication
Remote maintenance connection
Software update connection
License or activation services
Optional cloud reporting services
The first five may be entirely local, while remote maintenance or software licensing may require external connectivity.
The correct test is not "Can I block China?"
The correct test is "What exact destinations, ports and protocols are required for each AGV function?"
It depends on the software architecture.
If the fleet scheduler, AGV communication, maps and operational database are deployed locally, the vehicles may be capable of normal warehouse operation without continuous Internet access.
However, Internet access may still be required for certain optional or administrative functions, such as:
Remote technical support
Cloud monitoring
Software downloads
License verification
Remote diagnostics
Cloud-based reporting
Therefore, the buyer should test the system under an intentionally restricted network configuration before production deployment.
Remote maintenance should be treated as a separate security function from normal AGV fleet communication.
Depending on the implementation, secure remote access may use technologies such as:
TLS-encrypted connections
VPN tunnels
SSH-based administration
Certificate-based authentication
Multi-factor authentication
Role-based access controls
The exact implementation must be confirmed with the supplier. Simply stating that a remote connection is "encrypted" does not tell the IT team which protocol, authentication method, certificate model or access-control mechanism is actually being used.
Ask whether remote access is always enabled, manually enabled, time-limited, approval-based or disabled by default.
This depends entirely on the system configuration and the contract.
A secure deployment should make the remote-access mechanism visible to the customer's IT team.
Procurement documents should clarify:
Who can initiate remote access
Whether customer approval is required
How user accounts are authenticated
How access is logged
How long logs are retained
Whether access can be disabled locally
What systems the remote engineer can access
Whether file transfer is permitted
For enterprise deployments, remote support should ideally be controlled through a defined access procedure rather than through an undocumented permanent connection.
Some software products may use hardware-based licensing, while others may use software licenses, license servers, activation codes or other mechanisms.
If a physical dongle is required, clarify:
Whether the dongle is required for normal operation
Whether it is required only for engineering functions
Whether a replacement can be obtained locally
What happens if the dongle is damaged
Whether the software can operate without Internet access
Whether the license is transferable to replacement hardware
This is particularly important when the fleet server is located inside a customer's secured IT environment and cannot easily be replaced or connected to an external licensing service.
A network security review should be performed before the AGV fleet is connected to the production warehouse network.
Identify AGVs, access points, fleet servers, databases, engineering computers, WMS interfaces and external connections.
Record destination domains or IP addresses, ports, protocols, connection frequency and the purpose of each connection.
Disconnect external Internet access and verify whether normal AGV navigation, fleet scheduling and WMS task execution continue to operate.
Confirm exactly how remote support is initiated, authenticated, authorized and terminated.
Verify that important authentication, remote-access and system events can be recorded and reviewed by authorized personnel.
Network architecture should be included in the technical RFQ, not discussed only after the equipment arrives.
| RFQ Requirement | Information to Request |
|---|---|
| Network Architecture | AGV, Wi-Fi, fleet server, database and external connection topology |
| Communication Protocols | Protocols, ports and interfaces used by each system component |
| External Destinations | Required domains, IP addresses and cloud services |
| Remote Maintenance | Authentication, encryption, approval and logging mechanism |
| Offline Operation | Functions that remain operational without Internet access |
| Software Licensing | Dongle, activation, license server or subscription requirements |
| Data Ownership | Data storage location, retention, export and deletion procedures |
For enterprise warehouse deployments, network segmentation is often more practical than simply allowing the AGV fleet to share the same network as office computers and business applications.
A segmented architecture can separate:
AGV wireless traffic
Fleet management servers
WMS or ERP interfaces
Engineering and maintenance computers
Corporate IT systems
External remote-support connections
Firewall rules can then be based on the actual communication requirements of the system rather than broad assumptions about the manufacturer's country of origin.
Before connecting an imported AGV fleet to the warehouse network, confirm these seven points:
Where the fleet control software is hosted
Which protocols and ports are required
Which external destinations are required
What data leaves the local network
Whether the fleet operates normally without Internet access
How remote maintenance is authenticated and controlled
How software licensing works if external access is unavailable
The strongest approach is to obtain the supplier's network architecture before purchase, reproduce the proposed configuration in a controlled test environment, and verify the offline and restricted-network behavior before the AGVs enter production.
For a U.S. warehouse, this turns the question of "Is Chinese AGV software secure?" into a much more useful engineering question: What connections exist, what data moves through them, who controls those connections, and can the fleet continue operating when external access is restricted?
📖 AGV Forklift Guide — Essential manual for selection and safety.
⚙️ How AGV Systems Work — A deep dive into navigation and logic.
⚖️ AGV vs. AMR Comparison — Choosing the right technology for your facility.
💰 AGV Cost and ROI — Evaluating investment and payback periods.