Preventing WinCC Flexible Runtime PROFIBUS Address Overwrites

David Krause15 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

When WinCC flexible Runtime is launched on a configuration PC, the runtime service writes the configured MPI or PROFIBUS station address directly into the local PG/PC interface (the engineering station's CP or PC Adapter). This overwrites any address the engineer had previously set for normal STEP 7 online access. The behavior is triggered unconditionally on every Runtime start and continues until the user manually restores the original address in the Set PG/PC Interface dialog or the Windows registry.

The condition only manifests on MPI/DP connections. Ethernet- or PROFINET-based HMI connections do not modify the engineering station's local IP stack, so the panel and the PC can coexist on the same subnet without address conflict. Engineers who commission PROFINET-only systems often never see the issue, which is why it frequently surprises users migrating from PROFIBUS to mixed networks or replacing older panels.

Symptom in a typical scenario: the engineering PC starts WinCC flexible Runtime, the live HMI panel on the shop floor drops off the bus, the PLC's diagnostic buffer fills with "Station failure" entries, and Accessible Nodes in STEP 7 returns an empty list. The cause is a duplicate station address between the panel (which still holds the configured address) and the engineering station (which the Runtime just rewrote to the same value).

Root Cause Analysis

WinCC flexible Runtime communicates with the PLC through the same S7DOS / S7ONLINE infrastructure used by STEP 7 and the S7 communication drivers. To guarantee that the Runtime can reach the configured PLC regardless of the previous operator-side setting, the Runtime performs a write-back to the S7ONLINE access point at startup. The Runtime bypasses the user interface and writes directly to:

HKEY_LOCAL_MACHINE\SOFTWARE\Siemens\Automation\S7ONLINE\PRIFBUS\<CP_NAME>\ADDRESS

The value is a REG_DWORD containing the decimal station address (0-126). The write happens before the first S7 connection is opened, so it cannot be intercepted or queued. The same key also holds the bus parameters (transmission rate, HSA, profile); these are typically not overwritten, but the address always is.

WinCC flexible Runtime Start Read compiled project (*.hmi / *.fwx) Open S7ONLINE access point Connection type in project? MPI / PROFIBUS Write station address to S7ONLINE registry Override local CP Bus conflict with panel Ethernet / PROFINET Bind TCP socket to IP No local IP change Local stack untouched Live panel unaffected

This is intentional design rather than a defect. The Runtime must be able to reach the configured PLC address without operator intervention, especially in factory acceptance tests where the panel may be replaced temporarily. The trade-off is that any other station holding that address at the moment the Runtime starts will lose bus arbitration.

Affected Versions

Component Order Number / Version Behavior
WinCC flexible 2004 6AV6 612-0AA01-0AA0 MPI/DP address overwrite
WinCC flexible 2005 6AV6 612-1AA01-0AA0 MPI/DP address overwrite
WinCC flexible 2007 6AV6 612-2AA01-0AA0 MPI/DP address overwrite
WinCC flexible 2008 6AV6 612-3AA01-0AA0 MPI/DP address overwrite
WinCC flexible 2008 SP2 / SP3 / SP4 / SP5 Service packs Same behavior; no setting exposed
WinCC flexible Runtime (PC) Matching RT license Writes to S7ONLINE on every start
WinCC Comfort / Advanced / Professional (TIA Portal V13 to V18) 6AV2 1xx-... Same MPI/DP behavior; PROFINET unaffected

Affected PG/PC Interface Hardware

Hardware Order Number Notes
SIMATIC PC Adapter USB 6ES7972-0CB20-0XA0 USB-to-MPI/DP; writes to internal parameter set
CP 5611 A2 6GK1561-1AA01 PCI; legacy
CP 5612 6GK1561-2AA00 PCI; legacy
CP 5621 6GK1562-1AA00 PCIe; current standard
CP 5711 6GK1571-1AA00 USB; portable
CP 5512 6GK1551-2AA00 PCMCIA / CardBus; legacy
COM port via PC Adapter (MPI) 6ES7972-0CA00-0XA0 Legacy 9.6-187.5 kbps only

Supported Panels (WinCC flexible)

  • Operator Panels: OP 73 micro, OP 77A, OP 77B
  • Touch Panels: TP 170A, TP 170B, TP 177A, TP 177B, TP 177 micro, TP 277
  • Multi Panels: MP 177, MP 277, MP 377
  • Comfort Panels (newer firmware): TP 700 Comfort through TP 2200 Comfort, KP 700 Comfort through KP 1500 Comfort
  • Mobile Panels: Mobile Panel 177, Mobile Panel 277 (F-version with safety)

Solution 1: Migrate the HMI Connection to Ethernet or PROFINET

The cleanest and most durable fix is to change the HMI-to-PLC connection from MPI/PROFIBUS to Ethernet or PROFINET. The Runtime does not modify the local IP configuration, so simulation on the desk does not disturb the live panel. This option requires that the panel and the PLC both have Ethernet or PROFINET interfaces available.

Migration Procedure

  1. Open the WinCC flexible project and select Project > Connections.
  2. Change the active connection from MPI or PROFIBUS to Ethernet (or PROFINET IO for S7-1200/1500 controllers).
  3. Configure the PLC's IP address, subnet mask, and rack/slot (S7-300/400) or PROFINET device name (S7-1200/1500).
  4. Update the HMI station's IP address to match the production panel's IP.
  5. Configure any required router/gateway entries if the engineering PC and the panel are on different subnets.
  6. Recompile and transfer the project to the panel.
  7. Validate with the WinCC flexible Runtime on the engineering PC; confirm no address overwrite occurs.

For PROFINET IO, additional steps include assigning the device name using STEP 7 (Hardware Catalog > PROFINET Device Name) or the Primary Setup Tool (PST). The device name must match exactly what is configured in the WinCC flexible project.

For projects that must remain on PROFIBUS for legacy reasons (no Ethernet port on the panel, or existing PROFIBUS-only infrastructure), proceed to one of the following solutions.

Solution 2: Use Sm@rt Service for Remote Access

Sm@rt Service (also called Sm@rt Access on Comfort Panels and newer firmware) provides IP-based remote control of a running panel over Ethernet. The panel runs the live project; the engineer connects to it with a VNC-style viewer or web session. No Runtime simulator is needed on the engineering PC, so the address overwrite never occurs.

Requirements

  • Panel firmware V11.02.02 or higher (TP 177B, TP 277, MP 277, MP 377, all Comfort Panels)
  • Ethernet interface on the panel with routable IP address
  • WinCC flexible 2008 SP2 or higher with Sm@rt Service option licensed
  • Firewall rules allowing ports 80, 443, 5800, and 5900 between the engineering PC and the panel

Configuration Steps

  1. In WinCC flexible, open Device Settings > Sm@rt Service and enable the option.
  2. Set a password (minimum 8 characters, recommended 12+ with mixed case and digits).
  3. Configure IP address, subnet mask, and gateway to match the plant network.
  4. Compile and transfer the project to the panel.
  5. On the engineering station, open Internet Explorer (or any modern browser with ActiveX or HTML5 support) and navigate to http://<panel-ip>/smart_service or https://<panel-ip>/smart_service.
  6. Authenticate and operate the panel remotely.

Default Port Assignments

Service Port Protocol Notes
HTTP 80 / TCP TLS optional Configuration pages
HTTPS 443 / TCP TLS Recommended for production
VNC server (display) 5900 / TCP RFB Remote screen view
VNC server (HTTP) 5800 / TCP HTTP/Java Browser-based VNC client
Sm@rt Access on Comfort Panels adds HTTPS certificate management, ActiveX-free HTML5 client, and per-user permission profiles. Use Sm@rt Access (not Sm@rt Service) on Comfort Panels for the most current feature set.

Solution 3: Isolated Simulation Segment

For desks that must keep the engineering station disconnected from the plant network, build a private PROFIBUS segment using a second CP and a stand-alone DP master simulator. The Runtime writes its address into the isolated CP only; the live network remains untouched.

Hardware Setup

  • CP 5621 (6GK1562-1AA00) installed in the engineering PC
  • PROFIBUS cable with connectors (6GK1905-0AA00 or 6ES7972-0BA00-0XA0)
  • Bus termination resistors (220 Ω between pins 3 and 8) at both physical ends of the segment
  • Optional: DP repeater (6ES7972-0AA02-0XA0) for diagnostic isolation and segment amplification
  • S7-PLCSIM V5.4 SP5 or higher (STEP 7 V5.5) or PLCSIM V16+ (TIA Portal V16+)

Software Setup

  1. Install and license S7-PLCSIM.
  2. Start S7-PLCSIM and download the STEP 7 project to the simulated PLC.
  3. In WinCC flexible, configure the connection to use the local CP 5621 as the access point (via Set PG/PC Interface).
  4. Start WinCC flexible Runtime; the PROFIBUS address written to the local CP is contained within the isolated segment.
  5. When simulation completes, stop the Runtime; the CP retains the last-written address but no conflict occurs because the live network is not connected.
Even with an isolated segment, S7-PLCSIM does not provide a full PROFIBUS DP physical layer. For protocols that depend on DP diagnostics (DPV1 acyclic services, isochronous mode), verify with a real PLC or an ET 200 station on the isolated segment.

Solution 4: Manual Address Restoration

If none of the above options are feasible, the engineer can pre-stage the address before each simulation and restore it after. This requires discipline but is the only way to simulate against the live PROFIBUS without conflict.

Pre-Simulation Procedure

  1. Note the current PROFIBUS address of the engineering station by opening Start > SIMATIC > Set PG/PC Interface.
  2. Select the S7ONLINE access point and the corresponding CP (for example, CP5621.PROFIBUS.1 or PC Adapter (PROFIBUS)).
  3. Click Properties and record the Address field value (typically 0, 1, or 2).
  4. Open the WinCC flexible project, navigate to Connections, and change the HMI station's PROFIBUS address to a value not used on the live network (recommended: 124, reserved for engineering tools).
  5. Save and recompile the project.
  6. Start WinCC flexible Runtime.
  7. Stop the Runtime when simulation completes.
  8. Re-open Set PG/PC Interface and restore the original address value.

Registry-Level Backup and Restore (Advanced)

For scripted restoration, the S7ONLINE address is stored in the registry key shown earlier. Replace <CP_NAME> with the exact interface name as listed under S7ONLINE\PRIFBUS (commonly CP5621, CP5711, or PC_Adapter_USB). The value is a REG_DWORD containing the decimal address (0-126).

Backup Command (PowerShell)

reg export "HKLM\SOFTWARE\Siemens\Automation\S7ONLINE\PRIFBUS\CP5621" `
  C:\Backup\s7online_address.reg /y

Restore Command (PowerShell)

reg import C:\Backup\s7online_address.reg
net stop s7dos
net start s7dos
Editing the registry while the S7DOS service is running can corrupt the interface parameter set. Always stop the Runtime and the S7DOS service (net stop s7dos) before importing, or use the Set PG/PC Interface dialog which manages the service lifecycle automatically.

Step-by-Step: Configuring the S7ONLINE Access Point

This procedure ensures the local CP uses the correct access point and minimizes the chance of address conflict when the Runtime starts.

  1. Open Start > SIMATIC > SIMATIC Manager or Control Panel > Set PG/PC Interface.
  2. In the Access Point of the Application dropdown, select S7ONLINE.
  3. In the Interface Parameterization Used dropdown, select the CP you want to use (for example, CP5621.PROFIBUS.1 or PC Adapter (PROFIBUS)).
  4. Click Properties.
  5. On the PROFIBUS tab, configure:
    • Address: local station address; must not duplicate the live panel's address
    • Transmission rate: must match the bus; supported values: 9.6 kbps, 19.2 kbps, 45.45 kbps, 93.75 kbps, 187.5 kbps, 500 kbps, 1.5 Mbps, 3 Mbps, 6 Mbps, 12 Mbps
    • Highest Station Address (HSA): 126 (default; reduce only if the bus has fewer physical stations)
    • Profile: DP (default), Universal (for mixed MPI/DP segments), or User-defined
  6. Click OK to save.
  7. Verify by running PLC > Accessible Nodes in STEP 7; the expected PLC station should appear within 5-10 seconds.

If WinCC flexible Runtime still overwrites the address after this configuration, verify that the S7DOS service version matches the WinCC flexible installation. Mismatched versions can cause the Runtime to re-write the parameters during initialization. Reinstall the WinCC flexible matching the currently installed S7DOS version, or run the matching S7DOS setup from the WinCC flexible installation media.

Configuring the WinCC flexible Connection to Match

Inside the WinCC flexible project, the same address must be configured on the HMI station. Open Project > Connections, select the HMI station, and verify the Address field. For the connection to the PLC, set the PLC's PROFIBUS address, rack, and slot. For S7-300/400, rack 0 and slot 2 are typical for CPU 315-2 DP; consult the PLC hardware configuration for the exact slot.

Refer to the official WinCC flexible PROFIBUS communication PDF for the complete address assignment procedure.

PROFIBUS Timing Reference and Diagnostics

For engineers diagnosing bus instability alongside the address issue, the following PROFIBUS DP timing parameters are relevant when adding stations to a live segment:

Parameter Symbol Default Value Description
Slot time T_SL 1,000-12,000 bit times Maximum time a station may hold the bus for a single telegram
Min station delay T_SDR_MIN 11 bit times Minimum time before receiver can send reply
Max station delay T_SDR_MAX 60 bit times Maximum time before receiver must send reply
Quiet time T_QUI 0 bit times Idle time after last activity
Setup time T_SET 1 bit time Reaction time after receiving
Target rotation time T_TR 5,000-10,000 bit times Target token rotation time

When the engineering station duplicates the panel's address, the bus cycle time exceeds T_TR because token holders collide. The PLC's diagnostic buffer records the failure with event ID 0x0131 ("Station failure") on S7-300/400 or 0x001E on S7-1500. SF (red) and BF (red) LEDs light on the PLC and on DP slaves respectively.

Other diagnostic entries to watch for in the PLC buffer include 0x0130 (DP slave failure), 0x0132 (station reconfiguration), and 0x0138 (DP slave parameter error). These indicate bus-side instability that often accompanies the address conflict.

Troubleshooting Matrix

Symptom Probable Cause Check Resolution
Runtime starts; "Accessible Nodes" empty Duplicate address with live panel Open Set PG/PC Interface; compare address to panel Use isolated simulation segment
PLC diagnostic buffer: "Station failure" Engineering station stole panel address Read diagnostic buffer in STEP 7 Restore original address after simulation
Runtime shows "Online: Disconnected" Wrong baud rate or DP profile mismatch Compare CP and bus baud rates Match CP and bus transmission rate
BF LED lit on DP slave Duplicate address or missing termination Check bus terminator (220 Ω) at both ends Enable terminators; fix address conflict
Panel itself offline after Runtime stops Address still written to engineering CP Check Set PG/PC Interface address field Restore original address manually or via script
Engineering PC refuses to come online Duplicate address 0 or 1 with PLC Set PG/PC Interface > Properties > Default Reset to default; pick non-conflicting address
Runtime connects but tags are wrong Connected to wrong PLC (wrong slot) Check rack/slot in connection properties Correct rack/slot in project; recompile
WinCC flexible compilation warns "duplicate station" HMI address collides with PLC in project Open Connections > Stations; verify uniqueness Assign unique addresses across HMI and PLC

Verification Procedures

  1. After starting WinCC flexible Runtime, open Set PG/PC Interface > Properties and confirm the address matches the project's value.
  2. In STEP 7, choose PLC > Accessible Nodes (or Online > Accessible Nodes in TIA Portal) to verify the bus scan returns the expected PLC station.
  3. In WinCC flexible Runtime, open the Diagnostics view (under Tools > Diagnostics) and confirm the connection state shows Online.
  4. From the live panel, confirm its tags are still updating (no SF/BF alarms on the PLC or DP slaves).
  5. After stopping the Runtime, verify the address has been restored (manually or by re-importing the registry backup).
  6. Run a 10-minute stability check: cycle power on the engineering station and confirm the bus recovers without errors.
  7. Capture a PROFIBUS trace with an Amprolyzer or equivalent tool to confirm only one token holder exists per address.

Best Practices for HMI/PLC Commissioning

  • Always allocate a dedicated PROFIBUS address for the engineering station; never share it with a panel or PLC.
  • Document the complete address plan in the project documentation; include both bus address and IP (for mixed Ethernet/PROFIBUS segments).
  • Use PROFIBUS DP V1 diagnostics to detect address duplicates: the GSD file's diag_data exchange reports station status with bits 4 and 5 indicating address conflict.
  • For new installations, prefer PROFINET over PROFIBUS to eliminate this entire class of issue.
  • When migrating from WinCC flexible to TIA Portal, verify that the project's connection type and access point are preserved and that the new project uses a different S7 connection resource number if needed.
  • Use S7-PLCSIM (or PLCSIM V16+) for offline simulation; never simulate against a live PLC with the panel still online.
  • Lock down the panel address at commissioning: configure the panel project with a fixed address and document it in the panel faceplate.
  • Use a startup script to back up the S7ONLINE registry before every Runtime start; automate the restore on shutdown to minimize human error.
  • Disable the engineering station's CP from automatic bus attachment if the address collision risk is high; manually enable only when simulation is required.
  • Maintain a network diagram with all station addresses and update it whenever a new device is added.

Migration Path to TIA Portal WinCC and PROFINET

WinCC flexible was discontinued in 2014. New projects should use TIA Portal WinCC (Comfort, Advanced, or Professional). The same MPI/DP address overwrite behavior exists in TIA Portal WinCC Runtime, so the migration does not eliminate the issue on its own. However, TIA Portal provides better diagnostic views, including Online > Connection diagnostics and Projected vs. installed access points, which help identify which interface is being modified.

For long-term projects, migrate the HMI panel to PROFINET. The PROFINET IO standard (IEC 61784-2) names each device by IP address and station name, eliminating the address-collision class entirely. PROFIBUS segments can coexist with PROFINET via an IE/PB Link (6GK1411-5AB00) for legacy PLCs that lack PROFINET interfaces.

Refer to the official Siemens TIA Portal PROFIBUS communication documentation for step-by-step migration guidance and the WinCC flexible PROFIBUS communication PDF for legacy project reference. For assigning PROFIBUS addresses to field devices using SIMATIC PDM, see the Emerson reference on changing PROFIBUS device addresses.

Related Standards

  • IEC 61158: Industrial communication networks - Fieldbus specifications (includes PROFIBUS DP and PROFINET)
  • IEC 61784: Industrial communication networks - Profiles (PROFIBUS DP, PROFINET IO, PROFIsafe)
  • EN 50170: General purpose field communication (PROFIBUS reference, superseded by IEC 61158)
  • PI (PROFIBUS & PROFINET International) certification: PROFIBUS technology overview

FAQ

Does WinCC flexible Runtime overwrite the local IP address when using Ethernet?

No. WinCC flexible Runtime only modifies the local PROFIBUS or MPI station address through the S7ONLINE access point. Ethernet connections do not write to the local TCP/IP stack, so the engineering PC's IP address is preserved during Runtime simulation.

Can the address overwrite behavior be disabled?

No. The write-back is hard-coded in the WinCC flexible Runtime communication layer (S7DOS / S7ONLINE) and is not exposed as a user-configurable setting. Use a network-isolated simulation segment or migrate the connection to Ethernet / PROFINET.

What address ranges are valid for PROFIBUS stations?

PROFIBUS DP allows station addresses 0 to 126. Address 0 is reserved for masters with auto-configuration, address 1 is the conventional DP master address, and address 126 is reserved for commissioning tools without an assigned address. Avoid 0, 1, and 126 for engineering stations to prevent conflicts with masters and unconfigured tools.

Will the issue persist if I upgrade to TIA Portal WinCC?

Yes. TIA Portal WinCC Runtime (Comfort, Advanced, Professional) exhibits the same address overwrite behavior on MPI/DP connections because it shares the S7DOS / S7ONLINE infrastructure. Migrating the connection to PROFINET eliminates the issue entirely.

What is the fastest way to simulate without disconnecting the live panel?

Use a second PROFIBUS interface in the engineering PC (for example, a CP 5621 in addition to the existing PC Adapter USB) connected to an isolated segment with a stand-alone PLC simulator such as S7-PLCSIM or a real S7-300/400 station. The Runtime writes its address to the isolated CP only, and the live network remains untouched.

Can I assign the PROFIBUS address programmatically with SIMATIC PDM?

Yes. SIMATIC PDM (Process Device Manager) supports assigning PROFIBUS addresses to devices via the "Assign Address and TAG" function. See the Emerson reference for a worked example using a DVC6200P valve positioner.

Back to blog