Resolving PCS 7 Error 0xFFDF_011E S7DOS Database Disconnected

David Krause13 min read
Process ControlSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

When commissioning or troubleshooting a Siemens PCS 7 V6.1 (or comparable V6.x/V7.x) project compiled with CFC (Continuous Function Chart) and downloaded to an S7-PLCSIM virtual controller, engineers may encounter Error 0xFFDF_011E [S7DOS] when they try to open the chart online or activate TEST MODE from the CFC Editor. The accompanying symptom is a greyed-out Watch On button in the CFC online toolbar, indicating that the engineering station cannot establish — or has lost — the database connection to the target system.

The fault is raised by the S7-DOS (S7 Database Open Server) component that mediates online data exchange between the SIMATIC Manager / CFC Editor on the Engineering Station (ES) and the runtime database on the Automation Station (AS), in this case the S7-PLCSIM instance. The literal meaning of the error is DATABASE_DISCONNECTED — no connection to database anymore or S7DOS handle invalid (decimal severity 286, S7DOS offset 011E).

This article decodes the error, identifies the precise root causes encountered in field environments, and documents the recovery procedure that restores online monitoring against PLCSIM.

2. Decoding the Error Code 0xFFDF_011E

The diagnostic word 0xFFDF_011E follows the Siemens-internal PCS 7 / STEP 7 convention used by the S7DOS subsystem. The high word (0xFFDF) identifies the fault class as an S7DOS-specific return code; the low word (0x011E) is the offset into the S7DOS error table.

Field Value Interpretation
Prefix 0xFFDF_ S7DOS subsystem identifier (S7 Database Open Server)
Offset 0x011E (286 dec) DATABASE_DISCONNECTED
Literal tag [S7DOS] Subsystem marker appended to the error
Decimal severity 286 Informational / connection-level (not a CPU fault)
Category Online / connectivity Not a compilation error, not a CPU diagnostic

Because the error originates from the database layer and not the CPU firmware, it is not visible in the diagnostic buffer of the simulated AS (CPU 300/400 PLCSIM) — the PLC diagnostic buffer will typically show no entries. The fault must be diagnosed and cleared on the Engineering Station side.

3. What S7DOS Does in PCS 7 and S7-PLCSIM

S7DOS (S7 Database Open Server) is a Windows service installed with PCS 7 / STEP 7 that provides the structured database access used by the CFC Editor, SFC Editor, and PCS 7 OS faceplates. It exposes the online view of CFC charts, the SFC step/status transitions, and the OS variable browser to the underlying S7 communication stack. In a PLCSIM-based commissioning rig, S7DOS is also the channel through which the CFC online view and the PLCSIM process image exchange data. See the Siemens Industry Online Support portal for the PCS 7 engineering manuals covering the S7DOS architecture.

The S7DOS handle acquired when the ES opens a session with a target system (AS or PLCSIM) is invalidated when:

  • The PLCSIM instance terminates unexpectedly (CPU STOP from the PLCSIM menu, instance crash, or PC sleep).
  • The MPI/TCP/Profibus link between the ES and PLCSIM is broken or reconfigured mid-session.
  • The S7DOS service is restarted while an online session is open.
  • Windows places the network interface into a low-power or disconnected state.
  • Two Engineering Stations attempt to bind to the same PLCSIM slot.

Once the handle is invalidated, all subsequent online operations return 0xFFDF_011E DATABASE_DISCONNECTED until a new session is opened.

4. Root Cause Analysis

In the typical PCS 7 V6.1 / S7-PLCSIM commissioning scenario where this error is reported, one or more of the following conditions is responsible:

# Root cause Trigger Observable hint
1 PLCSIM CPU in STOP The PLCSIM MRES button or a previous error stopped the simulated CPU PLCSIM window shows a red STOP indicator
2 PG/PC interface mis-assigned Set PG/PC Interface points to a non-existent adapter or to a TCP adapter with no PLCSIM reachable Accessible Nodes returns no devices
3 S7DOS service not running Service crashed, was disabled, or was stopped manually services.msc shows S7-DOS stopped
4 TCP/IP loopback blocked Third-party firewall or endpoint protection blocks local loopback (port 102) used by PLCSIM Online Connect fails immediately
5 Stale S7DOS handle Online session opened before PLCSIM was started, or session opened against an MPI slot that has since changed Online view opens briefly then errors
6 Online connection never established User clicked Watch On without first executing Online → Connect to Target System Watch On button is greyed out
7 Multiple PLCSIM instances Two PLCSIM instances running on the same ES with the same MPI/TCP address Online view connects to the wrong slot
8 Insufficient user privileges SIMATIC Manager not running with administrator rights (Windows Vista/7/10/11) Online operations fail silently

In the originally reported case, the engineer compiled all CFC charts successfully and downloaded them to a freshly created PLCSIM virtual controller. The CPU was reported as running, the connection was reported as active, yet the Watch On button remained greyed out. This pattern is the classic signature of root cause #5 (stale S7DOS handle) combined with root cause #6 (online connection not yet established): the project was downloaded in offline mode, but the S7DOS online session was never opened against the running PLCSIM, so the database handle the CFC Editor expects does not exist.

5. Affected Versions and Components

Component Versions in scope Notes
PCS 7 V6.1, V6.1 SP1, V6.1 SP2, V7.0, V7.0 SP1, V7.1, V7.1 SP1, V8.0, V8.1, V8.2 S7DOS error catalog is shared across versions
STEP 7 V5.3 SP3 through V5.5 SP4 Required host for SIMATIC Manager and CFC Editor
S7-PLCSIM V5.3 (PCS 7 V6.1), V5.4 (PCS 7 V7.x/V8.0), V5.4 SP5+ (PCS 7 V8.1/V8.2) PLCSIM is the simulated AS in this scenario
CFC Editor V6.1 (PCS 7 V6.1), V7.0, V7.1, V8.0, V8.2 The component raising the S7DOS call
Operating system Windows XP SP3, Windows Server 2003, Windows 7 (32-bit), Windows Server 2008 R2 Per PCS 7 V6.1/V7.x compatibility matrix on the Siemens support site
Communication PLCSIM internal TCP loopback (port 102) on 127.0.0.1; MPI/Profibus not required PLCSIM does not require external MPI hardware
Compatibility note: The 0xFFDF_011E error is not restricted to PCS 7 V6.1. The S7DOS subsystem has remained stable across the V6.x, V7.x, and V8.x releases of PCS 7, and the same code path is exercised by every CFC Editor that opens an online session against PLCSIM or a real AS.

6. Pre-Diagnostic Checklist

Before opening the CFC chart for online monitoring, verify the following prerequisites on the Engineering Station:

  1. The S7-PLCSIM instance is started and the simulated CPU is in RUN (not STOP, not RUN-P with a pending error).
  2. The PLCSIM Monitor/Modify panel shows the expected slot (slot 2 for an S7-400, slot 3 for an S7-300) and the correct MPI/TCP address (default MPI = 2).
  3. The PG/PC interface is set to PLCSIM (MPI) or PLCSIM.ISO via Start → SIMATIC → SIMATIC Manager → Options → Set PG/PC Interface.
  4. The S7DOS Windows service is in state Started. Verify with services.msc; the service is listed as S7-DOS or Siemens S7 DOS.
  5. No third-party firewall or endpoint protection rule is blocking TCP port 102 on the loopback interface (127.0.0.1).
  6. SIMATIC Manager is running with administrator privileges (right-click → Run as administrator on Windows Vista and newer).
  7. Only one instance of S7-PLCSIM is running, and only one Engineering Station has an online session open against it.

7. Diagnostic Procedure

Execute the following diagnostic sequence in order. The first step that succeeds also indicates which root cause applies, allowing you to jump to the matching recovery action in Section 8.

  1. Verify the CPU state in PLCSIM. Open the PLCSIM window. If the CPU is in STOP, click RUN or RUN-P. If a diagnostic buffer entry is shown, clear the cause first.
  2. Test node accessibility. In SIMATIC Manager, choose PLC → Accessible Nodes. The PLCSIM virtual CPU must appear in the list with its configured MPI address.
  3. Open a test online session from SIMATIC Manager. With the project open, choose PLC → Connect to Target System. A successful connection opens the online view of the S7 program; a failure here points to PG/PC interface or firewall issues rather than S7DOS.
  4. Open the CFC chart in TEST MODE. Right-click the chart, choose Chart → Open, then from the menu choose Debug → Test Mode. If 0xFFDF_011E appears, the S7DOS database handle is invalid — proceed to Section 8.
  5. Check the S7DOS service. Open services.msc. Locate S7-DOS. If the service is Stopped, restart it (right-click → Start). If the service is Started, restart it anyway to discard any stale handle.
  6. Inspect the SIMATIC Manager diagnostic log. In SIMATIC Manager, choose Options → Diagnostics. The diagnostic overview lists open sessions and S7DOS handle states.
  7. Capture the loopback state. From an elevated command prompt, run netstat -ano | findstr :102. The PLCSIM process (typically S7-PLCSIM.exe) must be LISTENING on 127.0.0.1:102.

8. Resolution: Step-by-Step Recovery

Apply the recovery sequence that matches the root cause identified in Section 7. The steps are written so they can be executed in order if the root cause is not yet known; the redundant operations are safe.

8.1 Recovering the S7DOS Online Session

  1. Close all open CFC charts in SIMATIC Manager.
  2. In S7-PLCSIM, confirm the CPU is in RUN. If PLCSIM shows STOP, click the green RUN button on the PLCSIM toolbar.
  3. In SIMATIC Manager, choose PLC → Disconnect (if a connection is shown) to release any stale S7DOS handle.
  4. Wait five seconds. The S7DOS subsystem releases the handle asynchronously.
  5. Choose PLC → Connect to Target System. The connection panel opens; confirm the target (PLCSIM) and click OK.
  6. Open the CFC chart from the project tree. The Watch On button is now enabled.
  7. Click Watch On (or choose Debug → Watch On) to activate the online view. The chart fills with live process values from PLCSIM.

8.2 Restarting the S7DOS Service

If the S7DOS session cannot be recovered by disconnect/reconnect, restart the Windows service that hosts the S7 Database Open Server:

  1. Close SIMATIC Manager and the CFC Editor.
  2. Open Start → Run → services.msc (or run services.msc from an elevated command prompt).
  3. Locate the service S7-DOS (display name may be Siemens S7 DOS or S7 Database Open Server).
  4. Right-click the service and choose Stop. Wait for the state to become Stopped.
  5. Right-click and choose Start. Confirm the service reaches the Running state.
  6. Re-launch SIMATIC Manager with administrator privileges.
  7. Open the CFC project and repeat the Section 8.1 sequence.

8.3 Verifying PG/PC Interface and Loopback

If Section 8.2 still leaves the S7DOS handle invalid, the issue is typically the PG/PC interface assignment or a blocked TCP port:

  1. Open Start → SIMATIC → SIMATIC Manager → Options → Set PG/PC Interface.
  2. For PLCSIM, the correct interface is PLCSIM (MPI) or PLCSIM.ISO. Select it and click OK.
  3. Verify with PLC → Accessible Nodes. The PLCSIM CPU must appear.
  4. If Accessible Nodes returns an empty list, the loopback or a firewall is blocking port 102. Disable the third-party firewall temporarily and retest.
  5. From an elevated command prompt, run netstat -ano | findstr :102. The PLCSIM process must be LISTENING on 127.0.0.1:102. If the port is owned by another process, that process is conflicting with PLCSIM and must be stopped before the recovery continues.

8.4 Recompile and Re-download the CFC Charts

If the S7DOS handle remains invalid after the above steps, the project on the PLCSIM side and the offline database on the ES side may be out of sync. A clean recompile and re-download restores the database:

  1. In the CFC Editor, select the program folder containing the charts.
  2. Choose Options → Chart Compile → Charts as Program (or Charts → Compile in older CFC releases). Wait for "Compilation completed without errors".
  3. Right-click the S7 program (the offline container) and choose PLC → Download. Confirm the target system dialog shows PLCSIM.
  4. Click OK. The download writes the standard FB/DB/FC blocks into PLCSIM and updates the offline database.
  5. After download, PLCSIM transitions to RUN (if configured). Choose PLC → Connect to Target System.
  6. Open the CFC chart and click Watch On. The online view loads without 0xFFDF_011E.

9. Verification

After completing the recovery procedure, confirm that the online monitoring path is healthy:

Verification step Expected result Failure indicator
Open CFC chart and click Watch On Chart populates with live values within 1–2 s 0xFFDF_011E reappears; Section 8 must be repeated
Activate TEST MODE Toggle transitions chart to test mode without error dialog Error dialog with S7DOS text
Force a value in PLCSIM Monitor/Modify CFC online value updates within the configured scan time (default 100 ms) Value remains stale; S7DOS subscription is broken
SIMATIC Manager diagnostics Single online session listed, target = PLCSIM "No online connection" or duplicate sessions listed
S7DOS service state Running, started by LocalSystem or by the SIMATIC Manager user Service stopped automatically; insufficient privileges
netstat check on port 102 S7-PLCSIM.exe LISTENING on 127.0.0.1:102 Port not bound or bound by another process

10. Preventive Measures and Best Practices

  1. Always start PLCSIM before opening the online view. The CFC Editor must not open a chart in TEST MODE or Watch On mode against a PLCSIM instance that has not yet been started — the S7DOS handle will be invalid from the outset.
  2. Use the explicit Connect/Disconnect cycle. Avoid leaving an online session open across PLCSIM restarts. Always close charts, disconnect, restart PLCSIM, then reconnect.
  3. Run SIMATIC Manager elevated. On Windows Vista / 7 / 10 / 11, launch SIMATIC Manager with Run as administrator. The S7DOS service requires elevated rights to bind the loopback interface and open protected handles.
  4. Configure one PG/PC interface per project. Mixing the PLCSIM interface with a real MPI/Profibus adapter in the same session confuses the S7DOS connection routing.
  5. Document the PCS 7 and PLCSIM combination. PCS 7 V6.1 expects S7-PLCSIM V5.3; PCS 7 V7.x expects PLCSIM V5.4; PCS 7 V8.x expects PLCSIM V5.4 SP5 or newer. Mixing versions produces spurious S7DOS errors that are not the same as 0xFFDF_011E but mask the underlying mismatch.
  6. Avoid concurrent engineering sessions on the same PLCSIM. Two ES workstations cannot share a single PLCSIM instance; the second session steals the S7DOS handle and the first session reports DATABASE_DISCONNECTED.
  7. Lock the loopback in the host firewall. Create an explicit allow rule for TCP 102 on 127.0.0.1 rather than relying on the firewall to default-permit loopback traffic.
  8. Audit the S7DOS service after Windows updates. Major Windows updates occasionally reset service startup types. Verify the S7-DOS service remains at Automatic after every patch cycle.

Frequently Asked Questions

What does error 0xFFDF_011E mean in PCS 7?

It is the S7DOS (S7 Database Open Server) error code 286 / 0x011E with the literal text DATABASE_DISCONNECTED. The S7DOS online handle between the Engineering Station and the Automation Station (PLCSIM or a real CPU) is invalid or has been released. The CFC online view cannot read live values until a new online session is opened.

Why is the Watch On button greyed out when I open a CFC chart?

The button is disabled when the S7DOS online session is not yet established. Open the online session explicitly via PLC → Connect to Target System in SIMATIC Manager before clicking Watch On. If the button is still greyed out after a successful connect, restart the S7-DOS Windows service.

Can the error be cleared by simply restarting PLCSIM?

Yes, in most cases. Close the CFC chart, stop the PLCSIM instance, wait five seconds, restart PLCSIM, switch the CPU to RUN, then in SIMATIC Manager choose PLC → Connect to Target System before reopening the chart. If the error persists, restart the S7-DOS service and recompile the CFC charts.

Is error 0xFFDF_011E the same as a CPU diagnostic buffer entry?

No. The S7DOS error is raised on the Engineering Station side by the database component that mediates online access. The CPU diagnostic buffer of PLCSIM will not contain an entry for this fault, because the simulated CPU itself is operating correctly — the link between the ES and the simulated CPU's online database is what is broken.

Does the error appear with real AS hardware, or only with PLCSIM?

Both. The S7DOS layer is identical for PLCSIM and real AS-300/AS-400 stations. The same DATABASE_DISCONNECTED return value is reported when the ES loses contact with a real CPU over MPI, Profibus, or Industrial Ethernet. The recovery procedure (reconnect, restart S7DOS, recompile and re-download) is the same.

What TCP port does S7-PLCSIM use for the engineering link?

S7-PLCSIM binds TCP port 102 on the loopback interface 127.0.0.1. Verify with netstat -ano | findstr :102. If another process holds port 102, stop that process before starting PLCSIM, otherwise the S7DOS connection will fail with 0xFFDF_011E.

Back to blog