Problem Statement: ProSave "Hardware Configuration Incompatible" on OP17 Restore
When the backup file *.psr produced by ProSave from one Siemens SIMATIC OP17 operator panel is restored to a different hardware variant of the same OP17 family, ProSave aborts the download and returns the following dialog message:
Downloading was not possible because the hardware configuration
of the operating unit is incompatible.
The transfer fails before any block is written to the panel. No partial restore is performed, no fallback to firmware-only update is attempted, and no automatic conversion of the archive takes place - the panel is left untouched and the engineering PC returns an error to the calling automation tool (for example, the ProSave command-line interface or the WinCC flexible migration wizard).
This fault occurs because every ProTool project is generated for one specific OP17 variant. The internal *.psr archive stores the device variant, the projected connection, the runtime image, and the configuration data in a single, sealed, signed bundle. ProSave performs a strict identity check against the target panel's self-identification string (returned via the OP17 boot loader protocol) and refuses to write if the part number or the projected interface does not match exactly.
The most common real-world trigger is the loss of an installed OP17-PP and the field substitution of an OP17-DP (or vice versa). The original ProTool source database (*.pdb) is rarely archived alongside the *.psr backup, so the engineering team is left with a sealed archive that cannot be edited and a panel that refuses to accept it.
Affected Hardware: SIMATIC OP17 Family
The OP17 is a 5.7-inch STN monochrome graphics operator panel from the legacy SIMATIC HMI OP-series, configured with ProTool /Pro and transferred with ProSave. Three hardware variants shipped with different on-board interfaces, and only the matching variant can accept the original *.psr archive.
| Variant | Order Number (MLFB) | Primary Interface | Projected Connection Type | Typical Application |
|---|---|---|---|---|
| OP17-PP | 6AV3 617-1JC00-0AX | RS232 / RS485 (PPI / MPI) | Point-to-point or MPI | Stand-alone serial link or MPI link to SIMATIC S5 / S7 |
| OP17-DP | 6AV3 617-1JC20-0AX1 | Profibus DP slave, MPI | Profibus DP, MPI | Direct Profibus DP slave to SIMATIC S7-300 / S7-400 |
| OP17-DP-12 | OP17-DP variant (extended) | Profibus DP up to 12 Mbaud, MPI | Profibus DP, MPI | High-speed Profibus networks using the DP-12 profile |
*.psr archive without rebuild.The OP17 uses a 9-pin Sub-D connector on the rear face for serial (PPI/MPI/Profibus) communication. Power is supplied via a separate 24 V DC terminal block. The front face carries a 5.7-inch STN monochrome LCD with 320 x 240 pixel resolution, a function-key membrane with system keys, and a numerical keypad. The same front bezel is used for PP, DP, and DP-12 variants; the difference is internal to the communication sub-assembly.
Root Cause: Project Lock to Hardware Variant
The *.psr archive is a vendor-proprietary compressed bundle generated by ProSave. Inside the archive, ProSave stores the following logical blocks:
- Device descriptor: target variant, MLFB, firmware revision compatibility window.
- Connection block: driver type (PPI, MPI, Profibus DP), baud rate, MPI/Profibus address, slot configuration, monitoring times.
- Compiled runtime image: compiled screens, tag database, recipes, alarm logs, user administration.
- Optional firmware blocks: when the Firmware checkbox is selected during backup, the matching OP17 firmware image is embedded in the archive.
- Password / start-up protection metadata: hash of the operator, supervisor, and administrator passwords.
When ProSave opens the archive to perform a restore, it reads the device descriptor and compares it against the panel's own self-identification (the boot loader response on the OP17 serial port). If the variant differs - for example, OP17-PP 6AV3 617-1JC00-0AX versus OP17-DP 6AV3 617-1JC20-0AX1 - the integrity check fails and the transfer is rejected before any blocks are written. This behaviour is by design; it prevents mismatched firmware and corrupted connection parameters from being pushed to the panel, which could otherwise brick the device or introduce bus faults that are difficult to diagnose from the PLC side.
ProTool imposes the same constraint at project creation time. When you create a new project in ProTool, you must first select the OP17 variant, and the configuration tool only enables drivers that the selected variant supports. You cannot select an OP17-PP and then assign a Profibus DP connection block; the driver dropdown is greyed out. Conversely, an OP17-DP project does not expose the RS232 PPI driver. This is the upstream cause of the restore failure: the connection block inside the *.psr archive is intrinsically linked to the variant descriptor.
OP17 Boot Loader and Transfer Mode Entry
Understanding how the OP17 enters transfer mode is critical when the start screen is corrupted or when the operator soft-key is locked behind a forgotten password. The OP17 boot loader runs from a separate protected flash partition that cannot be overwritten by a normal *.psr restore.
- Cold start with valid project: the panel boots into the configured start screen. The operator presses Transfer on the system menu to halt the runtime and expose the boot loader menu.
- Cold start with corrupted project: the panel detects an invalid runtime image and falls back to the boot loader automatically. The transfer menu appears without any operator action.
- Cold start with forgotten password: the panel cannot be unlocked from the front, but the boot loader is still accessible by holding the upper-left soft-key combination while applying 24 V DC. This forces a transfer-mode entry without authentication.
- Self-identification string: while in transfer mode, the splash screen reports the panel MLFB, the firmware revision, the boot loader revision, and the active MPI/DP address. This string is the canonical reference ProSave uses for the integrity check.
The boot loader accepts only *.psr archives that match the reported self-identification. A signed mismatch always returns the hardware-incompatibility message, regardless of how the panel was forced into transfer mode.
OP17 Connection Type Compatibility Matrix
The connection type projected in ProTool must be supported by the target OP17 variant. The matrix below summarises which combinations ProTool accepts and which ProSave can subsequently restore.
| Projected Connection | OP17-PP | OP17-DP | OP17-DP-12 | Notes |
|---|---|---|---|---|
| RS232 point-to-point (ASCII / 3964R) | Supported | Not supported | Not supported | OP17-DP variants lack the RS232 PPI driver block |
| RS485 PPI | Supported | Limited (MPI fallback) | Limited (MPI fallback) | DP variants address as MPI node on RS485 |
| MPI (default 187.5 kbaud) | Supported | Supported | Supported | Common S7 link on all three variants |
| Profibus DP slave | Not supported | Supported | Supported | Requires OP17-DP or OP17-DP-12 hardware |
| Profibus DP up to 12 Mbaud | Not supported | Limited (1.5 Mbaud typical) | Supported | DP-12 required for full bus speed |
In a typical brown-field plant, the OP17-PP was deployed as a stand-alone serial terminal connected via PPI to a SIMATIC S7-200 or via MPI to an S7-300. When the OP17-PP failed, a spare OP17-DP was sometimes substituted because it was the only OP-series panel still on the shelf. Because the spare is wired into a Profibus segment, the field engineer is then forced to migrate the connection from PPI/MPI to Profibus DP - which, without the original *.pdb, requires a full project rebuild.
ProSave *.psr File Format Constraints
The *.psr file is a sealed, encrypted, and compressed archive. It cannot be:
- Edited with ProTool, WinCC flexible, TIA Portal, or any third-party tool.
- Opened or converted to the editable
*.pdbsource database. - Re-targeted to a different hardware variant.
- Migrated to a modern SIMATIC panel (Basic, Comfort, Unified) directly.
- Decompiled to recover screens, tags, or recipes in human-readable form.
The only file format that retains full editability and retargeting capability is the original ProTool source database (*.pdb) plus the project path layout. Without that, every variant change forces a full re-engineering of the project in ProTool.
ProSave therefore has only two legitimate operational workflows:
- Backup / Restore on identical hardware: recommended for commissioning spares and disaster recovery. Restores only to the same MLFB and same connection type.
- Initial commissioning: used to deploy the very first project to a fresh panel. The panel variant must match the projected variant exactly, or the transfer fails with the incompatibility message described above.
Field engineers sometimes attempt to rename the *.psr extension, replace the embedded device descriptor with a hex editor, or run ProSave in a compatibility mode. None of these methods is supported by Siemens, all of them violate the integrity check, and several of them risk corrupting the panel's flash file system to the point where only a firmware recovery via serial boot loader can revive the unit. The supported path is to rebuild the project in ProTool.
Diagnostic Workflow Before Recreating the Project
Before rewriting the project from scratch, run through the following checklist. The original *.pdb source may still be retrievable in places engineers routinely overlook, and recovering it saves days of rework.
-
Search the engineering workstation. Look in
C:\Program Files\Siemens\ProTool\Projects, in the user'sDocuments\ProTooldirectory, and in any custom project archive directory. ProTool defaults to the user profile unless the project was explicitly saved to a network share. -
Search the project archive. Many plants keep an automated ZIP of
\\server\HMI_Backup\<ProjectName>\*.zipcreated by a scheduled task. Decompress the most recent ZIP and inspect the contents. -
Check the version control system. Older OP17 projects often lived in PVCS, MKS Integrity, or Subversion with descriptive tags such as
OP17_LINE3_v2.1. Search the repository by tag. -
Inspect any backup of the engineering PC. System images, Windows Server Backup snapshots, or NAS snapshots of the engineering workstation can sometimes recover an orphaned
*.pdb. - Pull the project from the source PLC. ProTool cannot upload a project from a running OP17 panel. The runtime image stored in flash cannot be decompiled to source, and the OP17 has no online upload function in its boot loader.
-
Confirm the panel self-identification. Power up the target OP17-PP or OP17-DP, enter transfer mode via the Transfer soft-key on the OP17 main menu, and read the variant string on the splash screen. Cross-check against the MLFB on the rating plate. The boot loader also returns the firmware revision and the boot loader revision, which are useful when matching the firmware inside
*.psr. -
Document the original tag list. Before deleting the legacy
*.psr, generate a screenshot of every configured screen (with the OP17 in run mode, press Print to dump to the serial port) and capture the tag list from STEP 7 if the PLC is still accessible. These artefacts are the most reliable blueprint for the rebuild.
*.pdb source is recoverable, the only recovery path is to rebuild the project in ProTool for the new hardware variant. Estimate 8-16 hours of engineering effort per 50 screens, plus commissioning time.Step-by-Step: Rebuilding the Project in ProTool
ProTool /Pro CS or ProTool V6.x is required for OP17 projects. Both PP and DP variants of the OP17 are supported on the same installation; ProTool selects the driver set based on the chosen device at project creation time.
- Start ProTool. Launch Start → SIMATIC → ProTool → ProTool (or ProTool /Pro CS for the configuration suite).
-
Choose the device. Select File → New. In the device selector, pick the target variant - OP 17 DP for
6AV3 617-1JC20-0AX1. ProTool only lists drivers that match the variant. If the source project used a Profibus connection, you must select OP17-DP; otherwise the Profibus driver is greyed out. - Configure the connection. Open System → Connections. For a Profibus DP slave to a SIMATIC S7-300, configure the parameters listed in the connection block reference below.
- Rebuild the tag database. Recreate the tag list. Each tag is mapped to an S7 address (DB, MW, IW, QW, M, I, Q). Use the original tag list captured during the diagnostic workflow. Typical OP17 projects carry 100-400 tags.
- Rebuild screens, alarms, and recipes. Re-create the screen hierarchy. Each screen is a flat 320 x 240 layout with text fields, input/output fields, buttons, bars, and graphics. Alarms are configured as bit alarms or analog alarms, with classification (error, warning, information) and acknowledgement model.
- Set start-up parameters. Open System → Start-up. Enable or disable the Transfer mode soft-key. Configure the operator password levels (operator, supervisor, administrator) with the hashes carried over from the original project.
- Compile the project. File → Compile → Incremental (or Rebuild All for a clean baseline). Resolve every error before proceeding; warnings can be tolerated but should be reviewed.
-
Save as
*.pdb. Commit the editable source to a known path such as\\server\HMI_Projects\OP17-DP\<ProjectName>\. Tag the version in the version control system immediately. -
Generate the transfer image. ProTool produces
*.psron demand: File → Export → ProSave Backup. Use this*.psrfor the actual panel restore. Keep both the*.pdb(source of truth) and the*.psr(transfer image) under version control.
ProTool Connection Block Parameter Reference
The ProTool System → Connections dialog exposes the parameters that ProSave later writes to the OP17 boot configuration. The table below lists the typical values for an OP17-DP slave on a SIMATIC S7-300 / S7-400 network.
| Parameter | Typical Value | Notes |
|---|---|---|
| PLC type | SIMATIC S7-300/400 | Drives the tag address space and the put/get helpers |
| Driver | Profibus DP | Only available when the device is OP17-DP or OP17-DP-12 |
| Panel address | 3 | Must be unique on the segment; default is 1 for MPI, 3 for DP |
| Baud rate | 1.5 Mbaud (DP) / 187.5 kbaud (MPI) | Up to 12 Mbaud if the panel is OP17-DP-12 and the network supports it |
| Highest station address (HSA) | 126 | Profibus standard |
| Slot configuration | 2 slots default (1 in / 1 out) | Configurable up to 32 slots; OP17-DP typically uses 16 bytes input / 16 bytes output |
| Monitoring time | 600 ms | Time the master waits for the slave response before declaring a fault |
| Diagnostic address | 1023 (default) | Used for slave diagnostics on the S7 side |
When the rebuild targets a connection type that the original project did not use (for example, switching from PPI to Profibus DP), every tag in the database must be re-validated against the new driver's address space. ProTool's incremental compiler reports address conflicts as Address outside process image or DB does not exist; both must be resolved before the *.psr can be exported.
Cable Wiring and Bus Termination
For an OP17-PP, the serial link to the engineering PC is a null-modem RS232 cable with the following pinout on the 9-pin Sub-D:
| PC DB-9 (DTE) | OP17-PP DB-9 (DCE) | Signal |
|---|---|---|
| 2 | 3 | RxD / TxD crossover |
| 3 | 2 | TxD / RxD crossover |
| 5 | 5 | Ground |
| 7 / 8 | 7 / 8 | RTS / CTS (loop back at panel) |
Hardware flow control must be disabled on the PC COM port. ProTool and ProSave both expect a 3-wire connection with software handshake (XON/XOFF) for OP17-PP transfers.
For an OP17-DP or OP17-DP-12, the connection to the engineering PC is via a Siemens MPI/Profibus PC adapter (the PC-Adapter USB family). The adapter terminates to the OP17's 9-pin Sub-D using the standard Profibus pinout: pin 3 RxD/TxD-P, pin 8 RxD/TxD-N, pin 6 +5 V (only on powered nodes), pin 5 ground. The Profibus segment must be terminated at both ends with the standard Profibus connector (220 ohm between A and B, 390 ohm pull-up to +5 V on the A line, 390 ohm pull-down to ground on the B line). Leaving the segment unterminated is the most common cause of intermittent bus faults that surface only at high baud rates.
ProSave Backup and Restore Best Practices
Once the new project is rebuilt and stored as *.psr, deploy it with the same ProSave procedures used during the original commissioning. The restore is identical for OP17-PP, OP17-DP, and OP17-DP-12; only the cable and the panel address differ.
- Prepare the cable. Connect the OP17-DP to the engineering PC via the Siemens MPI/Profibus PC adapter. Connect the OP17-PP via a serial null-modem cable. Confirm the bus termination on Profibus segments.
- Enter transfer mode on the OP17. Power the panel. The OP17 main menu offers a Transfer soft-key. Press it to halt the runtime and enter the boot loader. If the start screen is corrupted, hold the appropriate soft-key combination while powering up to force transfer mode.
- Run ProSave. Launch Start → SIMATIC → ProSave → ProSave. Select the panel type (OP17-DP), the connection (USB to MPI/Profibus adapter), and the target MPI/DP address. ProSave will ping the panel and display its self-identification (MLFB and firmware revision) before the restore begins.
-
Restore. Click Restore and select the rebuilt
*.psr. The transfer takes 5-15 minutes depending on the project size and the selected baud rate. The progress bar advances block-by-block; do not interrupt the transfer or power-cycle the panel mid-restore. - Reboot the panel. When prompted, cycle power. The OP17 reboots into the new project. Verify the splash screen and the first configured screen.
- Verify online. In ProTool, click Online → Tag Monitor to confirm bus communication with the SIMATIC S7 PLC. From the panel side, navigate to the diagnostic screen and confirm that all configured tags are updating.
ProSave.exe /restore /panel:"OP17-DP" /conn:"USB" /file:"C:\Project.psr"). The CLI returns the same incompatibility error code if the panel MLFB does not match, and the same exit code can be trapped in a batch script to flag a manual rebuild.STEP 7 / PLC Side Integration
When the OP17-DP is moved to a Profibus segment, the PLC side must be updated as well. The OP17-DP is registered in STEP 7 HW Config as a Profibus DP slave with the GSD file supplied on the ProTool installation media (look in C:\Program Files\Siemens\ProTool\GSD\ for the OP17 GSD). Without the matching GSD, HW Config will not offer the OP17 as a drop-in slave.
| STEP 7 Parameter | Typical Value | Notes |
|---|---|---|
| Profibus address | 3 | Must match ProTool connection block |
| Diagnostic address | 1023 (default) | Used for slave diagnostics |
| Slot 1 (input) | 16 bytes input, configurable | OP17 → PLC direction |
| Slot 2 (output) | 16 bytes output, configurable | PLC → OP17 direction |
| Watchdog | 600 ms | Time the master waits for slave response |
After downloading the HW Config to the S7 CPU, run PLC → PROFIBUS → Diagnostics to confirm the OP17-DP transitions to DP-Slave in data exchange. Address conflict between master and slave manifests as Slave not found or Diagnostic interrupt Slot 0 in the S7 diagnostic buffer; both are cleared by correcting the address assignment and recompiling the HW Config.
Commissioning Verification
After the restore, perform the following live verification sequence before handing the panel back to operations.
- Bus diagnostic: the OP17-DP must report DP-Slave in data exchange on the Profibus master diagnostic buffer. No diagnostic interrupt should be pending.
-
Tag polling: a writeable tag from ProTool (for example,
DB100.DBW0) must change in both directions when forced from the PLC programming software (STEP 7 → Monitor/Modify). - Alarm path: trigger a configured alarm bit. The OP17 must display the alarm text and (if configured) acknowledge it. Bit-clear must clear the alarm and update the alarm history.
- Recipe / parameter set: download and upload one recipe to confirm DB synchronisation between the panel's internal recipe database and the PLC's recipe DB.
- User administration: log in at each configured level (operator, supervisor, administrator) and verify the password change and logout behaviour. Logout must revert the panel to the lowest access level.
- Power-cycle test: cycle the 24 V DC supply three times in succession to confirm that the panel re-enters the project without manual intervention and that no start-up errors appear.
Migration Path: Beyond the OP17
The OP17 family has been declared discontinued by Siemens and is no longer available as a spare part with active firmware updates. If the rebuild effort is significant, evaluate the migration cost against a transition to a current SIMATIC panel.
-
WinCC flexible 2008 SP5 supports OP17 source projects via the built-in Migration Tool. Tags, screens, and alarms are converted; recipes and user administration require manual rework. The migration wizard produces a WinCC flexible
*.hmiproject that can be edited and re-targeted to a current panel. - TIA Portal V16+ supports import of WinCC flexible projects via Migrate project → WinCC flexible → TIA Portal. For an OP17-to-TIA path, the intermediate migration step through WinCC flexible is required; there is no direct OP17-to-TIA converter.
-
Replacement hardware: modern successors in the Comfort Panel (TP700 / TP900 / TP1200) and Unified Comfort Panel lines offer a Profinet interface, multi-protocol driver (S7, Modbus TCP, OPC UA), and full TIA Portal support. They use a different runtime image format and require a full TIA Portal project - they cannot accept an OP17
*.psr.
For plants that have decided to keep the OP17 alive, store the rebuilt *.pdb project source and the matching *.psr archive in a clearly-named directory such as \\server\HMI_Backup\OP17-DP_6AV3617-1JC20-0AX1_<ProjectName>\, along with a README describing the build date, the ProTool version, the bus configuration, and the cable/adapter used for restore. Add a checksum (SHA-256) of the *.psr to detect silent corruption.
Preventive Maintenance Practices
To prevent future rebuild-from-scratch events, enforce the following habits across the engineering team:
-
Archive the
*.pdbon every commit: the editable source is the only asset that survives a variant change. A backup policy that stores only*.psrfiles is not sufficient. - Tag the version control system with the panel MLFB: every release branch should record which OP17 variant the project was compiled against, so that future rebuilds can target the correct hardware.
- Keep a hot-spare panel of every deployed variant: the rebuild cost usually exceeds the cost of a single decommissioned spare.
-
Validate
*.psrintegrity: compute SHA-256 of each archive and store it alongside. ProSave does not check for silent corruption of the archive; only the variant check is enforced. - Document the Profibus topology: store the HW Config screenshots and the GSD file revisions in the same directory as the project source, so that a future PLC-side rebuild uses the matching slave definition.
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| ProSave reports hardware configuration incompatible | Variant mismatch (e.g. OP17-PP *.psr on OP17-DP) |
Rebuild project for the actual panel MLFB; the *.psr cannot be cross-flashed |
| ProSave aborts with connection error at start of restore | Cable mismatch, wrong COM/USB port, MPI address conflict | Verify PC adapter drivers; verify panel MPI/DP address; check bus termination |
| Panel boots to Transfer screen and stays there | Restore did not set the start-up project bit | Enable Start-up project in ProTool System → Start-up and re-restore |
| Panel shows Connection failed on first screen | PLC PROFIBUS address or baud rate differs from project | Match ProTool connection block to STEP 7 HW Config; recompile HW Config |
| Compile error Driver not available for selected device | ProTool selected an OP17-PP but the connection block uses Profibus DP | Switch device to OP17-DP in the project and recompile |
| Restore succeeds but panel reboots with Configuration error | Corrupted firmware inside *.psr
|
Re-export *.psr from ProTool without firmware bit, restore, then run a separate firmware update |
| PLC diagnostic buffer reports Slave diagnostic - station failure | GSD file mismatch or duplicate Profibus address | Reinstall OP17 GSD in STEP 7 HW Config; reassign a free address |
| Panel runs but tags stay at zero | Wrong slot configuration in HW Config | Match slot byte count to ProTool connection block (16/16 default) |
Frequently Asked Questions
Can I convert an OP17-PP *.psr backup into an OP17-DP *.psr backup?
No. The *.psr file is a sealed, compressed, and signed archive containing the panel variant, firmware, connection block, and runtime image. It cannot be edited or converted by ProTool, ProSave, or any third-party tool. The only editable source is the ProTool *.pdb project, which must be present before the rebuild can start.
Will the same Profibus DP address work on both OP17-PP and OP17-DP panels?
The address assignment is project-defined, not hardware-defined. However, the OP17-PP cannot join a Profibus DP network at all because its hardware lacks the DP slave interface. Setting an address on an OP17-PP is only useful for MPI communication; an OP17-DP can use the same numeric address (for example, default 3) on a Profibus DP segment.
Which ProTool version is required to rebuild an OP17 project?
ProTool /Pro V6.0 SP3 or later is the last published version that supports the OP17 family. The same installation can target OP17-PP, OP17-DP, and OP17-DP-12; the driver list changes based on the selected device. Newer TIA Portal releases do not support direct OP17 project creation - migration must pass through WinCC flexible 2008 SP5 first.
Does the *.psr archive contain the firmware, or only the configuration?
Both. ProSave embeds the runtime image, the connection block, the recipe databases, and (when selected during backup) the panel firmware. To perform a firmware-only update without touching the project, use the Firmware Update tab in ProSave and supply the matching firmware file from the Siemens support portal.
Is it safe to overwrite an OP17-DP that already runs a working project with a different *.psr?
Yes, provided the *.psr is targeted at the same OP17-DP MLFB (6AV3 617-1JC20-0AX1). ProSave performs a strict variant check before writing. Always back up the running project first (Backup tab in ProSave) so the previous state can be restored in case the new image misbehaves.