Resolving MP277 Back-Transfer PLZ File Error in WinCC Flexible

David Krause17 min read
SiemensTroubleshootingWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

Field engineers maintaining legacy SIMATIC installations routinely face the need to recover the editable configuration of a deployed HMI panel for modification, audit, or migration. On the SIMATIC MP277 8" Touch — a Windows CE 5.0 based multi-panel that succeeded the MP270B and preceded the Comfort Panel TP700 Comfort line — the canonical recovery path is back-transfer through SIMATIC WinCC Flexible 2008 over Ethernet. When the upload attempt aborts with Could not find the PLZ file or stalls indefinitely at Establishing connection to device, the symptom is almost never a network fault. Healthy ICMP echo, correct IP addressing, and crossover-cable connectivity are necessary but insufficient. The root cause is that the panel-side project archive is absent from flash because the original commissioning engineer did not enable the back-transfer option when the project was downloaded.

This reference documents the diagnostic flow, separates the four legitimate recovery paths, indexes the file-system taxonomy inside the MP277, and lists the prevention steps that eliminate this failure mode at the next transfer. The same logic applies to the MP277 10" Touch and the MP277 12" Touch variants; only the panel part number and screen geometry differ.

Affected Hardware, Software, and File Formats

Component Identifier / Version Notes
HMI panel SIMATIC MP277 8" Touch Order numbers 6AV6 643-0CD01-1AX1 / -1AX2; color TFT 800 × 480
Panel OS Windows CE 5.0 Runtime shipped per panel variant; HSP upgrades available
Configuration software SIMATIC WinCC Flexible 2008 SP1 / SP2 / SP3 / SP4 ES + RT package; SP4 is the terminal release of the 2008 line
Standalone backup tool ProSave v9.x (WinCC Flexible 2008) or v12.x (TIA Portal) Installed alongside WinCC Flexible from the same DVD
Transfer cable RJ45 Ethernet crossover or switched LAN Later MP277 hardware revisions support Auto-MDIX
Storage MMC/SD slot (option) and USB 1.1 host Some MP277 units ship without an SD slot fitted
Editable archive *.plz (compressed project) Created only when back-transfer is enabled at download
Compiled runtime *.pdata, *.hmirtm, supporting *.dll Always created by transfer; not editable
Compiled backup *.psb Created by ProSave; not editable; restore requires same panel MLFB

Refer to the Siemens MP277 product support page and the SIMATIC WinCC Flexible 2008 system manual for canonical part numbers, firmware HSP revisions, and configuration limits.

Observed Error Strings and Diagnostic Decision Tree

Three failure messages surface under the documented symptom set. Match the strings before assuming a deeper issue.

  • Could not find the PLZ file. — Issued by WinCC Flexible or ProSave during the back-transfer handshake. The tool has authenticated with the panel, requested the PLZ archive, and received an empty or missing response.
  • Establishing connection to device... — Transfer progress stalls at this phase. The TCP session is alive but the HMI runtime is not serving the expected archive endpoint.
  • %1 is not a valid Win32 application. — Windows Explorer rejection when an operator double-clicks a panel-side binary (PDATA, HMIRTM, or supporting DLL) on a USB stick. These are ARM-compiled CE 5.0 binaries, not x86 Win32 executables.
Critical: A valid Ethernet session — including a successful ping — does not confirm the back-transfer will succeed. The PLZ file is a discrete artefact inside the panel's flash file system; its presence is governed by the back-transfer flag selected at the original download, not by the runtime configuration of the panel or the cable used.

Diagnostic decision flow:

  1. Confirm ping <panel IP> returns < 10 ms on the local subnet. If not, stop here and troubleshoot the network.
  2. Verify the panel Control Panel > Transfer > Ethernet channel is enabled. If not, stop here and enable it.
  3. Initiate the WinCC Flexible Back-transfer. If the PLZ error appears, the back-transfer flag was not set at the original download.
  4. Launch ProSave and attempt a Backup. A successful PSB confirms the compiled runtime is intact even though the editable PLZ is missing.
  5. If the backup fails, the runtime image itself is corrupt; the panel needs to be re-flashed or replaced.

Root Cause — Missing Backtransfer Flag

WinCC Flexible 2008 writes a compressed copy of the editable project to the panel whenever the operator selects Project > Transfer > Transfer Settings in the download dialog and enables Enable back-transfer. The archive is the .plz file referenced by the error string. If the checkbox is cleared — a default state in some automated deploy scripts and common when commissioning engineers are unaware of the implication — the panel never receives the PLZ file. Subsequent back-transfer attempts correctly report that the archive cannot be found, because it never existed on the panel.

This is fundamentally different from a transfer failure, a cable fault, or a routing problem. The PLZ file is a one-time write artefact; its absence is permanent for that project version on that panel, unless the project is re-downloaded with the flag set.

The compiled runtime files (PDATA, HMIRTM, DLLs) are always present because they are required for the HMI to execute. Their presence is what makes a ProSave backup possible; their absence would mean the panel cannot run at all. Confirming that ProSave can read the panel is therefore strong evidence that the runtime image is healthy and only the back-transfer archive is missing.

Network Configuration and Validation

Although network faults are not the root cause of the PLZ error, misconfigured connectivity will mask the real issue and consume troubleshooting time. Validate the following before assuming the back-transfer flag is at fault:

  1. Configure the PC Ethernet adapter to a fixed IPv4 address in the same subnet as the MP277. The factory default of the MP277 is typically 192.168.1.1 with mask 255.255.255.0; align the PC to 192.168.1.2 or a similar non-conflicting address.
  2. Disable the Windows firewall temporarily or open TCP port 5001 (HMI transfer) and TCP port 102 (S7ONLINE) inbound. WinCC Flexible uses port 5001 for the back-transfer handshake; port 102 is required only if STEP 7 is simultaneously programming the connected PLC.
  3. Ping the panel: ping 192.168.1.1. A successful echo confirms Layer 3 reachability but not service availability.
  4. From the PC, browse to \\192.168.1.1\ if file-share access has been enabled on the panel (Control Panel > Transfer > Enable file server). Listing the share confirms the TCP session WinCC Flexible will use.
  5. Confirm the MP277 Control Panel > Transfer settings: Enable both the channel (Ethernet) and the file-server option if LAN browsing is required.
  6. Confirm the destination PC is not on a different subnet or behind a managed switch with port 5001 blocked. Industrial firewalls frequently drop back-transfer traffic unless explicitly allowed.
Ethernet commissioning reference for MP277
Parameter Typical Value Where to Set
Panel IP address 192.168.1.1 Control Panel > Network > Ethernet
Subnet mask 255.255.255.0 Control Panel > Network > Ethernet
PC IP address 192.168.1.2 Windows Network Connections
HMI transfer port (TCP) 5001 Firewall inbound rule
S7ONLINE port (TCP) 102 Firewall inbound rule (only if STEP 7 in use)
File server Enabled Control Panel > Transfer > Enable file server
Auto-MDIX Yes (later revisions) Hardware-dependent; no setting

Only when Layer 3 and the transfer service are healthy does the Could not find the PLZ file error reliably point at the missing archive rather than a connectivity issue.

Recovery Path A — ProSave Compiled Backup (PSB)

ProSave is the standalone backup utility that ships on the WinCC Flexible 2008 DVD and the TIA Portal DVD. Even when the back-transfer flag was not set, ProSave can pull the compiled runtime image from the panel. The resulting archive is an exact panel-state snapshot, not an editable source project.

Procedure:

  1. Launch ProSave from Start > SIMATIC > ProSave or C:\Program Files\Siemens\Automation\WinCC Flexible\ProSave.exe.
  2. In the Device type drop-down select MP277 Touch 8". The field is driven by the panel MLFB; choosing the wrong family causes an immediate handshake abort.
  3. Set the Connection to Ethernet and enter the panel IP address.
  4. Click Connect. The status pane should report the panel type and firmware version. A failure here indicates a network or firewall problem — re-validate using the procedure above before continuing.
  5. Select the Backup tab. Choose a destination *.psb file on local disk. Tick Include recipes and Include passwords if the application requires them.
  6. Click Start Backup. ProSave reads the PDATA, HMIRTM, and DLL files from the panel and writes them to the PSB archive. Progress is reported per file in the status pane.
  7. After completion, store the PSB alongside the engineering project files. Use the Restore tab to deploy the PSB back to the same panel part number.
Important: ProSave Restore requires the target panel MLFB to match the backup source exactly. The PSB cannot be opened or edited in WinCC Flexible — attempting to do so produces a file-format error. Treat the PSB as a recovery artefact for an identical panel, not as a portable source.

Recovery Path B — Storage Media File Extraction

Engineers frequently attempt to extract the project files directly to a USB stick from the MP277 Control Panel > File Explorer and then open them on the PC. The visible files on the storage media will include the compiled artefacts, not the editable PLZ. This is expected: the panel's runtime stores PDATA, HMIRTM, and supporting DLLs because the runtime needs them; it does not store the PLZ unless the back-transfer flag was enabled at download.

What you can do with extracted files:

  • Compare file timestamps and SHA-256 hashes against a known-good deployment to confirm a particular runtime image was installed.
  • Use a hex viewer on the PDATA file to extract string constants, IO field references, and script snippets. Useful as a forensic recovery for tag names, alarm texts, and screen layouts, but not a clean source rebuild.
  • Re-flash the panel to a known-good backup via ProSave Restore, using the PSB archive as the source.
  • Cross-reference extracted string constants against PLC tag databases (for example, a STEP 7 symbol table export) to confirm the panel was talking to the expected PLC tag set.

What you cannot do with extracted files:

  • Open them as a WinCC Flexible project. The error %1 is not a valid Win32 application indicates that Windows is attempting to execute an ARM-CE binary under x86 Win32 — a category mismatch, not a file corruption.
  • Edit screens, tags, alarms, scripts, or schedules. The PDATA and HMIRTM files are already-compiled runtime representations and contain no editable metadata layer.
  • Restore them to a different panel variant. PDATA / HMIRTM files are bound to the panel MLFB on which they were compiled.

Recovery Path C — Re-Enable Backtransfer via Re-Download

If the engineer still has access to the original WinCC Flexible source project (.hmi), the missing PLZ can be regenerated in a controlled re-transfer that explicitly enables back-transfer. This is the only path that produces an editable archive on the PC.

  1. Open the original .hmi project in WinCC Flexible 2008 on the engineering station. Verify the project version matches the deployed panel; mismatched projects cause runtime faults at first screen change.
  2. Select Project > Transfer > Transfer Settings.
  3. In the Transfer Settings dialog, set the mode to Ethernet, enter the MP277 IP, and tick Enable back-transfer.
  4. Tick Overwrite all files on target if the goal is to confirm the panel matches the design exactly. This resets runtime data — recipes, logged alarms, and user data are not preserved unless they were configured to write to external storage.
  5. Click Transfer. The project is recompiled, sent to the panel, and the panel writes the PLZ archive to its flash. The transfer dialog displays the individual files transmitted and their byte counts.
  6. After the panel reports a successful transfer, initiate the back-transfer: Project > Transfer > Back-transfer. The PLZ is uploaded to the engineering station and unpacked into a directory structure that WinCC Flexible can open and edit.
Warning: This operation overwrites the deployed runtime image. Schedule a maintenance window and capture the existing PSB backup (Recovery Path A) before initiating the re-transfer. Any recipe data, alarm logs, or trend archives in the panel memory will be lost unless they were configured to write to external storage (MMC/SD/USB). Coordinate with operations before triggering an Overwrite-all transfer.

Recovery Path D — Source Project from Original Designer

When the editable source is genuinely unavailable and re-enabling back-transfer is not an option — no WinCC Flexible source on hand, panel cannot be re-flashed for production reasons — the only remaining path is to recover the project from the original designer or commissioning contractor. The Siemens Industry Online Support portal can route requests to the regional engineering team that built the project if the original integrator is not reachable, and contract records typically name the responsible engineering organization.

This path is administrative rather than technical and is included for completeness because it is the answer most commonly received from the OEM in the documented failure mode. Document the request with the panel MLFB, firmware HSP, and any visible string constants recovered via Path B so the original designer can identify the correct revision quickly.

PLC Integration, Recipes, and Runtime Data Handling

The MP277 does not exist in isolation. It is the HMI half of a STEP 7 (or third-party PLC) control system, and several runtime concerns affect the choice of recovery path:

  • PLC connection integrity. A ProSave backup captures the panel-side runtime but not the PLC project. After a panel re-flash, the PLC tags must still match the recovered project or the panel will display connection-error alarms on first start.
  • Recipe handling. Recipes stored on the panel are included in a ProSave PSB only when Include recipes is ticked at backup time. Re-downloading the project (Path C) wipes recipes unless the destination was configured to retain them via Project > Recipes > Settings > Persist.
  • Alarm and trend archives. Logs are written to the panel's flash by default. Re-downloading clears them. If long-term logs are required, configure the project to write to an MMC/SD card or a remote PC via the file server before initiating any recovery.
  • User administration. Passwords and user lists on the panel are wiped on Overwrite-all transfer. Capture a PSB first if user credentials need to survive the recovery.
  • Tag consistency. If the panel tag database was edited independently of the PLC, the recovery project must be reconciled against the actual PLC tag names. The PLC is the source of truth.
Runtime data impact by recovery path
Path Recipes Alarms / Trends Users / Passwords PLC Project
A — ProSave PSB Retained if option ticked Retained if option ticked Retained if option ticked Not captured
B — USB extraction View only View only View only Not captured
C — Re-download Wiped unless persisted Wiped Wiped Unaffected
D — Source recovery Depends on recovery contract Depends on recovery contract Depends on recovery contract Unaffected

Prevention, Migration, and TIA Portal Path

Establish a site-wide commissioning policy that requires Enable back-transfer to be checked for every project deployed to a SIMATIC panel. Treat it as a default-on setting rather than an opt-in flag. Add a stage in the commissioning checklist: Back-transfer verified — PLZ archive downloaded and re-opened in WinCC Flexible. This forces a round-trip test rather than a checkbox assertion.

Keep the WinCC Flexible source under version control (SVN, Git, or a controlled engineering file share). The PLZ is a recovery artefact, not a primary source. Take a ProSave PSB backup immediately after every commissioning step; the PSB is the only artefact that can rebuild a panel to a known-good runtime state without re-compiling. Tag every deployed panel with its project version, panel part number, and the date of the last successful back-transfer. This information is what an emergency service call needs to triage a missing-source incident.

Migrate legacy MP277 installations to TIA Portal / WinCC Comfort Panels where budget permits. The Comfort line (TP700 Comfort, TP900 Comfort, TP1200 Comfort) preserves the back-transfer workflow with a modernised toolchain. The TP700 Comfort is the direct 7" successor (part number 6AV2 124-1MC01-0AX0); the 9" TP900 Comfort (6AV2 124-1JC01-0AX0) and 12" TP1200 Comfort (6AV2 124-1MC02-0AX0) round out the family. Projects authored in WinCC Flexible 2008 can be migrated into TIA Portal V13 or later using the Migrate Project wizard. The migrated project retains tags, screens, alarms, and scripts, although some VBScript constructs require manual adjustment for the newer scripting runtime.

Once on TIA Portal, the back-transfer workflow is identical in concept but executed through Online > Backup from device and Online > Restore to device. The PLZ archive analogue is the TIA Portal *.ap project backup, which is created on the panel by default regardless of a flag because the TIA Portal transfer settings enforce it. Refer to the TIA Portal migration guide for procedural detail.

Troubleshooting Matrix and Field Verification Checklist

Quick triage of MP277 back-transfer symptoms
Symptom Likely Cause Confirm By Resolution
Could not find the PLZ file Back-transfer flag not set at original download Inspect panel Control Panel > File Explorer for .plz; ProSave backup still succeeds Re-download with flag enabled (Path C) or accept compiled-only backup (Path A)
Transfer hangs at Establishing connection Network service not started on panel, wrong IP, blocked port 5001 Panel Control Panel > Transfer settings; telnet <IP> 5001 from PC Enable Ethernet channel, fix addressing, allow port 5001 inbound
Not a valid Win32 application Attempting to execute ARM-CE binary on x86 Windows File properties > Type Do not open; use ProSave to backup and re-archive
ProSave backup fails partway Insufficient storage, bad cable, panel in transfer-mode lock ProSave log file in %TEMP%\Prosave.log Free disk space, replace cable, restart panel
Restore fails: wrong panel type Target panel part number differs from backup source Compare MLFBs on panel nameplate ProSave restore requires identical MLFB; deploy source project instead
Back-transfer succeeds but PLZ is empty Source .hmi project was empty at download time Inspect panel-side PLZ file size Re-download a populated project with back-transfer enabled
Ping works but transfer fails TCP 5001 blocked by Windows firewall or managed switch telnet <IP> 5001 returns connection refused Allow inbound TCP 5001 on PC firewall and switch ACL

Field-commissioning verification checklist:

  1. Confirm ping <panel IP> returns < 10 ms on local subnet.
  2. Verify the panel Control Panel > Transfer > Ethernet channel is enabled and Enable file server is on if LAN browsing is required.
  3. Re-download the project with Enable back-transfer checked, and document the timestamp.
  4. Immediately perform a back-transfer from the panel to confirm the PLZ round-trips correctly and the recovered project opens in WinCC Flexible.
  5. Take a ProSave PSB backup to local disk and store alongside the project source.
  6. Record panel part number (MLFB), firmware HSP, and project version in the site asset register.
  7. Verify recipe, alarm, and trend persistence paths are configured to external storage before the next Overwrite-all transfer.
  8. If migration to TIA Portal is in scope, plan the migration during the next scheduled outage rather than during an emergency recovery.

FAQ

Why does WinCC Flexible report "Could not find the PLZ file" when the network is healthy?

The PLZ archive is written to the MP277 flash only when Enable back-transfer is ticked during the original download. A successful ping confirms Layer 3 connectivity but cannot create an archive that was never written. Re-download the project with the flag enabled, or accept a compiled-only ProSave PSB backup as the recovery artefact.

Can I edit the files copied directly from the MP277 via USB?

No. The panel stores compiled runtime artefacts (*.pdata, *.hmirtm, supporting DLLs) that are ARM-compiled CE 5.0 binaries. Windows rejects them with "not a valid Win32 application" because the CPU architecture does not match. Editable project source exists only as a *.plz archive created when the back-transfer flag was enabled at download.

Can ProSave restore a PSB backup to a different MP277 part number?

No. ProSave Restore requires the target panel MLFB to match the backup source exactly. For a different panel part number, deploy the editable WinCC Flexible source project, recompile against the new panel target, and transfer with back-transfer enabled.

Does the MP277 support Auto-MDIX crossover cables?

Later hardware revisions of the MP277 support Auto-MDIX and accept either crossover or straight-through Ethernet cables. Early revisions require a true crossover cable. If ping fails outright, swap the cable before troubleshooting software settings.

What TCP port does WinCC Flexible use for back-transfer?

WinCC Flexible 2008 uses TCP port 5001 for the HMI transfer handshake over Ethernet. The S7ONLINE protocol on TCP port 102 may also be in use if the panel is simultaneously programmed by STEP 7. Open both inbound on any intermediate Windows firewall during commissioning.

How do I migrate an MP277 project to a TIA Portal Comfort Panel?

Open the WinCC Flexible 2008 .hmi project in TIA Portal V13 or later and run Project > Migrate project. Review the migration log for VBScript constructs that require adjustment, then recompile against the new Comfort Panel target (for example, TP700 Comfort, MLFB 6AV2 124-1MC01-0AX0) and transfer with the TIA Portal back-up enabled by default.

Back to blog