Factory Resetting Siemens KTP400 Basic 2nd Gen HMI via USB

David Krause12 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

Field engineers frequently attempt to restore a SIMATIC KTP400 Basic 2nd Generation panel to factory defaults using ProSave from TIA Portal V20 and conclude the panel is unreachable. Typical symptoms reported:

  • ProSave connects, the panel is listed, but Reset to Factory Settings either does not appear, is greyed out, or fails silently.
  • The HMI Image field reports an unknown version such as 17.00.00.02_01.01 22967.000 and refuses to continue.
  • The panel boots normally and answers ping 192.168.15.4 from a PC at 192.168.15.100, but no reset operation completes.
  • A TIA Portal V17 install DVD 3 is on hand but cannot be mounted because the engineering station is on TIA Portal V20.

Root cause: ProSave does not support a true factory reset on SIMATIC Basic Panels 2nd Generation. It only supports an OS update. Factory restore on this hardware class is performed exclusively through the panel's own USB recovery loader, with the HMI image supplied as a USB stick payload.

Hardware class matters. The factory-reset behaviour described here applies to KTP400 Basic, KTP700 Basic, KTP900 Basic, KTP1200 Basic and KP400 Basic 2nd Generation devices. Comfort, Mobile, and Unified Comfort panels use a different procedure (ProSave reset or TIA Portal "Reset to factory settings"). Do not apply the procedure below to a KTP1200 Comfort, TP700 Comfort, or MTP panel.

2. KTP400 Basic 2nd Generation Device Identification

Before any reset, confirm that the panel is in fact a Basic 2nd Generation device. The product is sold under several closely related MLFBs, and selecting the wrong one in ProSave is the single most common reason for the symptom in Section 1.

MLFB (6AV...) Designation Reset Tool
6AV2 123-2DB03-0AX0 KTP400 Basic mono PN USB Recovery
6AV2 123-2DC03-0AX0 KTP400 Basic Color PN USB Recovery
6AV2 123-2GB03-0AX0 KP400 Basic (key panel) USB Recovery
6AV2 124-1DC01-0AX0 KTP700 Basic Color PN (1st Gen) USB Recovery
6AV2 124-1DC01-0AX1 / ...-0AX2 KTP700 Basic 2nd Gen USB Recovery
6AV2 124-1GC01-0AX0 ... 0AX2 KTP900 Basic 2nd Gen USB Recovery
6AV2 124-1JC01-0AX0 ... 0AX2 KTP1200 Basic 2nd Gen USB Recovery

The MLFB is printed on the rating plate on the rear of the panel and is also returned by ProSave's Device > Read Diagnostics in the Identification tab. The trailing dash segment is critical: a panel marked ...-0AX0 is a 1st Generation Basic, while ...-0AX1 or ...-0AX2 indicates 2nd Generation. ProSave distinguishes "KTP400 Basic" and "KTP400 Basic Color PN" as separate device types, and a wrong selection will change the expected image size and fail the load.

3. Why ProSave Cannot Factory Reset Basic Panels 2nd Generation

ProSave's Reset to factory settings function targets the WinCC flexible / TIA HMI runtime and only operates on devices that expose a reset service over the configured channel (PN/PN-Ethernet or serial). The 2nd Generation Basic panel firmware does not implement this service. ProSave on this device class is therefore limited to:

  • OS Update — re-flash the runtime image from a local .img file.
  • Backup / Restore — push or pull a .psb / .par backup of recipe data and parameters.
  • License transfer — move runtime licenses to or from the panel.

It does not wipe user programs, transfer projects, or revert boot configuration. The only path that re-partitions the internal flash and reloads a clean image is the panel's own USB recovery loader, which boots before the operating system image and is independent of any installed runtime version.

4. Reset Method Comparison

Method Hardware Result Requires
ProSave "Reset to factory settings" Comfort, Mobile, Unified Full factory reset (no project, default IP) Network or serial, TIA Portal
ProSave OS Update Basic 2nd Gen Reflash runtime only — recipes / project remain Correct .img matching the panel variant
USB Recovery Mode Basic 2nd Gen Full factory reset (factory firmware restored) USB stick with matching image, panel bootloader
Control Panel > Service > Reset Some 1st Gen Basic Partial reset (project, IP only) Local operator input

5. Prerequisites

  1. USB stick, 1 GB to 32 GB, formatted FAT32 with default allocation unit size. NTFS and exFAT are not recognised by the recovery loader.
  2. HMI image package matching the panel variant. For a KTP400 Basic Color PN 2nd Generation loaded with image 17.00.00.02_01.01 22967.000, the matching package is the TIA Portal V17 / V18 / V19 / V20 "HMI Basic Images" bundle. Use the Siemens Industry Online Support entry search keyword "HMI Basic Images" and filter by device class.
  3. USB stick prepared with the HMI_PIU_installer workflow (see Section 7). The installer places the required image files at the root of the USB stick with the directory name expected by the bootloader (typically SIMATIC_HMI).
  4. 24 V DC supply rated for the panel (KTP400 Basic: 24 V DC, ~0.25 A typical, 1.0 A peak inrush during USB recovery).
  5. The engineering PC is not strictly required for USB recovery; once the USB stick is prepared, the recovery can be performed at the panel with no PC in the loop.
Power stability. A power loss during USB recovery can leave the panel in a non-bootable state. Use a UPS or a stable 24 V source. The bootloader will retry on next power-up, but a mid-write brownout may force a service replacement.

6. Pre-Reset Network and Configuration Check

If a PC is connected for diagnostics before the reset, document the following so the panel can be brought back online after recovery:

Parameter Typical Value (Example Site) Source
HMI IP address 192.168.15.4 Control Panel > Network > IP
HMI subnet mask 255.255.255.0 Control Panel > Network > Mask
HMI default gateway 192.168.15.1 Control Panel > Network > Gateway
HMI MAC 00-0E-8C-xx-xx-xx (label on rear) Rating plate
Engineering PC IP 192.168.15.100 Network adapter settings
ProSave device type KTP400 Basic (mono) or KTP400 Basic Color PN Verify against MLFB
Project name in panel From TIA Portal project tree ProSave Diagnostics > Project

Validate connectivity with ping -t 192.168.15.4 for at least 30 seconds. Drop count and RTT variance confirm link integrity before any reset activity.

7. Image Acquisition from TIA Portal V20

When the panel reports an image version unknown to ProSave, the correct image package is loaded from the TIA Portal installation media. The DVD 3 of older TIA versions is no longer needed; the installer can be downloaded.

  1. Open Siemens Industry Online Support and search for the entry titled "Image Downloads for SIMATIC HMI Operator Panels: Comfort / Mobile / Basic Panels".
  2. Locate section 1.1 "Installation via HMI_PIU_installer". Download the HMI_PIU_installer self-extracting archive.
  3. Run HMI_PIU_installer.exe on the engineering PC. Accept the license and the install path. The installer writes the matching image bundles into %ProgramData%\Siemens\Automation\HMI_PIU\Images\.
  4. For a KTP400 Basic Color PN, the relevant files are KTP400_Color_Basic_V17_xx.xx.xx.xx.img and the corresponding signature .sig pair.
  5. For section 1.2 "Manual download and installation", copy the .img / .sig pair into the SIMATIC_HMI\Images folder on the USB stick if a manual layout is preferred.

Cross-reference the file's internal version with the version string reported by ProSave or by the panel's Control Panel About dialog. The label format is xx.yy.zz.pp_qq.rr ddddd.ddd where the last decimal block is the panel-specific build number. Mismatched major versions will be rejected by the bootloader.

8. USB Recovery Mode Procedure (Factory Reset)

  1. Power down the KTP400 panel at the 24 V terminal.
  2. Insert the prepared USB stick into the panel's USB host port (X60 on the KTP400 Basic). The device port (X61) is not used for recovery.
  3. Press and hold the only available push-button on the rear of the panel (some variants use a touch sequence on the screen — see MLFB-specific note in Section 9).
  4. Apply 24 V DC power while the button is held.
  5. Release the button as soon as the recovery menu appears on screen (typically 5-10 s after power-up). The menu shows a list of .img files found on the USB stick.
  6. Use the touch interface to select the image matching the panel variant. The loader displays the target panel MLFB for confirmation; confirm only if it matches the device on the rating plate.
  7. Tap Update. The progress bar advances through "Format", "Erase", "Write", and "Verify" phases. Total time: 4-7 minutes for a KTP400 Basic Color PN.
  8. When the loader displays "Update completed successfully", tap Reboot and remove the USB stick.
  9. The panel boots into the factory-default Control Panel. Default IP is 0.0.0.0; the operator must re-enter the site IP, subnet mask, and gateway before any TIA Portal download.
Do not interrupt the write phase. Removing the USB stick, cycling power, or pressing the touch during "Erase" or "Write" bricks the panel's firmware partition and requires service. The recovery loader will not reflash on the next power-up without a valid image.

9. Variant-Specific Behaviour

The user observed that the panel is the KTP400 Basic Color PN 2nd Generation. The following details apply to this exact variant:

  • Display: 4.3" TFT, 480 x 272, 16M colours, single-touch analogue resistive.
  • Interfaces: 1 x PROFINET (X1), 1 x USB host (X60), 1 x USB device (X61), 1 x 24 V terminal.
  • Boot key: There is no physical button. The recovery loader is invoked by touching the four screen corners in sequence (top-left, top-right, bottom-right, bottom-left) within 2 s of power-up.
  • Image size: ~110 MB compressed, expanding to ~250 MB on the internal flash.
  • Default subnet mask after factory reset: 255.255.255.0; default port mode: PROFINET device.

If a panel is found that does not respond to the corner-touch sequence, the wrong device type has almost certainly been selected in a prior ProSave OS update, leaving the panel with a 1st Generation image. In that case, prepare the USB stick with the 2nd Generation image bundle and retry.

10. Verification After Reset

  1. Power cycle the panel. Expect a boot screen that displays the Siemens logo and the firmware version (e.g. 17.00.00.02_01.01 22967.000) for ~5 s.
  2. The Control Panel appears. Navigate to About > System and confirm:
    • Image version matches the prepared image.
    • Device name is blank (no project loaded).
    • License status is "Not licensed".
  3. Re-enter the site IP, subnet mask, and gateway under Control Panel > Network.
  4. From the engineering PC, run ping 192.168.15.4 -n 4. Expect 0% loss and RTT < 1 ms on a direct connection.
  5. In ProSave, select the correct device type, enter the panel IP, and click Read Diagnostics. The Identification tab must return the MLFB, the firmware version, and the serial number from the rating plate.
  6. Open TIA Portal V20, navigate to Online > Accessible Devices. The panel should appear as a participant with the assigned IP and PROFINET device name (default: empty).
  7. Transfer the project from the engineering station. A clean factory state is verified when the project loads without the warning "Existing project differs from configured project".

11. Troubleshooting Matrix

Symptom Likely Cause Action
ProSave "Reset to factory settings" is greyed out Basic Panel 2nd Gen detected — feature unsupported Switch to USB Recovery (Section 8)
ProSave reports unknown image version Image .img / .sig missing on PC Run HMI_PIU_installer to add the image
USB stick not detected during recovery NTFS / exFAT, or non-USB 2.0 stick Reformat as FAT32, retry
Recovery menu lists no images Image placed in wrong directory Copy into SIMATIC_HMI\Images
Update fails at "Erase" phase Image variant mismatch (mono vs Color, 1st vs 2nd Gen) Verify MLFB, re-download matching image
Panel does not boot after recovery Power interruption, partial flash Re-run USB Recovery with stable supply
Default IP unknown Factory IP is 0.0.0.0 on Basic Panels 2nd Gen Set IP locally on panel
Touch unresponsive in recovery menu Touch calibration corrupted Use a USB keyboard via X60 to navigate
Engineering PC cannot reach panel after recovery Subnet mismatch or PROFINET device name set Confirm IP/mask/gateway; clear PROFINET name if not used
ProSave shows "KTP400 Basic" instead of "KTP400 Basic Color PN" Wrong device class selected in dropdown Change to "KTP400 Basic Color PN", retry

12. Field Commissioning Notes

  • Project version compatibility. A panel reset to V17/V18 image will not load a TIA Portal V20 project that uses V20-only instructions. Match the runtime image version to the project's TIA source. If the TIA Portal on site is V20, use the V20 image package; do not attempt to install TIA V17 DVD 3 alongside V20.
  • Licensing. Runtime licenses are stored on the panel's internal flash. A factory reset erases them. Re-transfer licenses from the license certificate (CoL) using Automation License Manager before commissioning.
  • Recipe and parameter data. USB Recovery wipes the entire flash partition. Back up recipes with ProSave (Tools > Backup) before the reset, or pull the .psb via TIA Portal > Online > Backup before initiating recovery.
  • PROFINET device name. After reset the PROFINET name is empty. The controller's "Assign PROFINET device name" step must be repeated, or the controller will fail to establish AR (Application Relationship) on first download.
  • Time and date. The panel does not have a battery-backed RTC after a full reflash. Re-enter time and date on the Control Panel, or configure SNTP to a plant time server.
  • Auditing. For regulated sites, record the panel serial, the image version installed, the operator ID performing the reset, and the timestamp. USB Recovery leaves no log of its own; this is the only audit trail.
Safety. A factory reset does not affect connected I/O. If the panel is the operator interface for an active machine, place the machine in a safe state (e-stop, mode select to Manual/Service) before initiating USB Recovery, because the panel will reboot twice and lose its HMI tag connection for several minutes.

Can ProSave factory reset a Siemens KTP400 Basic 2nd Generation panel?

No. ProSave on the 2nd Generation Basic Panel family only supports an OS Update, not a factory reset. Use the panel's USB Recovery Mode to restore factory defaults.

How do I get the HMI image files for a panel that reports version 17.00.00.02_01.01?

Use the Siemens "HMI_PIU_installer" (Section 1.1 of the HMI Operator Panel Image Download entry) or download the matching .img / .sig pair manually (Section 1.2). The TIA Portal V20 installation does not bundle older DVD 3 content, so a fresh download from Industry Online Support is required.

What is the default IP address after a KTP400 Basic 2nd Gen factory reset?

The default IP is 0.0.0.0 with subnet mask 255.255.255.0. The site IP, gateway, and PROFINET device name must be re-entered on the Control Panel before any TIA Portal download.

Why does ProSave ask for "KTP400 Basic" vs "KTP400 Basic Color PN"?

ProSave distinguishes the mono and colour variants as separate device types because they use different firmware images. A KTP400 Basic Color PN (MLFB 6AV2 123-2DC03-0AX0) loaded with the wrong device class will fail the image upload with a size or signature error.

Can I keep my recipes when I factory reset the panel?

Yes, if you perform the recipe backup before the reset. Use ProSave Tools > Backup to write a .psb file, or TIA Portal > Online > Backup. After USB Recovery, restore the .psb to the panel. Note that the panel's flash is wiped during recovery, so a backup taken on the panel after recovery will not be retrievable.

Back to blog