KTP600 Basic PN OS Update: License Backup & S7-1200 Startup Fix

David Krause21 min read
HMI ProgrammingSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

KTP600 Basic PN OS Update: License Backup Procedure and S7-1200 Startup Fix

1. Problem Overview

A KTP600 Basic PN with order number 6AV6 647-0AD11-3AX0 running firmware V11.0.0.0 is deployed in a remote installation roughly 500 km from the engineering office. The connected S7-1200 CPU is a CPU 1214C (DC/DC/DC or DC/DC/RLY variant). Two engineering problems converge in this scenario:

  1. HMI feature gap — The system programmer wants to use the SetPLCmode system function from an HMI button to drive the CPU to RUN from the panel. The function is exposed in the WinCC Comfort/Advanced element list starting with the WinCC V12 (TIA Portal V12) HMI runtime. The installed V11 image does not publish this function in the events list, so the engineer proposes a runtime/OS update on the panel using SIMATIC ProSave.
  2. Spontaneous CPU STOP after power recovery — Every few years the installation is power-cycled. After power is restored the S7-1200 does not always return to RUN; the status LEDs typically show the orange/yellow flashing pattern that indicates the CPU is in STOP because the startup was interrupted by a power dip while the CPU was already in the middle of its boot sequence.

ProSave raises a destructive warning at the start of every OS image transfer:

"<Update OS> Transfer of selected image to the panel. Attention: If you execute this function, then all data installed and the licenses installed on the device will be irrevocably lost!"

The question the engineer has to answer before pressing Update OS is: Are there any licenses on this panel, and if so, how do I back them up?

Engineering rule of thumb: Before any ProSave OS update on a remote panel, always (a) archive the project from the panel with ProSave (Backup > Recipes/Passwords/Identification), (b) document the installed image version, and (c) determine whether the panel belongs to the Basic Panel 1st Generation or 2nd Generation product line. The license model is fundamentally different between the two.

2. Hardware Identification: 1st vs 2nd Generation Basic Panels

The MLFB (order number) of the panel is the only reliable way to identify the generation. The KTP600 in this article, 6AV6 647-0AD11-3AX0, is the KTP600 Basic mono PN, 1st Generation with a 6-inch touch + key front and Profinet interface. The full MLFB decodes as follows:

MLFB digit Meaning Value in this article
6AV6 647 Family — Basic Panels (KTP) KTP series
0A Display size 6" 6 inch
D Display type — monochrome, keys+touch Mono, KTP
11 Interface — Profinet PN
3AX0 Configuration / software bundle WinCC Flexible / early TIA

Key 1st Generation MLFBs in the same family include:

MLFB Description Generation
6AV6 647-0AD11-3AX0 KTP600 Basic mono PN 1st Gen
6AV6 647-0AE11-3AX0 KTP1000 Basic color PN 1st Gen
6AV6 647-0AF11-3AX0 TP1500 Basic color PN 1st Gen
6AV6 647-0AG11-3AX0 TP1500 Basic color PN (2nd Gen) 2nd Gen
6AV2 123-2MB03-0AX0 KTP700 Basic PN (2nd Gen) 2nd Gen
6AV2 123-1GB01-0AX0 KP400 Basic mono PN (2nd Gen) 2nd Gen

The 1st Generation product line is identified by the leading 6AV6 647 prefix and the 3AX0 suffix. The 2nd Generation product line uses 6AV2 123 prefixes. Only 2nd Generation Basic Panels carry a transferable license key stored on a non-volatile license container on the device — the 1st Generation panels do not expose an ALM-compatible license to back up.

A common pitfall: the firmware version (V11, V12, V13, V14, V15, V16, V17) is a software update axis, not a generation axis. A 1st Generation KTP600 can be upgraded through V11 → V12 → V13 → V14 → V15 → V16 → V17 image files, but it remains a 1st Generation device and will not gain 2nd-Generation-only license features.

3. License Model for Basic Panels

3.1 What licenses exist on a Basic Panel?

For Basic Panels the licensing model is not the SCADA-style "buy N tags" model. The base runtime shipped on the panel is fully functional out of the box — it does not require a runtime license, it does not require a tag-count license, and it does not require an audit/archives license. Optional license keys on Basic Panels (2nd Generation only) are used for add-on capabilities such as:

  • Sm@rtServer / Sm@rtAccess option
  • Audit option (2nd Gen only)
  • Specific protocol options added later in the product lifecycle

On a 1st Generation KTP600 such as the 6AV6 647-0AD11-3AX0, none of these options are supported by the device. The panel does not host an ALM-readable license container for runtime options. The base runtime is enabled at the factory and is tied to the hardware.

3.2 How to verify whether a license is installed

From the engineering PC with ProSave:

  1. Open SIMATIC ProSave and connect to the panel via Profinet (or Ethernet).
  2. Navigate to Panel > HMI Image or Options > License Management — the exact menu label varies with ProSave version.
  3. If the panel is 1st Generation, the license tab is greyed out or returns "No license key present".

From the panel itself (Control Panel — 1st Gen panels only expose a limited service menu):

  • Start Center > Settings > OP > License typically shows a list of optional license keys. On a 1st Gen KTP600 the list is empty or the menu is not present.

3.3 Consequence for this specific panel

For the panel identified above (6AV6 647-0AD11-3AX0, V11.0.0.0):

  • No ALM-backed license needs to be backed up before an OS update.
  • The ProSave warning is generic; it applies to all panels including those that do not host any license.
  • After the OS update, transfer the WinCC project from TIA Portal V12 (or later) back to the panel — the project, recipes, and passwords are stored in a separate container from the OS image.

3.4 License upgrade workflow (only required for 2nd Generation panels)

When the panel is a 2nd Generation device and an option license is installed, the engineer must perform a license transfer through the Automation License Manager (ALM) before the OS update. The TIA Portal V21 documentation under Installation > Licensing > Upgrade of licenses describes the generic workflow; the panel-specific steps are documented in the SIMATIC HMI Operating Instructions for the relevant Basic Panel 2nd Generation device and in the entry SIMATIC HMI HMI devices Basic Panels 2nd Generation: Transferring a license key.

Step Action on the engineering PC Tool
1 Open the Automation License Manager and connect to the local license storage folder (default C:\ProgramData\Siemens\Automation\Licenses). ALM
2 Right-click the license you want to back up → Export → save as a .zip container that includes the certificate. ALM
3 Verify the exported .zip contains the .lic file and the .txt certificate, store the certificate off-line. Explorer
4 Run ProSave OS update on the panel. ProSave
5 After the panel reboots, transfer the project, then re-install the license by dragging the .zip into ALM with the panel selected as the destination. ALM
The certificate file (CoL_<...>.txt) is the only way to recover a license if both the panel license and the local PC license are lost. Siemens support will request this certificate. Treat it as sensitive key material and store a copy on a separate, offline medium (USB stick in a safe, offline backup server, etc.).

4. The Real Engineering Issue: S7-1200 STOP After Power Recovery

The OS update is a side-track. The actual recurring field problem is that the S7-1200 sometimes does not restart in RUN after a power outage. The orange/yellow flashing pattern on the CPU indicates STOP with diagnostic buffer entry "Power on — CPU in STOP, no automatic restart" or, more commonly, the firmware has detected a startup interrupted condition.

The default behavior of an S7-1200 is governed by the Startup group in the device configuration of TIA Portal:

Parameter Path in TIA Portal Default Recommended for unattended plants
Startup after power on Device view > CPU > Properties > Startup Warm restart — RUN Warm restart — RUN (explicit)
Comparison preset to actual configuration Startup > Compare preset/actual Startup only if compatible Startup only if compatible
Parameter assignment of the modules during startup Startup > Module parameter assignment From PG/PC only From PG/PC only (for retentive) or from project (for non-retentive changes)
Time monitoring for startup Startup > Monitoring time Default 60 s Increase to 120-300 s on large configurations

On a CPU 1214C, the relevant bits are stored in the system memory of the CPU. If the power drops while the CPU is mid-startup and the diagnostic buffer records a startup abort, the CPU powers back up in STOP. To prevent the user from having to physically visit the site, the engineer can either:

  1. Configure the PLC to always run on power on by setting the startup mode in TIA Portal and downloading the hardware configuration.
  2. Use the HMI SetPLCmode system function on a button to drive the CPU to RUN remotely (requires WinCC V12 or later on the panel — this is the original reason the engineer wanted to update the HMI OS).

4.1 Setting the CPU 1214C startup mode in TIA Portal

  1. Open the TIA Portal project that matches the installed S7-1200 hardware.
  2. In the project tree, double-click Devices & networks and select the CPU 1214C.
  3. In the inspector window choose Properties > General > Startup.
  4. Under Startup after power on select Warm restart — RUN.
  5. Under Monitoring time for startup enter a value appropriate for the configuration (start with 120 s).
  6. Compile the hardware configuration (Hardware > Compile) and download to the CPU. The CPU will go to STOP briefly during the download; this is normal.
  7. Power-cycle the CPU and confirm it returns to RUN with the green RUN LED solid.

If the installation is unreachable for a remote download, the same parameter is accessible through the online diagnostics of any panel that can establish a Profinet connection to the CPU: open TIA Portal > Online & Diagnostics > Assign IP address / set PROFIBUS or, more usefully, write the value via an HMI screen that has been configured with a tag-based control element bound to the system byte or the SetPLCmode function.

4.2 Using SetPLCmode from the panel

The SetPLCmode system function is documented in the WinCC Comfort/Advanced system manual. It accepts a Mode parameter:

Mode value Effect on the connected PLC Available since
0 Go to STOP WinCC V12 (TIA Portal V12) on Comfort/Advanced panels; first published on Basic Panels 2nd Generation with V12 image
1 Go to RUN Same as above
2 Go to RUN (cold restart, S7-300/400/1500 only) Same as above

On a V11 panel, the function is not in the events list of the configurable buttons. Two solutions exist:

  1. Update the panel image to V12 or later (see section 5). This is the clean solution and unlocks other V12 features (Sm@rtServer option on 2nd Gen, improved alarm archiving, etc.).
  2. Use an HMI tag to write the CPU's startup behavior. Bind a button to a tag that writes the value 1 to a data block bit in the CPU. The CPU's OB100 / startup OB reads the bit and issues a SET on the REQ bit of a SET_CP_RT type call (CPU 1200 does not have a direct SET instruction, but the user program can call PLC_READY logic, or use the START bit of a timer-driven block that forces the CPU to RUN via the SETPLC instruction in SCL). The simplest pattern is to write 1 to CPU.Startup.WarmRestart — this is a write-protected system bit in TIA Portal and cannot normally be written from a tag. Therefore, the real path is option 1 (OS update) or section 4.1 (configure the CPU).

5. KTP600 Basic PN 1st Generation: OS Update Procedure via ProSave

If the engineering decision is to update the panel to a V12+ image to gain SetPLCmode and other V12 features, the procedure is:

5.1 Prerequisites

  • ProSave version matched to the target image. TIA Portal V12 ships a ProSave that is compatible with V12 images. Later TIA Portal versions include ProSave that can update to V13/V14/V15/V16/V17 images as well.
  • OS image file (.img) for the KTP600 Basic 1st Generation. Siemens provides these in the Support > Downloads area under SIMATIC HMI > KTP600 Basic PN > Firmware/Image.
  • Profinet or Ethernet connection from the engineering PC to the panel.
  • Panel IP address. If unknown, the panel can be reset to factory defaults through the Control Panel and then assigned a known address.

5.2 Step-by-step procedure

  1. Archive the project on the panel — connect with ProSave → Backup > Complete backup → store the backup on the engineering PC. This includes recipes, scripts, user administration, alarm logs, and the WinCC project. The backup does not include the OS image, which is exactly the point of separation.
  2. Verify that the panel is a 1st Generation device — confirm the MLFB matches the 6AV6 647-0xxx-xxAx0 range. Do not attempt to install a 2nd Generation image on a 1st Generation panel; the boot loader rejects the image with a hardware mismatch.
  3. Open ProSave > Panel > HMI Image > Update OS.
  4. Select the target image file (for example KTP600_Basic_V17.0.0.0.img if a V17 image is available for the device; otherwise V12, V13, V14, V15, or V16 depending on the engineering TIA Portal version).
  5. Acknowledge the destructive warning (it is generic — on a 1st Generation panel no ALM license is present, so the only data lost is recipes and the project, both of which are covered by the backup in step 1).
  6. Click Update OS. The panel reboots part-way through the transfer. Do not interrupt power during the image write.
  7. After the panel restarts, the Start Center shows the new version number. Re-confirm the Profinet connection to the CPU.
  8. Open the TIA Portal project, compile, and download the project to the panel.
  9. Verify all screens, tag connections, and the SetPLCmode function is now available in the events list of the button configuration.

5.3 Rollback

If the new image does not behave as expected, the panel can be flashed back to V11 (or to any prior version) using the same procedure. The image is not one-way. Confirm with Siemens compatibility notes that the TIA Portal project version still supports the downgraded image — a project compiled with TIA Portal V17 typically cannot be downloaded to a panel running a V11 image.

6. HMI Image and TIA Portal Version Matrix

The following table summarises the published TIA Portal and HMI image compatibility for the KTP600 Basic 1st Generation. The exact availability of a particular image depends on the country-specific support download portal and on whether the user has a valid Software Update Service (SUS) contract.

TIA Portal version Compatible KTP600 image SetPLCmode available? WinCC project source
V11 (2012) V11.0.0.0 No WinCC V11 / TIA V11
V12 (2013) V12.0.0.0 Yes WinCC V12 / TIA V12
V13 (2014) V13.0.0.0 Yes WinCC V13 / TIA V13
V13 SP1 (2015) V13.0.1.0 Yes WinCC V13 SP1
V14 (2016) V14.0.0.0 Yes WinCC V14 / TIA V14
V14 SP1 (2017) V14.0.1.0 Yes WinCC V14 SP1
V15 (2018) V15.0.0.0 Yes WinCC V15 / TIA V15
V15.1 (2019) V15.1.0.0 Yes WinCC V15.1 / TIA V15.1
V16 (2020) V16.0.0.0 Yes WinCC V16 / TIA V16
V17 (2021) V17.0.0.0 Yes WinCC V17 / TIA V17
V18 (2023) Not available for 1st Gen N/A WinCC V18
V19 / V20 / V21 Not available for 1st Gen N/A WinCC V19+

From TIA Portal V18 onward, the 1st Generation Basic Panels are no longer supported in the device catalog. The practical ceiling for the KTP600 Basic 1st Generation is V17.0.0.0. Once the panel is on V17, the path forward is to migrate to a 2nd Generation panel (KTP700 Basic, 6AV2 123-2MB03-0AX0) if the engineering software is upgraded to V18+.

7. TIA Portal Configuration: Quick Code Reference

The relevant TIA Portal paths and configuration values for this scenario are:

7.1 PLC startup parameter (CPU 1214C)

In the device configuration of the CPU 1214C:

  • Properties > General > Startup > Startup after power on: Warm restart - RUN
  • Properties > General > Startup > Monitoring time for startup: 120000 ms (2 minutes; increase for larger projects)
  • Properties > General > Startup > Module parameter assignment: From project (recommended for plants with frequent configuration changes)

7.2 HMI button event (WinCC V12 or later)

In the WinCC Comfort screen:

  1. Add a button to the screen.
  2. In the inspector choose Events > Click > Add function > SetPLCmode.
  3. Set the Mode input to 1 (RUN).
  4. Compile the project and download to the panel.

The runtime calls the PLC's system function with the new mode. On the CPU 1214C, the mode change is acknowledged in the diagnostic buffer as Mode change requested by HMI and the CPU goes to RUN if no error condition is blocking it.

8. Verification Checklist

After completing the OS update and the CPU configuration change, verify the following on site (or remotely if the panel is on a routable network and the Sm@rtServer option is licensed and enabled):

  1. Panel boots to the Start Center and shows the new image version under Start Center > System > Information.
  2. WinCC project downloads without errors.
  3. Tag connection to the CPU 1214C is green in the panel diagnostics (Start Center > System > Connections).
  4. The SetPLCmode function is now present in the button events list of the WinCC configuration in TIA Portal.
  5. CPU 1214C powers up in RUN after a power cycle.
  6. Diagnostic buffer of the CPU 1214C contains a single warm-restart entry and no STOP entries with reason Power on — startup interrupted.
  7. If the panel is 2nd Generation and an option license was installed before the OS update, verify in ALM that the license is still present after the project download. If it is missing, drag the exported .zip back into ALM and assign it to the panel.

9. Troubleshooting Matrix

Symptom Likely cause Resolution
ProSave cannot connect to the panel Wrong IP address, firewall on the engineering PC, panel in transfer mode with different IP Verify Profinet connection with ping; restart the panel's transfer mode; check Windows firewall
OS update fails mid-transfer, panel stuck in bootloader Power dip during image write, mismatched image file, defective compact flash Re-attempt OS update; verify the image MLFB prefix matches the panel; replace the panel if flash is defective
OS update succeeds but SetPLCmode is not in the events list Project was not recompiled after image update; wrong WinCC project version Recompile the project with a WinCC version that matches the new image; re-download the project
License tab in ALM is empty after OS update Panel is 1st Gen (expected) or option license was not backed up For 1st Gen: no action needed. For 2nd Gen: re-transfer the license using the exported .zip
CPU 1214C does not return to RUN after power cycle Startup mode is STOP, or module parameter assignment is set to from PG/PC only and no PC is connected Set Startup after power on to Warm restart — RUN in TIA Portal; set Module parameter assignment to from project
CPU 1214C returns to RUN but loses retentive tags Retentive memory not configured Set Retentive memory > Number of retentive MBs / DBs / Tags in the CPU properties; download the hardware config
SetPLCmode button click does nothing Wrong connection name in the project, or panel and PLC are on different subnets Verify the HMI connection in TIA Portal points to the correct PLC IP; verify routing

10. Decision Tree

The following decision flow helps the engineer decide whether to perform the OS update, change the CPU configuration, or both.

  1. Is the panel a 1st Generation KTP600 (6AV6 647-xxx-xxAx0)?
    • Yes → No license to back up. Skip license export. Proceed to step 2.
    • No → Confirm 2nd Generation MLFB. Export license via ALM. Proceed to step 2.
  2. Does the field problem require SetPLCmode from the panel?
    • Yes → Update the panel image to V12 or later (V17 max for 1st Gen). Recompile the WinCC project with a matching TIA Portal version. Configure the SetPLCmode function on a button.
    • No → Skip the OS update. Configure the CPU 1214C startup mode in TIA Portal and download.
  3. Is the site reachable for a remote download of the hardware configuration?
    • Yes → Change the CPU startup mode remotely via TIA Portal online connection. Done.
    • No → Either (a) send a USB-to-Profinet cable to site and have a local engineer perform the download, (b) use a remote maintenance router (SINEMA RC, M87x, or third-party) to bridge to the CPU, or (c) implement the SetPLCmode function on the HMI and let the local operator drive the CPU to RUN with a tap on the screen.

11. Field-Proven Caveats

  • OS image version is independent of generation. A V17 image on a 1st Gen panel is still a 1st Gen panel. The image enables V17 runtime features but does not change the hardware generation.
  • ProSave is version-sensitive. An older ProSave cannot push a newer image. A newer ProSave can usually push older images. Use the ProSave shipped with the target TIA Portal version, or the latest ProSave available.
  • Project downloads are version-sensitive in the opposite direction. A V17-compiled project will not download to a V11 panel. A V11-compiled project will generally not download to a V17 panel because the V11 project is missing newer mandatory parameters.
  • The license warning in ProSave is generic. It is shown for every panel, every time. Read the MLFB before panicking.
  • The SetPLCmode function is exposed on Comfort and Advanced panels from V12. On Basic Panels the function appears in the events list from V12, but only for 2nd Generation Basic Panels. 1st Generation Basic Panels (KTP600 mono, KTP1000, TP1500 1st Gen) do not include the function even with V12+ images. Verify in the TIA Portal help that the function is available for the configured panel.
  • The CPU 1214C startup behavior change is the higher-value fix. A 1st Gen Basic Panel cannot use SetPLCmode regardless of the image version. Configuring the CPU to always go to RUN on power on is the correct engineering solution and removes the need for any OS update.

12. Recommended Path Forward

For the specific case in this article (KTP600 Basic PN 1st Gen, V11, S7-1200 CPU 1214C, 500 km remote site):

  1. Do not perform the OS update. The panel is 1st Generation and does not host a transferable license, so the license concern is moot. More importantly, the 1st Generation Basic Panel will not expose SetPLCmode in the events list even with a V12+ image, so the OS update does not actually deliver the original goal.
  2. Change the CPU 1214C startup configuration to Warm restart — RUN with a 120-300 s monitoring time, and download the hardware configuration to the CPU. This is the only fix that addresses the field problem.
  3. Document the configuration change in the project's change log and update the operator manual so the local staff understands that the CPU will not remain in STOP on power recovery.
  4. Plan a long-term migration to a 2nd Generation panel (KTP700 Basic PN, 6AV2 123-2MB03-0AX0) when the engineering TIA Portal version is upgraded beyond V17. At that point the SetPLCmode function will be available natively, and Sm@rtServer remote access will replace the need for a 500 km service call.

Does the KTP600 Basic PN 1st Generation (6AV6 647-0AD11-3AX0) carry a license that I must back up before an OS update?

No. 1st Generation Basic Panels do not host an Automation License Manager (ALM) transferable license. The ProSave warning about irrevocable loss of licenses is generic and does not apply to this hardware. Confirm the MLFB prefix (6AV6 647) to identify the generation, and back up the project + recipes only.

How do I check whether my Basic Panel is 1st or 2nd Generation?

Read the MLFB on the rating plate. 1st Generation Basic Panels use the 6AV6 647-0xxx-xxAx0 range (KTP600, KTP1000, TP1500 1st Gen). 2nd Generation Basic Panels use 6AV2 123-xxx-xxAx0 (KP400, KTP700, KTP900, KTP1200, TP1500 2nd Gen). The MLFB is the only reliable way to identify the generation because the firmware version (V11..V17) is independent of the generation.

From which image version is the SetPLCmode function available in the HMI events list?

SetPLCmode is exposed on Comfort and Advanced panels from WinCC V12 (TIA Portal V12) onward. On Basic Panels it appears in the events list from V12 onward, but only on 2nd Generation devices. 1st Generation Basic Panels such as the KTP600 1st Gen do not include the function even with V12 or later images. Verify in the TIA Portal object list that SetPLCmode is in the system functions of the configured panel.

How do I stop the S7-1200 CPU 1214C from going to STOP after a power outage?

In TIA Portal, open the device configuration of the CPU 1214C, go to Properties > General > Startup, set Startup after power on to Warm restart — RUN, and increase the Monitoring time for startup to at least 120 s for typical configurations. Compile and download the hardware configuration. After the next power cycle the CPU will go to RUN automatically.

What is the highest image version supported on the KTP600 Basic 1st Generation?

The KTP600 Basic 1st Generation supports image files up to V17.0.0.0 (WinCC V17 / TIA Portal V17). From TIA Portal V18 onward the 1st Generation Basic Panels are removed from the device catalog. Plan a migration to a 2nd Generation panel (KTP700 Basic PN, 6AV2 123-2MB03-0AX0) if the engineering TIA Portal version is upgraded to V18 or later.

Back to blog