Resolving KTP600 HMI Login Loops and Slow Tag Update Cycles

David Krause12 min read
HMI / SCADASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

The SIMATIC KTP600 Basic color PN (catalog number 6AV6647-0AD11-3AX0 and siblings in the 6AV6647-0xxx family) is a 6-inch basic panel widely used with the SIMATIC S7-1200 1214C and TIA Portal V13/V13 SP1. Two issues consistently surface during commissioning: a "login loop" in which the operator is returned to the calling screen after a successful password entry, and a slow tag refresh that causes the value field to skip rather than ramp. Both are configuration issues in the WinCC project, not hardware faults.

This reference walks through the cause of each symptom, the exact configuration path in TIA Portal V13, the auxiliary settings that frequently trap first-time integrators (login attempt limiter, password reset lockout, update cycle of HMI tags, acquisition mode), and a verification matrix that can be run on the shop floor before signing off a project.

Scope: The procedures below are valid for TIA Portal V13, V13 SP1, and the matching WinCC Basic/Comfort (TIA Portal) image. KTP600 Basic panels are configured with WinCC Basic; KTP600 Comfort panels are configured with WinCC Comfort. TIA Portal V13 SP1 Update 6 or later is recommended for S7-1200 firmware V4.x CPUs.

System Context and Versions

Component Version / Catalog Notes
KTP600 Basic color PN 6AV6647-0AD11-3AX0 (6" TFT, 256 colors, PN interface) WinCC Basic configured
S7-1200 1214C 6ES7214-1AG40-0XB0 (DC/DC/DC) or 6ES7214-1BG40-0XB0 (AC/DC/RLY) Firmware V4.x recommended for V13 SP1
TIA Portal V13 / V13 SP1 / V13 SP1 Update 6+ Comfort license required only for Comfort panels
HMI Runtime Image version matches TIA Portal project Auto-compiled into panel firmware by ProSave

Before changing any property, confirm the panel catalog number, the firmware version loaded in the HMI, and the TIA Portal project version. A mismatched image version is the leading cause of attributes appearing to "do nothing" after download.

Problem 1 — Login Returns to the Calling Screen

Symptom

When the operator presses a button protected by an authorization level, the SIMATIC login dialog appears. After a correct user name and password are entered, the dialog closes and the operator is returned to the original screen. The button must be pressed a second time to activate the screen change, the function key, or the tag write that the button was meant to perform.

Root Cause

This is the documented behavior of WinCC TIA Portal: the security check on a button is a one-shot validation against the current user record. After a successful login, control returns to the screen object that requested the check, but the original event that triggered the button (e.g. ActivateScreen, SetBit, TriggerTag) has already been consumed. The user must re-trigger it. There is no built-in "on successful login, fire the original event" hook on the button object itself.

The standard remedy is one of the following patterns:

  1. Two-step operator UX: explicitly instruct the operator to log in first, then press the action button. The button's authorization check still gates the action; the loop is intentional and the operator simply re-presses.
  2. Project-side login screen: call the login dialog yourself from a screen change or a function key, store the result, and only then navigate. This pattern places the user record in the HMI runtime before any protected object is touched.
  3. System function in the user view's "OnLoggedIn" callback: in WinCC TIA Portal V13 the Login user view has a configurable OnLoggedIn / OnLoggedOut event that fires when the runtime user changes. Drive the screen activation from this event to avoid the second press.
Bonus trap: If the user administration contains the option "Enable limit for log-in attempts" (default: enabled, e.g. 3 attempts) the user is permanently locked out after the threshold is reached. The only recovery is to open the project on the engineering station and re-enter the password. Disable this option during commissioning or set the count high enough that operators do not lock themselves out.

Configuring the User Administration on the KTP600

  1. In the TIA Portal project tree, expand Devices & Configuration > [KTP600] > Runtime settings > User administration.
  2. Click Users and add a new user. Assign a group (e.g. Operator, Supervisor, Administrator).
  3. Add the corresponding authorization numbers (1..9) under Authorizations. Each button that should be protected is assigned a number; the user must hold that number in their group.
  4. Open the protected button: Properties > Security > Authorization. Uncheck "Allow operator control without authorization" and enter the number that matches the user group.
  5. For a function key, open Properties > General > Runtime authorization and select the same number.
The fields in the user view are NOT the same as the runtime security check on a button. Setting the field-level "Operator Control" property (with the box checked) only allows the user to acknowledge alarms or enter values; it does not gate button-driven screen changes. Always assign an explicit authorization number.

Eliminating the Second Press — Login Screen Pattern

For panels that need a true one-click transition after authentication, build a dedicated login screen that uses the system function LogOn (in the "Users" PLT) and the OnLoggedIn event of the user view to drive ActivateScreen with the original target screen stored in a local HMI tag.

  1. Create a screen Login that contains a User view object (Toolbar > User view). This object supplies the username/password fields and the OK/Cancel buttons automatically.
  2. Configure a string tag PendingTarget (internal HMI tag) that is written by the calling button before it calls ActivateScreen "Login". This stores where to go after authentication.
  3. On the OnLoggedIn event of the user view (Configure event > Add function), add a script or system function that reads PendingTarget and calls ActivateScreen "<PendingTarget>" using a name-based activation.
  4. On OnLoggedOut, return the operator to the home screen.

This pattern is exactly what the integrator is recalling as having seen in a finished project. It is not a property of the button; it is a screen-level choreography.

Password Lockout and the "Login Attempt Limit" Checkbox

Setting Default Effect Recommendation
Enable limit for log-in attempts Off in V13, depending on profile Locks user after N failed attempts Leave disabled during commissioning; enable per policy in production
Number of allowed attempts 3 Triggers lockout Raise to 5–10 if the policy is required
Password aging Off Forces password change after N days Disable unless site mandates it
Logon timeout 0 (no timeout) Auto-logout after inactivity (min) Set 5–15 min for operator panels

When a user is locked, the panel does not offer a "forgot password" link. The only recovery path is to open the project in TIA Portal, navigate to User administration > Users, and re-enter the password. The new password is then transferred on the next project download or on a panel-side import of the user list (ProSave > HMI Files > Recipe/User Administration).

Problem 2 — Tag Update Cycle is Too Slow

Symptom

The HMI displays a tag value (e.g. a timer, a counter, or a PLC integer) but the value only updates in large steps every several seconds. The display "leaps" instead of ramping.

Root Cause

By default, an HMI tag is acquired with a 1-second update cycle and the cyclic in operation acquisition mode. Three properties combine to determine how often the value is refreshed on the screen:

  1. Acquisition mode (Cyclic in operation / Cyclic continuous / On demand) — controls when the runtime polls the PLC.
  2. Update cycle (100 ms, 200 ms, 500 ms, 1 s, 2 s, 5 s, 10 s, 1 min, …) — controls the polling interval.
  3. Display refresh on the screen object (output field, bar, etc.) — bound to the same tag and inherits the cycle.

If the tag is acquired "On demand", the runtime only reads the tag when it is displayed; the screen must be on and the object must be re-drawn. Combined with the default 1-second cycle, this gives the appearance of a sluggish display.

Tuning Update Cycles in TIA Portal V13

  1. Open HMI tags in the project tree, double-click the tag whose display is too slow.
  2. In Properties > General, set:
    • Acquisition mode: Cyclic continuous (most reliable; polls the tag in the background even when not on screen)
    • Update cycle: 100 ms for fast timers/counters, 200 ms as a default, 500 ms for trend displays
  3. Verify the cycle is not constrained by the PLC's pointer area or by the connection. For a 1:1 PROFINET connection the S7-1200 1214C can sustain 100 ms cycles for a few hundred tags without load. For very large tag counts (1 000+), increase to 200–500 ms.
  4. Re-compile the project, download the HMI image, and observe the field.
Constraint: A Basic panel cannot poll faster than 100 ms per tag; some panel images only allow 200 ms as the minimum. Comfort panels support 100 ms. The available cycles are listed in the dropdown of the tag's Update cycle property and are panel-dependent.

Tag Acquisition Mode Decision Matrix

Acquisition mode Behavior Use when
Cyclic continuous Runtime polls tag continuously regardless of screen Counters, timers, alarms, value displayed on multiple screens
Cyclic in operation Runtime polls tag only while the screen with the object is active Screen-specific values, setpoint entry, recipes
On demand Runtime reads tag only when the object is redrawn Static labels, slow-changing diagnostic data

Additional Diagnostics for the Update Problem

  1. Confirm that the connection to the PLC is online. In the HMI runtime, the status bar (configurable) shows Connected / Disconnected. A "Disconnected" status freezes all cyclic updates.
  2. Open the connection in TIA Portal Devices & Networks, check the partner IP and subnet. A wrong subnet mask is the single most common cause of the panel going into repeated connection retries.
  3. Check the PLC's protection level. If the CPU is in Read/Write protection with a password that the HMI does not know, the HMI will read zero or the last good value, which the operator perceives as a "frozen" value.
  4. Check the tag address in the PLC. The HMI is asking for a non-existent DB or offset, and the PLC returns an error that the HMI silently ignores. Validate the address in the watch table of the PLC.
  5. Disable any Job Mailbox or Data Block Pointer areas that are not used. Spurious job mailbox usage can stall cyclic traffic on Basic panels.

Question Marks Not Displaying in Text Fields

The original poster also reports that question marks (and sometimes other ASCII characters) do not render in text I/O fields. The cause is the panel's default text font. The KTP600 Basic ships with a font set that does not always include the full ASCII printable range. The remedy is to assign a font that contains the character, e.g. a TTF embedded in the project.

  1. Open the I/O field in the screen editor: Properties > Appearance > Font.
  2. Select a font that is bundled with the panel image. Arial and Tahoma are typical candidates that include the question mark glyph.
  3. If the question mark appears as a fallback box, embed the font into the project: Project tree > Languages & Resources > Project fonts, add a TTF, and reference it on the I/O field.
  4. Re-download the project to the panel and verify the character renders.
On WinCC Basic, the panel's default font is fixed. If a project uses a custom TTF that is not deployed to the panel, the runtime falls back to its default font, which may not contain all glyphs. The question-mark issue is almost always a missing glyph in the deployed font set, not a project setting.

Verification and Commissioning Checklist

Step What to verify Pass criterion
Compile TIA Portal compiles the HMI without warnings 0 errors, 0 warnings related to tags, screens, or user admin
Image download ProSave / TIA download completes Panel reboots, runtime starts automatically
Connection Status bar shows connection to PLC Status: connected, partner IP matches
User admin Create operator, assign group, set password User can log in via user view; locked-out count = 0
Login attempt limit Set to "Off" during commissioning Three wrong passwords do not lock the user
Protected button Authorization set on button; user holds group Button performs its event after login (or two-step UX is acceptable)
Update cycle Tag set to Cyclic continuous, 100–200 ms Display updates visibly faster than 1 s
Question mark glyph Font set on I/O field includes ASCII ? and other ASCII printables render
Logout User is logged out after timeout or manual logout Protected button requests login again

Troubleshooting Matrix

Symptom Likely cause Where to look
Login dialog returns to original screen Button event was consumed by security check Use user-view OnLoggedIn event; protect object, not event
User locked out Login attempt limit reached Disable limit; reset password in TIA Portal
Tag freezes at 0 or last value Connection offline, protection level, wrong address Status bar; PLC watch table; connection in Devices & Networks
Tag updates in steps every 1–2 s Default 1 s cycle, on-demand acquisition HMI tag > Acquisition mode + Update cycle
? not shown in I/O field Default font glyph missing Assign Arial/Tahoma or embed TTF in project
Buttons grayed out User logged out, no group matches authorization User administration > Group assignment
Download fails Version mismatch between TIA project and panel OS ProSave > OS Update; recompile project

References for Further Verification

Engineers implementing these fixes should always cross-check the panel-specific manual and the WinCC TIA Portal online help against the project at hand. Authoritative entry points:

FAQ

Why does the login dialog return to the original screen on my KTP600 instead of opening the target screen?

The button's security check consumes the click event that was meant to trigger the screen change. After a successful login, the runtime returns to the calling screen with no pending event. Use a dedicated login screen with the user view's OnLoggedIn event, or accept the two-step UX in which the operator logs in and then re-presses the button.

How do I change the update cycle of an HMI tag in TIA Portal V13?

Open HMI tags in the project tree, double-click the tag, and set Acquisition mode = Cyclic continuous and Update cycle = 100 ms (or 200 ms on Basic panels). Re-compile and re-download the HMI image.

What is the minimum update cycle on a KTP600 Basic?

WinCC Basic on the KTP600 supports 200 ms as the practical minimum; some images allow 100 ms. Comfort panels support 100 ms cleanly. Cycles faster than these are silently rounded up by the runtime.

How do I unlock a user who has been locked out by the login attempt limit?

Open the TIA Portal project on the engineering station, navigate to User administration > Users, and re-enter the password. Download the project (or just the user list via ProSave) to the panel. The locked counter resets on the next successful login. Best practice is to disable the limit during commissioning.

Why are question marks not shown in I/O fields in runtime?

The default font shipped with the panel may not include the question-mark glyph. Assign a font such as Arial or Tahoma, or embed a TTF in Languages & Resources > Project fonts, and reference it on the I/O field. Re-download the project to the panel.

Back to blog