Resolving KTP400 Basic Start Screen Loop with S7-1200 PLC
The SIMATIC KTP400 Basic PN panel is a compact 4-inch operator interface widely used as a low-cost HMI for SIMATIC S7-1200 and S7-1500 controllers on PROFINET. One of the most frequently reported field failures is a continuous start-screen loop: the device boots into a white transfer/start/settings screen, never reaches runtime, and never establishes a tag connection to the PLC. In most cases the panel is healthy, the PROFINET cable is intact, and the CPU is running; the cause is a firmware / TIA Portal project compatibility mismatch combined with an outdated boot loader on the basic panel. This reference documents the diagnostic path, the recovery procedures, and the preventive settings for a stable KTP400 Basic to S7-1200 PROFINET link.
1. Affected Hardware and Catalog Numbers
The basic panels in scope are the second-generation KTP400 Basic PN units (4-inch, monochrome or color, single Ethernet port) listed in the table below. The first-generation 6AV6 647-0AA11-3AX0 / 6AV6 647-0AB11-3AX0 devices are also affected when paired with a TIA Portal V16+ project.
| Catalog number | Description | Display | Interfaces |
|---|---|---|---|
| 6AV2 123-2DB03-0AX0 | KTP400 Basic PN, mono | 4" mono FSTN, 4 grayscales | 1 × PROFINET (RJ45) |
| 6AV2 123-2DS03-0AX0 | KTP400 Basic PN, color (variant) | 4" TFT color 256 colors | 1 × PROFINET (RJ45) |
| 6AV6 647-0AA11-3AX0 | KTP400 Basic mono DP/PN (legacy) | 4" mono | PROFIBUS + PROFINET |
| 6AV6 647-0AB11-3AX0 | KTP400 Basic color DP/PN (legacy) | 4" color | PROFIBUS + PROFINET |
Key device parameters to verify on the type plate or in the TIA Portal device view:
- Article (MLFB) number
- Hardware (FS) version (e.g., FS:01, FS:02, FS:03, FS:04)
- Firmware version reported under Control Panel → System → Device (e.g., V13.0.1.0, V14.0.1.0, V15.1.0.1, V16.0.0.1)
- Boot loader version and date (e.g., Boot Loader V2.12 / 2016-08-17 for early FS:01/FS:02 hardware)
2. Root Cause Analysis
The start-screen loop on a KTP400 Basic connected to a S7-1200 has three well-documented root causes. The most common in the field is cause #1, but all three should be ruled out before a panel is replaced or returned.
2.1 TIA Portal V16 Image with Old Panel Firmware (most common)
The project is configured in TIA Portal V16 (or V15.1, V17, V18). When compiled, the HMI generates a runtime image that is signed and formatted for a specific minimum firmware. If the panel flash still holds a runtime image whose version is below the minimum required by the project, the boot loader refuses to launch it, drops into the loader menu, retries the transfer, and loops. This is the textbook case for a panel that boots correctly with an old TIA V13/V14 project but loops with a new V16 project.
| TIA Portal version | Minimum panel firmware accepted | Common panel image version |
|---|---|---|
| V13 / V13 SP1 | ≥ V13.0.0.0 | V13.0.1.x |
| V14 / V14 SP1 | ≥ V14.0.0.0 | V14.0.1.x |
| V15 / V15.1 | ≥ V15.0.0.0 | V15.1.0.x |
| V16 | ≥ V16.0.0.0 | V16.0.0.x / V16.0.1.x |
| V17 | ≥ V17.0.0.0 | V17.0.0.x |
| V18 / V19 | ≥ V18.0.0.0 | V18 / V19 image |
2.2 Corrupted Runtime Image in Flash
Power loss during transfer, an interrupted OS update, or a flash wear-out can leave an invalid image. The boot loader detects an invalid signature or checksum and falls back to the loader menu. The symptom is identical to cause #1 but is independent of the TIA version. It typically appears on a panel that previously ran fine and then began to loop after a power cycle, an attempted update, or a forced reboot during a transfer.
2.3 PROFINET Name / IP Conflict and Transfer Channel Stuck Open
When the panel is set to Transfer mode persistently (PN/IE mode, "automatic transfer" enabled) and no valid TIA device is found, the loader waits indefinitely for a transfer and re-displays the start menu on timeout. This is not strictly a firmware issue but presents the same observable loop. PROFINET device name and IP must match the TIA configuration exactly.
2.4 PLC Connection Profile Incompatibility
On the S7-1200 side, the HMI connection must be configured with a valid Connection resource. If the connection was deleted from the S7-1200 project, the HMI runtime establishes the TCP session and is dropped by the CPU's connection management, which on basic panels is reported as "connection interrupted" with a fallback to the loader on some firmware levels. This is rare and is usually a symptom rather than a cause.
3. Pre-Diagnostic Checklist
Before opening the loader menu or attempting an OS update, capture the following. Each is read in <30 seconds and is essential for a clean recovery.
- Panel article number and FS: read on the type plate on the back of the unit. The FS determines the latest firmware that can be installed.
- Current firmware and boot loader version: if the loader menu is reachable, choose Settings → Control Panel → System → Device. If not, see Section 4 for forced entry.
- TIA Portal version used to compile the project: Help → Installed Software on the engineering station. The TIA version determines the minimum required image.
- PROFINET device name and IP of the panel: in the loader menu under Settings → Network (or Control Panel → Network and Dial-up Connections).
- S7-1200 firmware and PROFINET device name: read from TIA Portal online or via the CPU display (if the CPU is a 1214C/1215C/1217C with display).
- PROFINET topology: confirm cabling, switch ports, and the absence of any duplicate IP on the subnet.
4. Forcing Entry to the Loader and Control Panel
On a panel that boots into a continuous white screen, access the loader by holding the touch in a specific zone during power-up. The procedure below is field-proven for KTP400 Basic PN (FS:01 through FS:05).
- Power off the panel (24 V DC off).
- Press and hold finger #1 on the upper-left corner of the touch area and finger #2 on the lower-right corner simultaneously.
- Apply 24 V DC while continuing to hold both touch points for ~5 seconds after the backlight turns on.
- Release; the panel enters the Loader menu (Transfer / Start / Settings).
- Tap Settings to open the Control Panel. From here navigate to System → Device to read firmware, and to System → Backup / Restore to perform an OS update.
5. Compatibility Matrix: TIA Portal ↔ KTP400 Basic Firmware
The table below is the de-facto compatibility matrix that the Siemens Product Support and Support Request tools use to triage this exact symptom. Use it to decide whether the project needs to be re-targeted to an older TIA or whether the panel needs a newer OS.
| Project compiled with | Required panel image | Can it run on V16-compiled image if panel is on V14 image? | Recommended path |
|---|---|---|---|
| TIA V13 / V13 SP1 | ≥ V13.0.0.0 | Yes | Keep TIA version; transfer project |
| TIA V14 / V14 SP1 | ≥ V14.0.0.0 | Yes (forward only if V14 image is present) | Transfer project; panel will auto-upgrade |
| TIA V15 / V15.1 | ≥ V15.0.0.0 | Yes (panel boots into loader if V14 image is in flash) | Run OS update first |
| TIA V16 | ≥ V16.0.0.0 | No — boot loader loops because V14/V15 image is not signed for V16 container | Run OS update to V16 image before transfer |
| TIA V17 | ≥ V17.0.0.0 | No | Run OS update to V17 image |
| TIA V18 / V19 | ≥ V18.0.0.0 | No | OS update to V18 / V19 image |
For the case described in the field report (TIA Portal V16, panel with boot loader V2.12 / 2016-08-17), the only stable resolutions are:
- Path A — Update the panel OS to a V16.0.x image via ProSave or TIA Portal OS Update.
- Path B — Re-create the project in TIA Portal V13 SP1 / V14 SP1 to match the older panel image.
Path A is the correct engineering path. Path B is acceptable only when the project is small and there is no in-house TIA V16+ license available.
6. Recovery Procedure: Forcing an OS Update on the Panel
6.1 Prerequisites
- A Siemens programming PC with TIA Portal installed in the same version as the project (V16 in this case), or a standalone installation of SIMATIC ProSave matching the panel image.
- Ethernet connection between the PC and the panel, point-to-point or via the same PROFINET subnet as the S7-1200. Disable the PC firewall during the update to avoid ARP/ICMP filtering.
- The correct panel image (HSP or *.upd file) for the KTP400 Basic PN. The image is bundled with the TIA Portal installation under Support > Panel Images > Basic Panels > KTP400 and is also available on the Siemens Industry Online Support as the "SIMATIC KTP400 Basic PN Image Update" package.
- Static IP configured on the PC (e.g., 192.168.0.10 / 255.255.255.0) to be in the same subnet as the panel.
6.2 Update via TIA Portal
- Open the project in TIA Portal V16.
- In the project tree, right-click the HMI device and select Online → HMI Device Maintenance → OS Update.
- Select the target panel by PROFINET device name or by entering its IP.
- Browse to the PanelImages folder inside the TIA installation directory and select the appropriate .upd file for the KTP400 Basic PN.
- Confirm. The panel will reboot into update mode, the update will run (~3–8 minutes), and the panel will restart automatically.
6.3 Update via ProSave (Standalone)
- Start ProSave on the PC.
- Set Device type = KTP400 Basic PN, Connection = Ethernet.
- Enter the panel IP and click Connect. The panel must be in transfer/loader mode.
- Open the OS Update tab and click Update OS.
- Select the correct .upd image. Click Execute.
- Wait for the green Update complete status. Do not power off during this window.
6.4 Verification After OS Update
- Power-cycle the panel.
- Enter the loader and check Settings → Control Panel → System → Device → Firmware version. The reported image version must be ≥ V16.0.0.0.
- Transfer the project from TIA Portal V16 to the panel.
- Confirm the panel reaches the configured start screen and the S7-1200 reports the HMI connection in Online & Diagnostic → Connection information.
7. PROFINET Device Name and IP Configuration
The PROFINET device name is case-sensitive and must match the TIA Portal project exactly. Mismatches are a leading secondary cause of the start-screen loop because the panel keeps trying to be discovered and the loader retries transfer mode.
| Parameter | Value | How to set |
|---|---|---|
| PROFINET device name | Matches TIA Portal HMI device properties, e.g., hmiktp400-1
|
Control Panel → System → PROFINET IO, or assign via Online → Accessible Devices in TIA |
| IP address | Same subnet as the S7-1200, e.g., 192.168.0.50 / 255.255.255.0 |
Control Panel → Network and Dial-up Connections → PN interface |
| Default gateway | Leave blank unless routed PROFINET is used | Same menu |
| Transfer mode | Set to PN/IE if the panel is on PROFINET only | Loader → Transfer → Mode |
To assign the PROFINET device name from TIA Portal V16:
- In the project tree, right-click the HMI device and select Online → Accessible Devices.
- Select the panel by MAC address (printed on the type plate and on the back of the unit).
- Click Assign PROFINET device name. The name from the project is written to the panel.
- Power-cycle the panel to apply the name.
8. PLC Connection Profile on the S7-1200
The HMI connection on the S7-1200 side is a passive resource; the CPU does not "call" the HMI. The CPU only accepts incoming HMI connections on the configured connection. Verify:
- Devices & Networks → HMI_1 → Connections shows a valid S7 connection to the S7-1200 station.
- The S7-1200 has an active Web server license slot available (not directly required for HMI, but a useful diagnostic when a panel works on a bench but not in the cabinet — the web server exposes the same TCP port 102 that the HMI uses for the S7 protocol).
- The CPU's Connection resources count in the CPU properties is not exhausted. S7-1200 CPUs ship with a default of 6 PG, 6 OP, 6 S7 connections reserved; if all are consumed by other clients, the HMI connection is dropped silently.
- The CPU's Access level for the HMI connection in TIA Portal is set to HMI access with a password if one is required.
CPU connection resource count for common S7-1200 CPUs:
| CPU | Max S7 connections (total) | Reserved for PG / OP / S7 by default | HMI connections possible |
|---|---|---|---|
| CPU 1211C / 1212C | 8 | 1 / 1 / 8 | 1 + 5 dynamic |
| CPU 1214C / 1215C | 12 | 1 / 1 / 12 | 1 + 10 dynamic |
| CPU 1217C | 14 | 1 / 1 / 14 | 1 + 12 dynamic |
| CPU 1212C DC/DC/DC (FW ≥ V4.4) | 16 | 1 / 1 / 14 | 1 + 14 dynamic |
9. TIA Portal Project Settings That Trigger the Loop
Three project settings are known to produce the start-screen loop on a V16-compiled image even when the panel OS is up to date. Verify each before deployment.
- Panel image version lower than the TIA project. Open HMI_1 → Properties → Device configuration and check the image version. It must be ≥ the project's TIA version.
- Disable "Allow transfer via PN/IE" unticked. In Runtime settings → Services → Transfer, tick Transfer via PN/IE and set a transfer password if the line is shared with a process network.
- Configured area pointer mismatch. Wrong tag prefix, wrong DB number, or wrong area pointer for date/time / job mailbox causes runtime to drop and re-enter loader. Verify under Connections → Area Pointers.
10. Field Procedure: Step-by-Step Recovery
The procedure below consolidates Sections 4 through 8 into a single linear recovery script. Follow in order; do not skip the verification step at the end of each phase.
- Power off the panel. Disconnect the PROFINET cable from the S7-1200 side to rule out PLC interaction during OS update.
- Connect the engineering PC directly to the panel's PROFINET port. Set the PC IP to
192.168.0.10 / 24. - Power on the panel. Use the two-finger hold (Section 4) to enter the loader.
- Read the current firmware version and boot loader version; record both.
- Start TIA Portal V16 on the PC. Use Online → HMI Device Maintenance → OS Update with the appropriate .upd image.
- Wait for "Update complete". Power-cycle the panel.
- Re-enter the loader. Confirm the new firmware version is reported.
- Reconnect the PROFINET cable to the S7-1200 subnet.
- Assign the PROFINET device name from TIA Portal (Section 7).
- Compile the project (Hardware rebuild if any HMI tags were changed) and transfer the project to the panel.
- Run the panel. The configured start screen should appear within 15 seconds.
- In TIA Portal Online → Online & Diagnostics on the S7-1200, open Connection information. The HMI connection should be Established with a valid partner IP and connection ID.
11. Verification and Acceptance Test
After recovery, the following acceptance checks must pass before the panel is returned to production. Each test has a single pass criterion; do not accept a pass on a single screen refresh.
| Check | Method | Pass criterion |
|---|---|---|
| Panel boot into runtime | Power-cycle 5 times consecutively | Configured start screen appears within 15 s every cycle |
| HMI ↔ PLC connection | TIA Portal Online → Connections on the CPU | HMI connection status = Established |
| Tag update | Force a tag in TIA watch table, observe HMI | HMI displays the new value within 1 s (depends on acquisition cycle) |
| Power-down data retention | Power off for 60 s, restore power | Project reloads from flash, no loader menu |
| PROFINET station fault | CPU diagnostic buffer | No station-fault or name-mismatch entries in the last 24 h |
| Loader not visible to operator | Lock the loader with transfer password | Loader requires password to open from the touch |
12. Preventive Measures
- Lock the TIA Portal project version. When commissioning multiple panels of the same article, decide once whether the fleet will track the latest TIA version or stay on a fixed version. Mixing causes the start-screen loop at every re-deployment.
- Standardize on one panel image. Use the same .upd file for every panel in the machine park. Store the file under version control alongside the TIA project.
- Enable transfer password. Set a project password in Runtime settings → Services → Transfer. This blocks the loader menu and prevents accidental entry by an operator with a wet finger or a stuck key.
- Document the boot loader version. Capture the boot loader version at commissioning. A panel showing a 2016 boot loader is a candidate for proactive OS update to a current image.
- Avoid mid-transfer power interruptions. Schedule OS updates during planned downtime with a UPS on the 24 V DC supply.
- Use a fixed PROFINET device naming convention. Document the device name in the machine's electrical drawing. A panel re-installed after a field replacement with the wrong name will loop on first power-up.
13. When to Replace the Panel
A panel should be replaced rather than recovered when any of the following is true:
- OS update fails three consecutive times with the same .upd file (sign of flash wear or hardware fault).
- The boot loader does not respond to the two-finger hold (sign of corrupted boot loader; requires factory programming tool).
- The PROFINET port does not link up at all (link LED dark) and the panel is confirmed to be receiving 24 V DC within tolerance.
- The touch membrane is unresponsive in more than one quadrant (recoverable only with panel replacement on basic panels).
- The article number has been declared Phase-out by Siemens and no compatible image is available in TIA Portal V16+.
14. Related Errors and How They Differ
Several other panel faults present similarly but have a different root cause. The table helps triage at a glance.
| Symptom | Most likely cause | Distinguishing detail | Resolution |
|---|---|---|---|
| Start-screen loop (white / transfer / settings) | Firmware ↔ TIA mismatch or corrupted image | PROFINET link LED on; no project visible | OS update to match TIA version |
| Permanent white screen, no loader | Hardware fault or under-voltage on 24 V | Backlight may be on; touch unresponsive | Check 24 V DC ≥ 19.2 V, replace panel if OK |
| "Connecting to PLC" then loader | PROFINET name / IP mismatch | Loader reachable | Assign name from TIA |
| Project runs, all values "####" | Area pointer or DB access error | No loader shown | Recompile, re-check tag DBs |
| Touch offsets by several mm | Calibration lost or touch hardware fault | Loader and project both visible | Recalibrate via Control Panel |
| Project visible, no PLC connection | CPU has no free connection resource | Loader not shown | Free a connection on the CPU |
| Panel reboots every ~60 s | Watchdog in project or under-voltage | Loader not shown | Check 24 V DC stability |
15. Quick Reference Card
Print and keep near the cabinet:
- Symptom: KTP400 Basic loops on start screen, white background.
- First action: Power off. Hold upper-left and lower-right touch points. Apply 24 V. Release after 5 s.
- Read: Settings → Control Panel → System → Device. Record FW and boot loader version.
- Decision: FW ≥ TIA version? — Yes: recompile and retransfer. No: run OS update to matching image.
- OS update: TIA Portal V16 → right-click HMI → Online → HMI Device Maintenance → OS Update → select .upd for KTP400 Basic PN.
- Name/IP: TIA → Online → Accessible Devices → assign PROFINET device name.
- Verify: S7-1200 → Online & Diagnostics → Connection information → HMI = Established.
16. Engineering Notes and Caveats
- The KTP400 Basic PN does not ship with a Reset to factory defaults menu entry. Recovery is always by OS update or by a Siemens service center with the programming adapter.
- The 2016-dated boot loader (V2.12) on early FS:01 hardware is the oldest in the field that is still recoverable by OS update. A 2014 or earlier boot loader is not compatible with V16 images and the panel must be replaced.
- Some FS:01 hardware revisions have a known issue where the internal flash block size is too small to receive a V18+ image. TIA Portal V16 remains the highest recommended version for these early units; V17/V18 projects should be re-targeted to V16 for these specific article numbers.
- OS update via ProSave requires the same PC Ethernet subnet as the panel. Cross-subnet OS update is not supported on basic panels.
For product manuals, firmware images, and TIA Portal installation guides for the KTP400 Basic PN, refer to the Siemens Industry Online Support portal and the SIMATIC HMI Basic Panels product page at SIMATIC HMI. Compatibility matrices for TIA Portal versions and panel images are published in the TIA Portal release notes under Siemens Industry Online Support.
What causes the KTP400 Basic to loop on the start screen after a TIA Portal V16 download?
The panel's runtime image is older than the minimum required by TIA Portal V16 (≥ V16.0.0.0). The boot loader refuses to launch the image, drops to the loader menu, and retries indefinitely. Update the panel OS to a V16 image using TIA Portal Online → HMI Device Maintenance → OS Update or with SIMATIC ProSave.
How do I enter the loader menu when the panel is stuck on a white screen?
Power off the panel, press and hold the upper-left and lower-right corners of the touch area, apply 24 V DC, and continue holding for ~5 seconds after the backlight turns on. The loader menu (Transfer / Start / Settings) will appear. From there, Settings → Control Panel → System → Device shows the firmware and boot loader versions.
Can I keep TIA Portal V16 but recover an old KTP400 Basic with a 2016 boot loader?
Yes. The boot loader V2.12 / 2016-08-17 is compatible with V16 panel images. Run an OS update with the V16 .upd file from the TIA V16 installation directory, then re-transfer the project. Earlier boot loaders (2014 or older) on FS:01 hardware cannot be recovered and the panel must be replaced.
Do I have to re-create the project in an older TIA Portal version to fix the loop?
No. Updating the panel OS to match the TIA Portal version used to compile the project is the recommended path. Re-creating the project in TIA V13 or V14 is only required when an in-house V16+ license is unavailable and the project is small enough to be re-authored.
How do I confirm the HMI connection to the S7-1200 is established after recovery?
In TIA Portal, go online with the S7-1200, open Online & Diagnostics → Connection information. The HMI connection must be listed with status Established, the partner IP must match the panel, and the local connection ID must match the project's connection configuration. A status of Not established indicates a PROFINET name or IP mismatch.