Problem Summary
Siemens PRONETA (PROFINET Network Analysis) is the standard field tool for topology discovery, IO check, and network commissioning of PROFINET and standard Ethernet segments. After a major Windows 10 cumulative update (most commonly seen with build 1909 → 20H2 transitions and later 21H1 / 21H2 feature upgrades), PRONETA Basic 2.7, 3.1, and 3.2.0 may fail to enumerate any local network adapters. The main window displays an empty adapter list, the Topology scan button stays inactive, and the IO test cannot select an interface.
Typical accompanying symptoms:
- The Network adapters dropdown on the PRONETA start screen is empty.
- The Settings → Network panel reports
No adapter found. - Re-installing the bundled WinPcap driver fails with a dialog referencing
npf.sysload failure, error code0x800F0922or0x800F081F. - Running
PRONETA.exeas administrator does not restore adapter detection. - Manually installing
WinPcap_4_1_3.exeexits with "Could not install the driver NPF".
Affected Versions and Environment
| Component | Tested Version | Status |
|---|---|---|
| PRONETA Basic | 2.7.0.4 | Affected |
| PRONETA Basic | 3.1.0.18 | Affected |
| PRONETA Basic | 3.2.0.41 | Affected |
| WinPcap (bundled) | 4.1.3 (driver 4.1.0.3001) | Fails to install |
| Windows 10 | 1909, 20H2, 21H1, 21H2, 22H2 | Trigger condition |
| Windows 11 | 21H2, 22H2 | Same root cause |
| Npcap (replacement) | 1.55 → 1.78 (current) | Working fix |
PRONETA uses the WinPcap API to enumerate and bind to Ethernet adapters. The legacy WinPcap project has been unmaintained since 2013 and its npf.sys kernel driver is not signed for Windows 10 20H2+ Secure Boot enforcement. The post-update driver signature revocation list rejects the legacy npf.sys, which is the root cause of the install failure and the missing adapter list.
Root Cause Analysis
Three independent failure paths converge on the same symptom:
-
Driver signature enforcement. Modern Windows builds enforce Windows Hardware Quality Labs (WHQL) signing. The shipped
npf.sysinside the PRONETA installer is signed with an older certificate that Microsoft has revoked viadbanddbxEFI variables after the cumulative update. The OS returnsERROR_DRIVER_BLOCKED (0x800F0922). -
Network adapter enumeration path. PRONETA's network module queries
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCardsthrough the WinPcap service to build its dropdown. If the service is not started, the registry subkeys still exist but the tool cannot open the adapter handle. Microsoft documents this enumeration path in the Network Adapters not displayed in advanced network settings knowledge base article, which is the same registry path PRONETA relies on. - Universal Windows Platform (UWP) packet capture. Windows 10 20H2 introduced the PacketDirect provider as a replacement. WinPcap does not register with PacketDirect, so the adapter bind fails silently even when installation appears to succeed.
The robust fix is to migrate the packet-capture stack to Npcap, the actively maintained WinPcap drop-in replacement that ships signed by Insecure.Com LLC and exposes the same pcap_open_live / pcap_findalldevs API surface that PRONETA's binary expects.
Prerequisites
- Local administrator account on the engineering workstation.
- Internet access to nmap.org/npcap for the current installer (Npcap 1.78 at the time of writing).
- Working Ethernet or Wi-Fi adapter with PROFINET access if the fix will be validated against live devices.
- Approx. 10 MB of free disk space and a clean Windows driver store (
C:\Windows\System32\driversmust not be locked by an in-progressDISMorsfcrun). - Optional: 7-Zip or
Expand.exeto inspect the PRONETA installer.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards before any driver change:
reg export "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards" C:\backup\NetworkCards.reg /y
This guarantees you can rebuild the adapter list if the cumulative update later clears the keys.
Step-by-Step Fix: Replace WinPcap with Npcap
-
Remove the broken WinPcap installation.
Open Settings → Apps → Apps & features and uninstall WinPcap 4.1.3. If the entry is missing, run:
sc stop npf sc delete npf del /f /q "%SystemRoot%\System32\drivers\npf.sys"Reboot the workstation to clear the blocked driver image from memory.
- Download the current Npcap release from the official repository: https://nmap.org/npcap/. Use the Npcap 1.78 OEM or Installer build — not the source archive.
- Launch the installer as administrator and step through the wizard. On the Installation Options dialog, enable the following checkboxes:
| Option | Required | Reason |
|---|---|---|
| Support raw 802.11 traffic (monitor mode) | Optional | Needed only for Wi-Fi sniffing |
| Restrict Npcap driver's access to Administrators only | Recommended | Aligns with PRONETA privilege model |
| Use DLT 148 (Linux cooked) for "cooked" capture | No | WinPcap default is fine for PROFINET |
| Install Npcap in WinPcap API-compatible Mode | YES — mandatory | Exposes the legacy pcap*.dll import surface that PRONETA links against |
- Click Install and accept the driver signing prompt (it is signed by Insecure.Com LLC).
-
Reboot. The Npcap service
npcapis registered as a kernel service and must start at boot. -
Verify the driver load from an elevated command prompt:
sc qc npcap packet.dll --versionExpected return includes
START_TYPE: 0 BOOT_STARTand a reported version string matching the installer (e.g.1.78.0-r0). - Start PRONETA as administrator. Open PRONETA Basic 3.x from the desktop shortcut with right-click → Run as administrator. The network adapter dropdown should now display every wired and wireless interface visible to the OS.
wpcap.dll shim and PRONETA's import table will fail with LoadLibrary failed: 126 (The specified module could not be found). Verify the checkbox state in Add or Remove Programs → Npcap → Modify if the dropdown remains empty.
Step-by-Step: Verify the NetworkCards Registry Branch
If the adapter list is still empty after the Npcap install, the underlying Windows enumeration may itself be broken (the cumulative update can occasionally clear the NetworkCards subkeys for virtual adapters). Microsoft documents this exact symptom in Network Adapters not displayed in advanced network settings.
- Open
regedit.exeas administrator. - Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards. - Confirm each physical interface has a subkey
1,2,3, ... with values:Name REG_SZ "Intel(R) Ethernet Connection I219-LM" ServiceName REG_SZ "e1dexpress" Description REG_SZ "Intel(R) Ethernet Connection I219-LM" - If the key is missing entirely, run
netcfg -winpefollowed bynetcfg -eto re-enumerate. A full network stack reset can also be triggered with:netsh winsock reset netsh int ip reset ipconfig /flushdns reboot - Re-test PRONETA. The Adapter selector in the Topology and IO test screens should populate.
Step-by-Step: Administrative Privileges and Service Configuration
PRONETA opens the capture handle with OpenService(SERVICE_QUERY_CONFIG | SERVICE_START | SERVICE_USER_DEFINED_CONTROL) and binds the adapter via the Network Packet Filter alias. If the npcap or npf service is not started, the call fails with ERROR_SERVICE_NOT_ACTIVE (0x80070426).
- Set the service to automatic:
sc config npcap start= auto sc start npcap - Confirm the
ServiceSidTypeis0x3 (SERVICE_SID_TYPE_UNRESTRICTED). If a group policy has downgraded it, restore with:reg add "HKLM\SYSTEM\CurrentControlSet\Services\npcap" /v Type /t REG_DWORD /d 0x1 /f - Disable Memory integrity in Windows Security → Device security → Core isolation only if Npcap fails to load with a code-integrity
0x80070241error. This is a fallback for Windows 11 22H2 hosts where the HVCI hash for the newnpcap.sysis not yet in the Code Integrity Allow List.
Verification and Functional Test
- Launch PRONETA, switch to the Network analysis tab, and confirm the adapter dropdown lists at least one interface.
- Select the PROFINET-bound Ethernet port, click Read → Topology. A successful scan returns the controller, every switch, and every IO device with their device names, IP addresses, and PROFINET station names.
- Run IO test with a known-good ET 200SP or ET 200MP station. All configured slots must report
OKand the Port Statistics counters should increment. - Cross-validate the scan with Wireshark 4.x bound to the same adapter through Npcap. A single PROFINET DCP IdentifyAll request must be visible. If Wireshark sees traffic but PRONETA does not, the issue is the WinPcap API-compatible Mode flag — re-run the Npcap installer and enable it.
Troubleshooting Matrix
| Symptom | Likely Cause | Remediation |
|---|---|---|
| Adapter list empty after install | WinPcap API-compatible Mode not selected | Re-run Npcap installer, enable checkbox |
npf.sys load fails with 0x800F0922 |
Legacy WinPcap still present |
sc delete npf + reboot + reinstall Npcap |
| PRONETA crashes at startup | Conflicting WinPcap and Npcap DLLs in PATH | Remove %ProgramFiles%\WinPcap from PATH |
| Adapter visible but no DCP traffic | Hyper-V vSwitch or VPN virtual adapter hijacking bind | Disable vEthernet adapters or bind PRONETA to physical NIC explicitly |
| Works as admin, fails as standard user | Npcap installed with Restrict to Admins enabled and user is not elevated | Reinstall Npcap with the option disabled, or add user to Network Configuration Operators |
| Scan returns only the local PC | Promiscuous mode blocked by switch port security | Mirror PROFINET port on managed switch, or use a tap |
| PRONETA 2.7 still fails after Npcap | PRONETA 2.7 hard-codes npf service name |
Upgrade to PRONETA 3.1+ — PRONETA 3.x queries npcap first |
Rollback Considerations
If a clean Windows reinstall is acceptable, a fresh image of Windows 10 22H2 with PRONETA 3.2.0 and Npcap 1.78 installed before any cumulative update does not exhibit the issue. The patch sequence is therefore:
- Deploy OS image.
- Install Npcap 1.78 with WinPcap API-compatible Mode enabled.
- Install PRONETA 3.2.0.
- Validate the topology scan on a bench PROFINET line.
- Defer Windows quality updates to the Current Branch for Business cadence (four months) to avoid the early-WHQL period during which Microsoft revokes the legacy driver certificate.
Do not roll back a Windows 10 feature update to recover PRONETA. The legacy npf.sys signature is also revoked in earlier branches, so a downgrade is no guarantee of success and exposes the workstation to months of missing security patches.
Cross-References and Tool Compatibility
The same Npcap substitution fixes other WinPcap-based PROFINET tools, including:
- Wireshark 3.6 and 4.x — set Edit → Preferences → Advanced → Capture → Use Npcap.
- Siemens Primary Setup Tool (PST) 5.x — Npcap fully replaces the bundled WinPcap.
- PROFINET IO Test Tool from PI International.
- PRONETA Professional 4.x — already uses the Npcap installer shipped by Siemens PRONETA documentation in the TIA Portal Manual Collection.
FAQ
Why does PRONETA stop detecting network adapters after a Windows 10 update?
The bundled WinPcap 4.1.3 driver (npf.sys) is unsigned against the post-update driver signature revocation list, so the install fails and PRONETA cannot bind an adapter. Replacing WinPcap with Npcap 1.78 in WinPcap API-compatible Mode restores the capture path.
Do I have to uninstall WinPcap before installing Npcap?
Yes. Stop and delete the npf service first: sc stop npf, sc delete npf, reboot, then install Npcap. Two parallel packet-capture drivers will cause PRONETA to throw load-library errors at startup.
Which Npcap checkbox is mandatory for PRONETA?
Enable Install Npcap in WinPcap API-compatible Mode on the Installation Options dialog. Without it, Npcap does not expose the legacy wpcap.dll import table and PRONETA cannot resolve its packet functions.
Can I run PRONETA as a standard user after the fix?
Only if Npcap was installed with the Restrict driver's access to Administrators only option disabled. Otherwise you must launch PRONETA elevated every time, because the npcap service refuses non-admin handles.
Does the fix work on Windows 11 and Windows Server 2022?
Yes. Npcap 1.78 is signed for Windows 11 22H2 and Server 2022. If HVCI blocks the driver with code 0x80070241, temporarily disable Core isolation → Memory integrity, install Npcap, and re-enable HVCI; the signed driver is added to the allow-list on the next successful load.