Resolving PCS 7 V9 Standby OS Server Connection Read-Only Error
In a PCS 7 V9.0 SP1 OS server/standby pair with an S7-400H (CPU 417-5H) automation system and two CP 1623 industrial Ethernet cards per OS station, operators frequently encounter the WinCC Explorer error "Failed to edit the object. Note: The connection is read-only" when attempting to change S7 connections on the standby server. This reference explains the underlying cause, the intended protection mechanism, and the precise engineering workflow that restores runtime connectivity without breaking redundant behavior.
1. Problem Statement
A typical redundant OS architecture is configured as follows:
- One PCS 7 engineering station (ES) with SIMATIC Manager / PCS 7 V9.0 SP1.
- One OS Master server and one OS Standby server, each equipped with two CP 1623 PCIe cards.
- Five OS Clients that subscribe to the master/standby pair.
- One AS pair with two CPU 417-5H controllers in fault-tolerant H mode.
- SIMATIC NET OPC / S7-REDCONNECT redundancy over the CP 1623 interfaces.
After a successful project download to both servers the following symptoms are observed:
| Symptom | Master OS Server | Standby OS Server |
|---|---|---|
| Runtime starts and logs into the AS pair | OK - tags are updating | Runtime not connected / tags dead |
| Redundancy partner reachable via SIMATIC Shell | OK | Partner detected but not alive |
| S7 connections in Tag Management | Editable | Read-only |
| Diagnostic error | None | "Failed to edit the object. Note: The connection is read-only" |
| Ping to CPU 417-5H IP | OK | OK |
The fact that ICMP ping to the H-CPU IP succeeds on the standby confirms that the physical network path is intact. The actual fault therefore lies inside the WinCC connection layer, in the NetPro database, or in the CP 1623 channel unit assignment.
2. Root Cause Analysis
Three independent root causes are routinely responsible for the symptoms described above. In most field cases, more than one applies simultaneously.
2.1 Standby connections are intentionally read-only
PCS 7 OS redundancy is implemented through S7-REDCONNECT. The redundancy layer duplicates all configured S7 connections from the master to the standby, but only the currently active server opens the S7 connection to the AS pair. The passive standby server stores the same S7 connection configuration but never actively establishes it. To prevent an operator on the standby server from creating a configuration that diverges from the master, WinCC flags every S7 connection on the standby station as read-only. Trying to edit it produces the dialog "Failed to edit the object. Note: The connection is read-only". The correct place to change the connection is on the master or, preferably, in the ES project.
2.2 NetPro S7 connection does not match between ES and standby
If the NetPro database on the ES differs from the runtime database on the standby server (different CP 1623 interface selected, missing H connection, different partner IP), the standby will boot in a degraded state. WinCC then locks the local copy of the connection to avoid corrupting it further, producing the read-only error.
2.3 Wrong channel unit selected on the standby
This is the most common mistake. The ES was configured against an IE General adapter (CP 1613/IE onboard), but the actual OS servers use CP 1623. After the download, the standby binds the connection to a non-existent adapter. WinCC again protects the configuration and reports it as read-only because the underlying channel cannot be opened.
3. Affected Versions and Compatibility
| Component | Order Number / Version | Status |
|---|---|---|
| SIMATIC PCS 7 | V9.0 SP1 (released 2018) | Affected - bug fixed in PCS 7 V9.0 SP2 / SP3 with HSP updates |
| SIMATIC PCS 7 | V9.1 / V9.1 SP1 | Not affected when configured correctly |
| WinCC | V7.5 SP1 Update 6 / later | Recommended patch level |
| SIMATIC NET CP 1623 | 6GK1162-3AA00 (firmware V2.x) | Affected when channel unit is wrong |
| SIMATIC NET CP 1628 | 6GK1162-8AA00 | Alternative, recommended for new builds |
| CPU 417-5H | 6ES7417-5HT06-0AB0, FW V6.0.7+ | Standard H-CPU for redundant AS |
| Windows Server | 2016 LTSC / 2019 LTSC | Certified OS for PCS 7 V9 |
The original PCS 7 V9.0 SP1 release notes (entry ID 109769534 in the Siemens Industry Online Support) and the SIMATIC PCS 7 OS Configuration Manual (entry ID 109751904) explicitly call out the requirement to match NetPro connections and CP channel units before commissioning OS redundancy.
4. Prerequisites
Before applying the procedure below, ensure the following conditions are met:
- Both OS servers and the ES are members of the same Windows domain or workgroup with identical administrator accounts.
- The PCS 7 V9.0 SP1 installation is the same on all three PCs (ES, master, standby). Verify with
Start > SIMATIC > SIMATIC Manager > Help > Aboutand the Windows Programs and Features list. - Both CP 1623 cards are physically installed in the same PCIe slot position on each IPC (recommended for documentation). Record the MAC address of every port with
SIMATIC NET > Commissioning > Commissioning Wizard. - Latest SIMATIC NET driver package is installed. For CP 1623 use SIMATIC NET PC Software V17 or later (entry ID 109769086), recommended for PCS 7 V9.0 SP1.
- The H-CPU pair is in redundant mode (
RUN-REDUNDANT), not solo. Both 417-5H CPUs must showH-Syncactive on the HMI display. - The PCS 7 project on the ES is consistent. Run
Project > Check Consistencyin SIMATIC Manager and resolve all warnings before downloading.
5. Step-by-Step Resolution Procedure
The procedure below restores the standby server while preserving OS redundancy. It assumes you have full administrative access to the ES and both OS servers.
5.1 Validate NetPro connections on the ES
- Open SIMATIC Manager and load the PCS 7 project from the ES archive.
- Open NetPro from Options > NetPro or by clicking the NetPro toolbar button.
- Select the OS Master station and confirm that an H connection (S7 connection, fault-tolerant) is configured from the OS Master to the S7-400H AS pair, not a standard S7 connection.
- Select the OS Standby station. Confirm that the identical H connection exists with the same connection ID, partner IP, and rack/slot.
- Open the properties of each H connection and verify the following parameters:
| Property | Required value |
|---|---|
| Connection type | S7 connection fault-tolerant |
| Partner (AS) | S7-400H station object, not a single CPU |
| Interface on OS | CP 1623 (#1) - rack 0, slot corresponds to PCIe index |
| Interface on AS | CP 443-1 / integrated PN interface, both H-CPUs |
| Connection resource | Same connection ID on master and standby (e.g. 0x0001) |
| Establishment | Active on master, mirrored to standby |
- If the standby H connection is missing, right-click the OS Standby station, choose Insert New Connection > S7 Connection Fault-Tolerant and link it to the same AS pair. Use
Save and Compile(Network > Save and Compile) to push the new XDB to all OS stations. - Confirm there are no yellow or red entries in the Consistency Check dialog. A clean compile is a hard prerequisite; do not skip it.
5.2 Verify CP 1623 installation on every OS server
- Open SIMATIC NET > Commissioning > Configuration Console on each OS server.
- Confirm that both CP 1623 cards are visible under Modules > PC Station. Note the MAC address and index of every port. They must be the same physical position (same PCIe slot) on master and standby so the index mapping is identical.
- Assign IP addresses / subnet masks through the configuration console, not through Windows. Recommended scheme:
| Server | CP 1623 #1 (terminal bus) | CP 1623 #2 (plant bus) |
|---|---|---|
| OS Master | 192.168.1.10 / 255.255.255.0 | 192.168.2.10 / 255.255.255.0 |
| OS Standby | 192.168.1.11 / 255.255.255.0 | 192.168.2.11 / 255.255.255.0 |
| CPU 417-5H #0 | 192.168.2.100 | - |
| CPU 417-5H #1 | 192.168.2.101 | - |
- From each server, ping the partner CP 1623 and both H-CPU IPs. Ping success is necessary but not sufficient; it confirms only L3 connectivity, not S7-REDCONNECT.
5.3 Correct the WinCC channel unit on both OS servers
- On the OS Master, open WinCC Explorer.
- Right-click Tag Management > System Parameters > Unit tab.
- In the Logical device list, select S7ONLINE → CP 1623 (ISO) for the terminal-bus connection and S7ONLINE → CP 1623 (TCP/IP) for the plant-bus connection. The choice between ISO and TCP depends on whether your plant network uses ISO-on-TCP (RFC1006) - the default for PCS 7 plant bus is ISO-on-TCP.
- Repeat the same selection on the OS Standby. The same logical device name must be chosen on both servers.
- Save and close WinCC Explorer on both servers.
5.4 Download the OS project to both servers
- On the ES, open the OS project editor for both master and standby.
- From the menu, choose PLC > Download > OS Servers (Complete Project). Always perform a complete download when changing connections; a delta download does not reset the channel unit binding.
- During download, WinCC prompts to overwrite the running project. Confirm Yes. The OS Runtime on each server stops, the project is replaced, and Runtime restarts automatically.
- Open WinCC Explorer > Tag Management on the standby. The S7 connections should now appear in the Connections list but remain flagged as read-only - this is the expected, correct state.
- If the connections still show as read-only and the underlying state is wrong, right-click the standby server and choose OS Project > Assign OS Server > Standby again, then repeat the download.
5.5 Verify the redundancy state in SIMATIC Shell
- On either OS server, open SIMATIC Shell from the desktop or Start > SIMATIC.
- Browse to OS Servers > [Project Name]. Both master and standby should be visible with the assigned role (Master / Standby) and state (Active / Passive).
- Right-click the partner server and choose Status. Confirm that the redundancy state reports OK and the role is correct.
- If you see Redundancy error, open the Redundancy.log under
<Project>\Redundancy. Typical entries and meanings:
| Log entry | Meaning | Fix |
|---|---|---|
| Partner not reachable on logical device | Channel unit mismatch | Re-run section 5.3 |
| CRC mismatch on XDB | NetPro not consistent | Re-run Save and Compile in NetPro |
| H-CPU not in redundant state | AS pair running solo | Check H-CPU mode on the HMI |
| License missing for redundancy | ASIA / redundancy license not activated | Install PCS 7 OS Redundancy license |
6. Why the Error Occurs on First Commissioning
The error message "Failed to edit the object. Note: The connection is read-only" is a WinCC protection layer that prevents an operator from changing a connection on the wrong station. In a fresh project this can appear immediately on the standby if any of the following conditions are true:
- The ES compiled NetPro before the CP 1623 driver was installed on the OS servers. The runtime then finds no matching adapter and locks the connection.
- The OS Standby was downloaded before the OS Master. PCS 7 expects the master to be downloaded first.
- The Windows firewall on the standby blocks the SIMATIC NET redundancy port (default TCP 4410 / UDP 4411 for S7-REDCONNECT). The standby boots in a partial state and locks connections defensively.
- The same CP 1623 MAC address is reported on both servers because of a virtualization layer or because the IPCs were cloned without randomizing MACs.
Each of these conditions is detectable with the tools in section 7.
7. Diagnostic Tools and Verification
| Tool | Where to find it | What it confirms |
|---|---|---|
| SIMATIC Shell | Desktop on each OS server | Master/standby role and reachability |
| WinCC Channel Diagnosis | WinCC Explorer > Tools > Channel Diagnosis | Connection state at runtime |
| SIMATIC NET Diagnostics | Start > SIMATIC > SIMATIC NET > Diagnostics | CP 1623 port state, frame errors |
| S7-REDCONNECT Trace | Configuration Console > CP 1623 > Trace | Establishment / break events |
| Windows Event Viewer | Eventvwr.msc > Applications and Services Log > Siemens | WinCC startup and license errors |
| Redundancy.log | <Project>\Redundancy | State transitions and errors |
| Ping | cmd > ping <AS IP> -t | L3 connectivity (necessary but not sufficient) |
| arp -a | cmd > arp -a | Verify the AS IP is reached via the CP 1623 MAC, not a wrong adapter |
7.1 Quick channel diagnosis script
The following command line check can be run on either OS server to confirm that the SIMATIC NET redundancy driver is alive:
sc query "S7RedundancyService" | findstr STATE
Expected output: STATE: 4 RUNNING. If the service is stopped, start it with sc start S7RedundancyService and rerun the OS download.
7.2 Tag liveness check
From any client, open WinCC Explorer, navigate to Tags > Internal > @Redundancy and read the tags @RedundancyState and @RedundancyLostCount. Healthy values:
| Tag | Healthy value |
|---|---|
| @RedundancyState | 1 (redundant, partner OK) |
| @RedundancyLostCount | 0 or near-zero during commissioning |
| @ServerState | 1 on master, 2 on standby |
8. Channel Unit Reassignment (Detailed)
Channel unit reassignment is the most frequent fix for the read-only error when the ES and the OS servers use different network adapters. The procedure below is the canonical Siemens approach and works for both CP 1623 and CP 1628.
- Close WinCC Runtime on the target OS server.
- Open WinCC Configuration Studio (WinCC V7.5) or WinCC Explorer (V7.4 and earlier).
- Navigate to Tag Management > SIMATIC S7 PROTOCOL SUITE > [your connection name] > System Parameters.
- Open the Unit tab. The list of logical devices is generated by the SIMATIC NET Configuration Console.
- Select the logical device that maps to the CP 1623 port bound to the plant bus. Confirm by clicking Test. A success dialog should appear; a failure indicates that the selected device is not bound to a live adapter.
- Repeat for each S7 connection on the master and then on the standby.
- Save the project and re-download to the affected server only.
9. Prevention for Future Projects
Adopt the following project conventions to avoid the read-only error on future PCS 7 V9 builds:
- Always commission OS servers with the same hardware revision and the same PCIe slot assignment for the CP 1623 cards. Use slot 5 (x4) on each IPC and document this in the cabinet layout drawing.
- Install the SIMATIC NET driver on the ES before opening NetPro. This makes the IE General adapter visible and prevents an early mismatch.
- Run Save and Compile > Consistent Whole Project from NetPro every time the AS or OS hardware is changed.
- Perform a complete OS download (master first, standby second) and never a delta download after NetPro changes.
- Activate the Siemens firewall rule set shipped with PCS 7 instead of the Windows default. The Siemens rules explicitly open TCP 102 (S7 communication), TCP 4410 (S7-REDCONNECT), and UDP 4411.
- Document the MAC address of each CP 1623 port in the PCS 7 project under PC Station > Properties > Interfaces. During commissioning, compare this against the
ipconfig /alloutput.
10. Verification Checklist
Use the following list before declaring the OS redundancy pair healthy:
| # | Check | Pass criterion |
|---|---|---|
| 1 | Master runtime starts without error | No red entries in WinCC startup log |
| 2 | Standby runtime starts without error | WinCC log shows Passive mode entered |
| 3 | Tag liveness on master | Internal clock tag updates every second |
| 4 | Tag liveness on standby after master stop | Same internal clock tag continues to update |
| 5 | SIMATIC Shell redundancy state | OK on both servers |
| 6 | @RedundancyState | 1 throughout the test |
| 7 | Fault-tolerance test (pull one H-CPU power) | No tag interruption longer than 2 s |
| 8 | Failover test (stop master runtime) | Standby becomes master within 5 s |
| 9 | Read-only check on standby | Tag Management connections visible and read-only as expected |
| 10 | Channel Diagnosis on master | All H connections show Established |
11. Frequently Asked Questions
Question?
Why does WinCC show "Failed to edit the object. Note: The connection is read-only" on the OS Standby?
WinCC intentionally flags every S7 connection on the standby server as read-only because only the active server establishes connections to the AS pair. The lock is a design feature, not a fault, and protects the redundant configuration from diverging. Edit the connection on the master or in the ES project and re-download.
Question?
Does the read-only state mean the S7 connection is broken on the standby?
No. On a healthy redundant pair the standby stores a mirrored copy of the master's connection but never actively opens it. Connections are read-only because they are managed from a single source. If you also see dead tags and a "Redundancy error" in SIMATIC Shell, the cause is a NetPro mismatch or a wrong channel unit, not the read-only flag itself.
Question?
How do I select the CP 1623 channel unit on the standby server?
Open WinCC Explorer on the standby, navigate to Tag Management > System Parameters > Unit tab, and choose the logical device that maps to the CP 1623 plant-bus port (typically S7ONLINE → CP 1623 ISO). The same logical device must be selected on both OS servers and must match the interface used in NetPro.
Question?
Do I have to manually reconfigure the connection on the standby after every download?
No. With a correct NetPro compile and channel unit assignment, the standby inherits the master's configuration at download time. Manual changes on the standby are blocked on purpose; any edit must be made on the master or on the ES.
Question?
Which SIMATIC PCS 7 version first enforced the read-only behavior on standby connections?
The behavior has been part of WinCC since V6.2 SP2 with PCS 7 V8.0 SP1 and was carried forward into PCS 7 V9.0 SP1. The dialog text was refined in WinCC V7.4 SP1. The underlying mechanism is the S7-REDCONNECT driver that ships with SIMATIC NET.
Question?
Can I disable the read-only state by editing the registry?
No. The lock is enforced by WinCC at runtime, not by a registry flag. Disabling it would corrupt the redundant configuration. Always resolve the underlying NetPro or channel unit mismatch instead of attempting to bypass the protection.