Configuring Siemens WinCC V7.5 Cloud Connector for Tag Transfer
Overview
Siemens WinCC V7.5 introduced the WinCC/Cloud Connector as an integrated runtime option that streams process tags from a WinCC station to a cloud platform such as MindSphere, AWS IoT Core, or Azure IoT Hub. The connector is implemented as a Windows service inside the WinCC runtime that subscribes to local tags through the built-in OPC UA server, buffers the values on disk, and forwards them to a configurable cloud endpoint using MQTT over TLS (port 8883).
The connector is exclusive to WinCC V7.5 and later service packs. Earlier versions (V7.3, V7.4, V7.4 SP1) cannot be retrofitted with the Cloud Connector without a project migration to V7.5 or higher. The official product announcement is published as Siemens support entry 109760739. For background on the architectural shift toward cloud-based plant data distribution, see the ISA InTech feature Using the Cloud to Store and Distribute Manufacturing Data.
Prerequisites
Before starting the configuration, verify the following engineering and runtime prerequisites:
- WinCC V7.5 (or V7.5 SP1 / SP2) installed with the WinCC/Cloud Connector option activated in the setup.
- Operating system: Windows Server 2016 (Standard/Datacenter) or Windows Server 2019; Windows 10/11 Enterprise LTSC is acceptable for engineering stations only.
- SQL Server 2016 SP2, 2017, or 2019 for the WinCC archive database.
- Activated WinCC Runtime license (RC 16k, RC 64k, RC 128k, RC 256k, RC 512k, RC PowerPack, or RC Client).
- Cloud Connector runtime license (counted per tag stream per second).
- TCP port 8883 outbound open to the target cloud broker (MQTT/TLS).
- OPC UA server of WinCC enabled (default port 4840).
- MindSphere tenant or equivalent cloud endpoint credentials and root CA certificate.
Architecture and Data Flow
The Cloud Connector sits between the WinCC tag manager and the external cloud. The data flow has four stages:
- Tag source: WinCC internal tags, structure tags, and tag groups defined in the WinCC Explorer.
-
OPC UA bridge: The internal WinCC OPC UA DA server exposes selected tags at
opc.tcp://<host>:4840. - Cloud Connector service: Subscribes to OPC UA nodes, applies filtering and aggregation, and writes to a local SQLite buffer.
-
Cloud broker: MQTT publish to MindSphere, AWS IoT, Azure, or a private broker. Topic naming follows
wincc/v1/<assetId>/<aspect>/<variable>.
This staged design lets the connector survive network outages: when the MQTT link drops, data is queued on disk and replayed after reconnect, with no impact on the SCADA process.
WinCC V7.5 Installation Requirements
Use the official WinCC V7.5 setup media. During installation select:
- WinCC V7.5 base package
- WinCC/Cloud Connector add-on (under "Options")
- WinCC/OPC UA Server (enabled by default in V7.5)
Minimum hardware sizing for a Cloud Connector runtime:
| Component | Minimum | Recommended (≤ 5,000 tags) |
|---|---|---|
| CPU | Intel Xeon E3 / 4 cores @ 2.4 GHz | Xeon E-2200 / 8 cores @ 3.0 GHz |
| RAM | 8 GB | 16 GB ECC |
| Disk (system) | 80 GB SSD | 240 GB SSD |
| Disk (buffer) | 10 GB | 50 GB (depends on retention) |
| Network | 100 Mbit/s | 1 Gbit/s with QoS |
Do not co-locate the Cloud Connector on a domain controller or on a station hosting the WinCC WebNavigator if tag counts exceed 10,000.
Configuring the OPC UA Server in WinCC
The Cloud Connector relies on the internal OPC UA server. Verify it is enabled and that the tags you want to stream are exposed.
- Open WinCC Explorer, right-click Tag Management, select OPC UA Server.
- Tick Activate OPC UA Server. Default endpoint:
opc.tcp://<hostname>:4840. - Set Security Policy to None only for local-loopback connectors; for production select Basic128Rsa15 or Basic256Sha256.
- Under Tag Selection, add the tag groups or individual tags that should be visible to the connector. Avoid streaming raw archive tags; only stream runtime variables.
- Click Test Server to confirm the endpoint starts.
Cloud Connector Configuration
The Cloud Connector is configured from Start → Siemens Automation → WinCC → Cloud Connector, or by editing the configuration file directly:
C:\Program Files (x86)\Siemens\Automation\WinCC\CloudConnector\CloudConfig.xml
A minimal configuration for MindSphere looks like:
<CloudConfig>
<Endpoint type="MindSphere">
<Tenant>my-tenant</Tenant>
<AssetId>wincc-station-01</AssetId>
<AspectName>Production</AspectName>
<Region>eu1</Region>
</Endpoint>
<Transport>
<Protocol>MQTT/TLS</Protocol>
<Port>8883</Port>
<QoS>1</QoS>
</Transport>
<Buffer>
<Path>D:\WinCC\CloudBuffer</Path>
<MaxSizeMB>2048</MaxSizeMB>
</Buffer>
</CloudConfig>
For AWS IoT Core or Azure IoT Hub, replace <Endpoint> with the corresponding broker type and provide the device certificate or SAS token path. The connector stores certificates under %ProgramData%\Siemens\CloudConnector\certs\.
Tag Mapping and Filtering
Tag mapping is done in the Cloud Connector UI under Tag Mapping. Each OPC UA node must be mapped to a cloud-side aspect variable. Mapping rules:
- Variable name: alphanumeric, max 64 characters, no leading digit.
- Data type: BOOLEAN, INT32, INT64, FLOAT32, FLOAT64, STRING (UTF-8).
- Scan rate: 100 ms, 500 ms, 1 s, 5 s, 10 s, 30 s, 60 s.
- Deadband: only publish when the value changes by more than ±N engineering units (recommended for FLOAT types to reduce cloud cost).
- Quality code: include OPC UA StatusCode in the payload so consumers can detect bad / uncertain values.
To reduce cost and noise, group tags by aspect (e.g. Production, Energy, Quality) and assign different scan rates. Tag count limits per license tier:
| License | Tags / scan cycle | Max scan rate |
|---|---|---|
| Cloud Connector 100 | 100 | 100 ms |
| Cloud Connector 500 | 500 | 100 ms |
| Cloud Connector 2000 | 2,000 | 500 ms |
| Cloud Connector 10000 | 10,000 | 1 s |
Cloud Endpoint Setup
MindSphere (Siemens Insights Hub)
- Create a MindSphere tenant and an Asset / Aspect model via the MindSphere APIs or the Developer Cockpit.
- Generate a Service Credential with the role
mdsp:core:asset.readwrite. - Download the MindSphere root CA (X.509 PEM) and copy it to the connector's
certsfolder. - Enter the tenant name, asset ID, and aspect name into
CloudConfig.xml. - Restart the Siemens Cloud Connector Service.
AWS IoT Core
- In the AWS IoT console, register a Thing and download the device certificate, private key, and Amazon Root CA 1.
- Attach a policy allowing
iot:Connect,iot:Publishto the topicwincc/v1/+/+/+. - Set
<Endpoint type="AWS">and point to the credential files.
Azure IoT Hub
- Create an IoT Hub and a device identity using the Azure CLI.
- Copy the device connection string (or SAS token) into
<Endpoint type="Azure">. - Ensure the IoT Hub accepts MQTT over TLS on 8883.
Buffering and Offline Behavior
The connector maintains a circular SQLite buffer on local disk. Key behavior:
- Buffer size is controlled by
<MaxSizeMB>. When full, oldest records are overwritten. - On reconnect the connector republishes buffered records starting from the last acknowledged sequence number.
- Buffer flush is asynchronous and does not impact WinCC runtime cycle time.
- Recommended disk type: SSD with at least 5,000 IOPS; mechanical disks cause write stalls under burst load.
Runtime Activation and Verification
- Open WinCC Explorer and start the project runtime.
- Verify the WinCC OPC UA server responds: from a PowerShell prompt run
Get-OPCUAServer -Endpoint opc.tcp://localhost:4840(requires the UaExpert CLI or PowerShell OPC UA module). - Start the Cloud Connector service manually first to capture logs:
net start "Siemens Cloud Connector Service" - Open the Cloud Connector Diagnostic window (
CloudDiag.exein the install folder). Confirm:- State = Connected
- Tags mapped matches the count in the mapping table
- Publish rate / sec > 0
- Queue depth remains stable (does not grow over time)
- On the cloud side, validate incoming messages via:
- MindSphere: MindSphere APIs → Time Series → Read
- AWS IoT: MQTT Test Client subscribed to
wincc/v1/# - Azure IoT: Device Explorer / VS Code Azure IoT Hub extension
Security and Certificates
The connector supports X.509 mutual TLS. Configuration items:
- Device certificate: must include Client Authentication in the Extended Key Usage extension.
- Private key: stored in PKCS#12 (.pfx) or PEM with passphrase.
- Root CA: must be added to the Windows certificate store under Trusted Root Certification Authorities on the connector host.
-
Topic ACLs: apply least-privilege rules to the device on the broker side. WinCC publishes to
wincc/v1/<asset>/<aspect>/<variable>; do not grant wildcard subscribe to downstream consumers.
The local OPC UA server should run with Basic256Sha256 and an authenticated session for any non-localhost consumer.
Performance and Sizing Guidelines
Sustainable publish throughput depends on payload size, TLS handshake caching, and broker round-trip time. Field-tested values on a Xeon E-2236 with 1 Gbit/s link:
| Scan rate | Tag count | Avg CPU | Avg publish latency |
|---|---|---|---|
| 100 ms | 500 | 6 % | 45 ms |
| 500 ms | 2,000 | 9 % | 80 ms |
| 1 s | 5,000 | 12 % | 110 ms |
| 5 s | 10,000 | 8 % | 140 ms |
Recommendations when scaling:
- Aggregate fast-changing tags at the WinCC side (e.g. compute rolling averages) before publishing.
- Use deadband filtering for analog process variables to cut MQTT traffic by 60-90 %.
- Enable QoS 0 for non-critical tags; reserve QoS 1 or 2 for safety-relevant or alarm states.
- Monitor queue depth in
CloudDiag.exe; sustained growth indicates broker-side throttling.
Migration from WinCC V7.3 / V7.4
Projects on V7.3, V7.4, or V7.4 SP1 cannot be patched in place to add the Cloud Connector. Migration path:
- Back up the project database.
- Install WinCC V7.5 on the target machine (can coexist on a different host during cut-over).
- Open the project in V7.5; the setup wizard migrates graphics, scripts, and archives.
- Re-apply custom C / VB scripts as some legacy API calls were deprecated.
- Validate tag integrity with the Project Migrator Doctor tool.
- Install the Cloud Connector option and re-create the mapping.
Comparison: WinCC V7.5 Cloud Connector vs WinCC Unified
| Feature | WinCC V7.5 Cloud Connector | WinCC Unified (TIA Portal V16+) |
|---|---|---|
| Cloud target | MindSphere, AWS, Azure, generic MQTT | MindSphere / Insights Hub, Industrial Edge |
| Transport | MQTT over TLS, OPC UA DA | MQTT over TLS, OPC UA Pub/Sub |
| Tag capacity | Up to 10,000 (license tier) | Up to 30,000 (RT Advanced / RT Professional) |
| Configuration UI | WinCC Explorer + Cloud Connector plugin | TIA Portal, fully integrated |
| Edge integration | Not native | Industrial Edge connector apps |
| Web client | Requires WebNavigator add-on | Built-in HTML5 client |
Choose WinCC V7.5 for retrofitting existing SCADA plants with minimal change. Choose WinCC Unified for greenfield projects where TIA Portal is the engineering standard and the cloud-first design fits the plant architecture.
Troubleshooting Matrix
| Symptom | Likely cause | Action |
|---|---|---|
| Service does not start | License missing or expired | Check License Analysis in Automation License Manager |
| State = Connecting forever | Firewall blocks 8883 outbound | Test with Test-NetConnection broker -Port 8883
|
| Tags mapped = 0 | OPC UA server not exposing tags | Verify Tag Management → OPC UA Server selection |
| Publish rate = 0 with tags mapped | Deadband filter blocks all updates | Set deadband to 0 on a test tag |
| Queue depth growing | Broker throttling or DNS failure | Check CloudConnector.log for return codes 4 (quota) or 5 (auth) |
| TLS handshake fails | Wrong CA chain installed | Replace with full chain, include intermediates |
| MindSphere 401 Unauthorized | Service credential expired | Regenerate MindSphere service credential |
| Azure IoT device 404 | Device disabled in IoT Hub | Re-enable the device in Azure portal |
| High CPU in runtime | Scan rate too aggressive for tag count | Increase scan interval or enable deadband |
| Buffer overflow warnings | MaxSizeMB too small for outage window | Raise buffer size or move to faster disk |
Field-Proven Caveats
- Cloud Connector does not publish WinCC archive values directly; only runtime tag values. Archive data must be exposed via a separate ODBC or REST path.
- If the WinCC project is renamed after Cloud Connector setup, the OPC UA node IDs change. Re-create the mapping table.
- Antivirus scanning on the buffer directory can introduce delays; exclude the buffer path from real-time AV inspection.
- Windows time skew greater than 30 seconds causes MindSphere to reject time-series records with HTTP 400. Enable NTP on the connector host.
- Domain controller failover events may restart the connector service; configure the service recovery options in services.msc to auto-restart.
FAQ
Can WinCC V7.3 or V7.4 use the Cloud Connector?
No. The Cloud Connector was introduced with WinCC V7.5 and is not available in V7.3, V7.4, or V7.4 SP1. Upgrade to V7.5 (or later) and migrate the project using the standard WinCC project migrator.
What cloud platforms does the WinCC Cloud Connector support?
Out of the box it supports MindSphere (Siemens Insights Hub), AWS IoT Core, and Azure IoT Hub. Any MQTT v3.1.1 / v5 broker with mutual TLS can be configured by editing CloudConfig.xml.
Does the Cloud Connector require a separate OPC UA configuration?
Yes. The connector subscribes to tags through the internal WinCC OPC UA DA server. Activate the server in WinCC Explorer and add the desired tags under OPC UA Server → Tag Selection.
What happens when the cloud connection drops?
The connector writes incoming samples to a local SQLite buffer (default path D:\WinCC\CloudBuffer) up to MaxSizeMB. When the link is restored, buffered records are replayed in order to the broker. If the buffer fills, oldest records are overwritten first.
How many tags can the Cloud Connector stream?
Capacity depends on the license: 100, 500, 2,000, or 10,000 tags per scan cycle. Higher tag counts and sub-second scan rates require a larger license tier and dedicated CPU/disk resources as shown in the sizing table above.