PCS 7 RDP vs KVM: Siemens Restrictions for OS Servers and Clients

David Krause15 min read
HMI / SCADASiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

PCS 7 RDP vs KVM: Siemens Release Constraints, Service-Mode Requirements, and IPC574 Field Practice

Siemens SIMATIC PCS 7 V9.x and V10 environments that mix redundant OS Servers, OS Clients, and Engineering Stations (ES) on SIMATIC IPC574 hardware raise a recurring infrastructure question: which remote-access technology does Siemens actually release for the operator stations — Remote Desktop Protocol (RDP) over standard Ethernet, or a dedicated Keyboard-Video-Mouse (KVM) extender over Category 6 / fiber cabling? The answer governs both capital expenditure (fiber KVM matrix switches vs. zero-cost TCP/IP infrastructure) and long-term data-integrity risk on the WinCC/PCS 7 archives.

This reference consolidates the official Siemens release statements, the underlying service-mode mechanism, the documented failure mode, the KVM-over-IP alternatives, and a verification procedure that lets an integrator prove to IT management that an RDP-only topology is not supported for OS Servers or the Engineering Station on a PCS 7 plant.

1. Problem Definition: Distance, KVM Signal Integrity, and the IT Department Debate

A standard PCS 7 station is a SIMATIC IPC574 (or the legacy IPC547 / IPC647 generation) installed in the Control and Protection Domain (CPD). The default operator-room layout is:

  • Two redundant OS Servers (typically configured as a Master/Standby pair with a WinCC/PCS 7 redundancy license).
  • Two OS Clients (one per operator console, usually with multi-monitor graphics cards supporting 4 to 6 screens each).
  • One Engineering Station (ES) with the SIMATIC Manager / PCS 7 Engineering Toolset.
  • Optional Web Navigator / Information Server host.

Originally the operator consoles and the OS Servers were co-located in the same cabinet row, and a KVM extender pair driven by shielded Category 6 cable delivered acceptable analog or digital video at distances of 30 to 50 m. New installations in the same plant have pushed the distance beyond 80 m, and image artifacts (pixel tearing, dropped frames, EDID re-handshake, USB keyboard lag) appear because:

  • Category 6 copper KVM extenders are typically rated to 100 m, but only with premium shielded cable (S/FTP, foil + braid) and bonded conduit.
  • Industrial CPDs route cable trays next to VFD power conductors, welding supplies, and 480 V motor feeders. Common-mode noise coupling degrades the TMDS video pairs even inside the KVM extender's shielding.
  • Multi-head graphics cards (4 × DisplayPort 1.2) stress the extender's pixel clock; some KVM models only support dual-link DVI at 30 Hz beyond 50 m.

The IT department's preferred answer is RDP: it reuses the existing plant Ethernet, requires no proprietary hardware, and integrates with the Active Directory group policy. The integrator's counter-argument must be backed by official Siemens documentation, not by opinion.

2. Siemens Official Release Statement for RDP on PCS 7

Siemens publishes release statements in two layers:

  1. PCS 7 Process Control System documentation — entry ID 109780270 on the Siemens Industry Online Support portal. The manual explicitly states that "Use of the Remote Desktop Protocol (RDP) is permitted only for remote maintenance of PCS 7 OS clients. The RealVNC software should be used for remote access…" See SIMATIC PCS 7 Process Control System, entry ID 109780270.
  2. WinCC / TIA Portal help — the WinCC Server / WinCC RT Professional documentation entry on Remote access and Remote Desktop Protocol (RDP) repeats the same constraint at the WinCC layer: "The use of the Remote Desktop Protocol (RDP) is only permitted if the WinCC server or the single-station system is running in service mode." See Remote access and RDP (WinCC RT Professional V21).

Both documents collapse to the same decision tree, which is reproduced below as the canonical reference for any argument with IT management.

2.1 Decision matrix — Siemens release scope

Station role Station type in WinCC Explorer RDP allowed by Siemens? Conditions
OS Server (Master) WinCC Server, redundant partner configured No Not released. RealVNC or KVM only.
OS Server (Standby) WinCC Server, redundant partner configured No Not released. Mirror the same access method as Master.
OS Client (operator console) WinCC Client Yes, restricted Only for remote maintenance. Server must be in service mode if the client side is being remoted.
OS Single Station WinCC Server (single) Conditional Only when the station runs in service mode (interactive desktop suppressed).
Engineering Station (ES) WinCC Explorer with ES configuration No Not released. RDP can corrupt the in-progress download to the AS.
Web Navigator / Info Server WinCC Web Navigator Server Conditional Allowed only for maintenance; HTTPS to clients is the supported path.
Critical field guidance: If the OS Server is remoted over RDP and a SQL Server Express instance (the default for WinCC/PCS 7) is still attached, an RDP session log-off detaches the database from the WinCC runtime. The archives stop and the OS Server raises a WinCC-Channel-Diag: 0x80004005 error. The runtime does not always restart cleanly without a full station reboot.

3. Why Siemens Restricts RDP: The Service-Mode Mechanism

The restriction is not arbitrary. WinCC Runtime uses the Windows interactive desktop to host the Graphics Runtime process (CCWriteRts.dll and the PDLRT runtime). When an operator console or a server is launched normally, the runtime holds a window station handle (winsta0\default) and renders to a logical desktop. If an RDP session is opened against the same station while the runtime is running, Windows creates a separate session and a separate window station. The WinCC services detect a new logon event and re-attach their handles; on the next RDP session log-off, the services sometimes fail to release the handles cleanly, which is the root cause of the documented SQL background-process stop.

The fix in Siemens's official release is service mode:

  1. Open WinCC Explorer on the OS Server or single-station system.
  2. Right-click the computer name → Properties → Start Configuration.
  3. Activate the "Service Mode" checkbox. This runs the Graphics Runtime as a Windows service (CCStartService.exe) that is decoupled from any interactive logon session.
  4. Reboot the station. The runtime now starts before any RDP user logs on and survives an RDP disconnect.

Service mode is the only configuration under which Siemens releases RDP, and even then only for OS Clients. The OS Server role is excluded because the redundancy handshake — message-queue replication, partner-watchdog CCRedundantService, alarm-logging flush — depends on uninterrupted local access to the Windows Session 0 and the SQL Express instance.

4. The KVM Technology Family: Copper, Fiber, and IP

If RDP is constrained and Cat 6 copper is degraded, three KVM technologies are available. The choice is governed by distance, number of consoles, and the level of BIOS-level access required.

4.1 Copper KVM Extenders (Cat 5/6/6a)

  • Typical distance: 50 to 100 m at 1920 × 1200 / 60 Hz, 150 m at 1080p.
  • Limitation: Susceptible to electromagnetic interference from VFDs and 480 V feeders. Premium shielded S/FTP Cat 6a and grounded extender chassis are mandatory in industrial CPDs.
  • Examples: AdderLink XDIP, Raritan Dominion CatX, IHSE Draco compact.

4.2 Fiber KVM Extenders

  • Typical distance: 5 km (single-mode OS2 fiber) at 4K60, 300 m on multi-mode OM3.
  • Advantages: Total galvanic isolation, immune to ground loops, immune to VFD common-mode noise. Latency < 1 ms with modern DisplayPort 1.2 optical transceivers.
  • Examples: IHSE Draco vario, AdderLink Infinity, Black Box Emerald, Guntermann & Drunck (G&D) DL-Vision.
  • Cost: Single-head fiber extender pair: USD 1,800 to 3,500. Four-by-eight matrix switch with fiber I/O: USD 18,000 to 45,000.

4.3 KVM-over-IP (IPMI, iLO, iDRAC, RealVNC Enterprise)

  • Typical distance: Unlimited (any routable TCP/IP network).
  • Examples: SIMATIC IPC574 includes Intel AMT / iAMT with out-of-band KVM; RealVNC Enterprise is the Siemens-recommended solution for OS Clients in service mode.
  • Limitation: Out-of-band iAMT / iDRAC is not released by Siemens for PCS 7 OS Servers because the out-of-band channel cannot participate in the Windows domain authentication that the WinCC redundancy handshake requires.

5. SIMATIC IPC574 Hardware Considerations

The SIMATIC IPC574 (article number 6AG4014-1...) is the standard PCS 7 V9.x OS Server / OS Client / ES platform. The relevant specifications for KVM and remote-access design are:

Parameter IPC574 (6AG4014-1...) value Implication for KVM/RDP
Chipset Intel W480E (LGA1200, 10th-gen Core i / Xeon W) Supports Intel vPro / iAMT 14 for out-of-band KVM (with i7 / Xeon SKUs only).
Graphics (default) Intel UHD 630 integrated, 3 × DisplayPort 1.2 Three independent 4K @ 60 Hz streams — fiber KVM must support 3 × DP1.2 or use a multi-head KVM transmitter.
Graphics (optional) NVIDIA Quadro P2200 / RTX A2000 (4 × DP 1.4) 4-head graphics required by PCS 7 OS Client 4-monitor layouts; KVM must support at least 4 video channels.
IPMI / Out-of-band Intel iAMT 14 (SKU dependent) / integrated BMC on Xeon variants Available for BIOS-level remote access; not released for OS Server role.
OS Windows Server 2019 / 2022 Standard (OS Server), Windows 10 IoT Enterprise LTSC 2021 (OS Client / ES) Server SKU must remain in service mode for any RDP remote maintenance.

For the operator consoles that are 80 m+ from the CPD, the recommended architecture is fiber KVM with 4-port multi-head transmitters (IHSE Draco vario DV-4XCPU or G&D DL-Vision), with the Cat 6 copper link replaced by single-mode OS2 9/125 fiber pairs. The fiber path also segregates the video link from the plant Ethernet, satisfying the IEC 62443 zone-and-conduit requirement for the Basic Process Control System (BPCS) zone.

6. RealVNC Enterprise — The Siemens-Recommended RDP Alternative

Where a TCP/IP solution is genuinely required (remote engineering from outside the plant, vendor support from a different continent), Siemens releases RealVNC Enterprise in addition to RDP. RealVNC's mirror driver integrates with the Windows session 0 and survives an RDP-style disconnect, which removes the database-detach failure that plain RDP triggers.

Implementation outline:

  1. Acquire the RealVNC Enterprise license per OS Client / OS Server (Siemens supplies the SIMATIC WinCC/PCS 7 RealVNC bundle as add-on article number 6AV6371-1PT0x-0Ax0).
  2. Install the RealVNC Server component on each OS Client and (with explicit Siemens approval) on the OS Server.
  3. Configure the VNC Server in Service Mode (mirror driver + GFX hooks) — this is mandatory.
  4. Open port 5900 (or 443 for the VNC Connect cloud relay) inbound to the operator subnet only; never to the corporate IT subnet.
  5. Authenticate against the same Active Directory domain used for WinCC user administration.
Security note: RealVNC must be deployed inside the BPCS zone, not bridged to the IT corporate network. If the IT department insists on a single converged network, isolate the RealVNC traffic on a dedicated VLAN with ACLs that prevent the WinCC Server message-queue ports (TCP 139/445/SMB, dynamic WinCC archive replication) from leaking to IT.

7. BIOS-Level and Out-of-Band Access: When RDP Cannot Reach

KVM-over-IP and KVM extenders retain one capability that RDP cannot match: access before the operating system has booted, into the BIOS, the UEFI setup, the Intel iAMT provisioning console, or the Windows Recovery Environment. For a PCS 7 OS Server that fails to boot, only this layer of access can recover the system without dispatching a field engineer with a crash cart.

Recommended configuration on the SIMATIC IPC574 OS Servers:

  1. Enable Intel iAMT in the BIOS setup (Advanced → Intel AMT → Enabled).
  2. Provision iAMT to the management VLAN (out-of-band). Record the iAMT hostname and the MPS (Management Presence Server) address.
  3. Use the VNC Viewer in iAMT mode (port 16994, 16995) for BIOS-level access only. This connection is for fault recovery, not for routine operation.

8. Verification Procedure After Installation

After a fiber KVM is installed (or RealVNC is deployed on the OS Clients), execute the following sequence to verify both the video quality and the runtime integrity.

  1. Boot the OS Server. Verify that the WinCC Graphics Runtime launches automatically and that the green "Server is running" indicator appears in the operator area (lower right corner of the standard PCS 7 faceplate).
  2. Open the redundancy status window (WinCC Explorer → Redundancy → Status). Confirm that the partner's status reads Standby and the last synchronization time stamp is current.
  3. Initiate a forced failover (Right-click redundancy partner → Master). Confirm that the Standby takes over within 60 seconds and that the alarm log is continuous.
  4. From a second OS Client, establish a VNC / KVM session against the OS Client under test. Walk through the operator screens, trigger an alarm, acknowledge it, and confirm that the alarm appears in the chronological log within 2 seconds.
  5. Disconnect the VNC / KVM session. Wait 5 minutes. Reopen the WinCC Explorer on the OS Server. Confirm that the SQL Express database is still Online (right-click the database in SQL Server Management Studio → View Job History). The "DBM FULL" alarm must not appear.
  6. Open the Windows Event Viewer → Applications and Services Logs → WinCC. No error events with Event ID 4900, 4901, or 4902 should appear in the last hour.

9. Troubleshooting Matrix

Symptom Likely cause Diagnostic step Corrective action
Tearing / dropped frames on KVM video Cat 6 cable not shielded; distance too long Measure cable with Fluke DTX cable analyzer; check NEXT/ELFEXT Replace with S/FTP Cat 6a; or upgrade to single-mode fiber KVM
OS Server alarm log stops after RDP disconnect SQL Express detach on session log-off Check WinCC Channel Diagnosis for 0x80004005 Disable RDP, switch to KVM/RealVNC, enable Service Mode
RealVNC session shows black screen Mirror driver not installed; running in application mode instead of service mode Check VNC Server → Options → Capture Switch to mirror driver capture method; reboot station
ES download to AS fails halfway RDP session to the ES interrupted the SIMATIC Manager download Open SIMATIC Manager → PLC → Download; check error log Never remote the ES over RDP. Use KVM/RealVNC at the engineering console.
iAMT / iDRAC unreachable Management VLAN ACL; iAMT not provisioned Ping iAMT IP from management network Provision iAMT (Ctrl-P at boot) or configure BIOS iDRAC IP
OS Client keyboard lag USB-HID extender buffer overflow Check KVM extender logs Reduce keyboard polling rate; replace extender with USB 2.0 transparent model
Redundancy partner not detected after KVM switch Network adapter re-enumerated; WinCC redundancy MAC binding stale Open Redundancy → Partner Status Restart CCRedundantService on both servers

10. Building the Argument for IT Management

When the IT department presses for an RDP-only topology, the technical response should be:

  1. Cite the release statement. Quote the SIMATIC PCS 7 manual (ID 109780270) section that limits RDP to OS Clients in service mode. Provide the link in writing.
  2. State the failure mode. An RDP disconnect on the OS Server detaches the SQL Express database. The WinCC Runtime continues to accept new tag values but the archive flush stalls, leading to a DBM FULL alarm and loss of historical data.
  3. Identify the cost of an archive loss. In a regulated process (FDA 21 CFR Part 11, GAMP 5), loss of one production batch's archive is a deviation report. A fiber KVM matrix switch pays back in one avoided deviation.
  4. Offer the compromise. RDP is acceptable for OS Clients in service mode only, with RealVNC as the supported alternative. Fiber KVM extends coverage to the Engineering Station and the OS Servers without violating the Siemens release.

11. Migration Path: From Degraded Cat 6 to Fiber KVM

A typical migration plan for an existing PCS 7 plant with Cat 6 KVM degradation:

  1. Survey all Cat 6 KVM runs; record distance, shielding type, and tray segregation.
  2. For runs above 70 m, replace copper with OS2 single-mode fiber; use LC/UPC connectors and a 4-port KVM transmitter (e.g., IHSE Draco vario 4X-CPU).
  3. For OS Clients inside the 50 m radius, retain the existing copper extenders, but upgrade to shielded S/FTP Cat 6a.
  4. Install RealVNC Enterprise on the OS Clients and the ES for remote vendor support.
  5. Disable RDP on the OS Server and the ES through Group Policy (Computer Configuration → Administrative Templates → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Connections → Allow users to connect remotely = Disabled).
  6. Document the topology in the Plant Security Plan and update the PCS 7 network architecture diagram.

12. Summary of Siemens-Released Remote-Access Methods

Method OS Server OS Client ES BIOS-level
RDP (in service mode) Not released Released for maintenance Not released No
RealVNC Enterprise Released (with explicit Siemens approval) Released Released No (mirror driver only)
Fiber KVM extender Released Released Released Yes (KVM transmitter bypasses OS)
Intel iAMT / iDRAC Released (out-of-band recovery only) Released Released Yes
Field-proven caveat: An RDP-only topology on a PCS 7 plant with redundant OS Servers will eventually cause a database-detach event. Plan the migration to fiber KVM (or a RealVNC topology in service mode) before commissioning, not after the first archive loss.

13. FAQ

Is RDP officially released for PCS 7 OS Servers?

No. Siemens restricts RDP on PCS 7 to remote maintenance of OS Clients only, and only when the WinCC server or single-station system runs in service mode. The OS Server role and the Engineering Station are explicitly excluded. See the PCS 7 manual (entry ID 109780270) and the WinCC RT Professional help on Remote access and RDP.

What is the documented failure mode of RDP on a PCS 7 OS Server?

When an RDP session is disconnected, the SQL Express instance attached to the WinCC archives can detach because the runtime loses its interactive window-station handle. The runtime continues to process values but the archive flush stops, eventually triggering a DBM FULL alarm and a WinCC Channel Diagnosis error 0x80004005. Recovery normally requires a full station reboot and an OS reinstall if the archive is corrupt.

What is "Service Mode" in WinCC and why does Siemens require it?

Service Mode launches the WinCC Graphics Runtime as a Windows service (CCStartService.exe) in Session 0 instead of an interactive user logon. This decouples the runtime from any RDP user session and lets the station survive an RDP disconnect. Activate it in WinCC Explorer → Computer → Properties → Start Configuration → Service Mode and reboot the station.

Does RealVNC replace RDP on a PCS 7 OS Server?

RealVNC Enterprise is the Siemens-recommended alternative to RDP for routine remote maintenance of OS Clients and (with explicit Siemens approval) OS Servers. It must be installed in mirror-driver service mode to match the Siemens release scope. The 6AV6371-1PT0x-0Ax0 RealVNC bundle is the version pre-qualified for SIMATIC PCS 7.

Which fiber KVM extender is compatible with the SIMATIC IPC574 4-head graphics option?

For the IPC574 with the optional NVIDIA Quadro P2200 or RTX A2000 (4 × DisplayPort 1.4), select a multi-head fiber KVM transmitter such as the IHSE Draco vario 4X-CPU, Black Box Emerald 4K, or G&D DL-Vision. Confirm that the extender supports four independent DP 1.2 streams at 60 Hz and 4K resolution; the per-channel bandwidth must reach 17.28 Gbps.

Can Intel iAMT replace the KVM for an OS Server that fails to boot?

Yes, for BIOS-level recovery only. Provision Intel iAMT 14 in the IPC574 BIOS, assign a management-VLAN IP, and connect through the VNC viewer on port 16994. The out-of-band path is suitable for diagnosing a non-booting OS Server; it is not a substitute for KVM in normal operation because it cannot participate in the WinCC redundancy handshake.

Back to blog