Resolving PCS 7 V9 Standby OS Server Connection Read-Only Error

David Krause15 min read
SCADA ConfigurationSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving PCS 7 V9 Standby OS Server Connection Read-Only Error

In a PCS 7 V9.0 SP1 OS server/standby pair with an S7-400H (CPU 417-5H) automation system and two CP 1623 industrial Ethernet cards per OS station, operators frequently encounter the WinCC Explorer error "Failed to edit the object. Note: The connection is read-only" when attempting to change S7 connections on the standby server. This reference explains the underlying cause, the intended protection mechanism, and the precise engineering workflow that restores runtime connectivity without breaking redundant behavior.

Affected products: SIMATIC PCS 7 V9.0 SP1 (component version TIA Portal / STEP 7 V5.6 + WinCC V7.5 / PCS 7 OS V9.0), CPU 417-5H (6ES7417-5HT06-0AB0 and compatible), CP 1623 (6GK1162-3AA00), CP 1628 (6GK1162-8AA00) as alternate, SIMATIC IPC industrial workstations running Windows Server 2016 / 2019.

1. Problem Statement

A typical redundant OS architecture is configured as follows:

  • One PCS 7 engineering station (ES) with SIMATIC Manager / PCS 7 V9.0 SP1.
  • One OS Master server and one OS Standby server, each equipped with two CP 1623 PCIe cards.
  • Five OS Clients that subscribe to the master/standby pair.
  • One AS pair with two CPU 417-5H controllers in fault-tolerant H mode.
  • SIMATIC NET OPC / S7-REDCONNECT redundancy over the CP 1623 interfaces.

After a successful project download to both servers the following symptoms are observed:

Symptom Master OS Server Standby OS Server
Runtime starts and logs into the AS pair OK - tags are updating Runtime not connected / tags dead
Redundancy partner reachable via SIMATIC Shell OK Partner detected but not alive
S7 connections in Tag Management Editable Read-only
Diagnostic error None "Failed to edit the object. Note: The connection is read-only"
Ping to CPU 417-5H IP OK OK

The fact that ICMP ping to the H-CPU IP succeeds on the standby confirms that the physical network path is intact. The actual fault therefore lies inside the WinCC connection layer, in the NetPro database, or in the CP 1623 channel unit assignment.

2. Root Cause Analysis

Three independent root causes are routinely responsible for the symptoms described above. In most field cases, more than one applies simultaneously.

2.1 Standby connections are intentionally read-only

PCS 7 OS redundancy is implemented through S7-REDCONNECT. The redundancy layer duplicates all configured S7 connections from the master to the standby, but only the currently active server opens the S7 connection to the AS pair. The passive standby server stores the same S7 connection configuration but never actively establishes it. To prevent an operator on the standby server from creating a configuration that diverges from the master, WinCC flags every S7 connection on the standby station as read-only. Trying to edit it produces the dialog "Failed to edit the object. Note: The connection is read-only". The correct place to change the connection is on the master or, preferably, in the ES project.

Design intent: Read-only on the standby is not a bug. It is enforced by WinCC because configuration changes must originate from a single source to keep both servers synchronized. Any attempt to edit connections locally on the standby will fail by design.

2.2 NetPro S7 connection does not match between ES and standby

If the NetPro database on the ES differs from the runtime database on the standby server (different CP 1623 interface selected, missing H connection, different partner IP), the standby will boot in a degraded state. WinCC then locks the local copy of the connection to avoid corrupting it further, producing the read-only error.

2.3 Wrong channel unit selected on the standby

This is the most common mistake. The ES was configured against an IE General adapter (CP 1613/IE onboard), but the actual OS servers use CP 1623. After the download, the standby binds the connection to a non-existent adapter. WinCC again protects the configuration and reports it as read-only because the underlying channel cannot be opened.

3. Affected Versions and Compatibility

Component Order Number / Version Status
SIMATIC PCS 7 V9.0 SP1 (released 2018) Affected - bug fixed in PCS 7 V9.0 SP2 / SP3 with HSP updates
SIMATIC PCS 7 V9.1 / V9.1 SP1 Not affected when configured correctly
WinCC V7.5 SP1 Update 6 / later Recommended patch level
SIMATIC NET CP 1623 6GK1162-3AA00 (firmware V2.x) Affected when channel unit is wrong
SIMATIC NET CP 1628 6GK1162-8AA00 Alternative, recommended for new builds
CPU 417-5H 6ES7417-5HT06-0AB0, FW V6.0.7+ Standard H-CPU for redundant AS
Windows Server 2016 LTSC / 2019 LTSC Certified OS for PCS 7 V9

The original PCS 7 V9.0 SP1 release notes (entry ID 109769534 in the Siemens Industry Online Support) and the SIMATIC PCS 7 OS Configuration Manual (entry ID 109751904) explicitly call out the requirement to match NetPro connections and CP channel units before commissioning OS redundancy.

4. Prerequisites

Before applying the procedure below, ensure the following conditions are met:

  1. Both OS servers and the ES are members of the same Windows domain or workgroup with identical administrator accounts.
  2. The PCS 7 V9.0 SP1 installation is the same on all three PCs (ES, master, standby). Verify with Start > SIMATIC > SIMATIC Manager > Help > About and the Windows Programs and Features list.
  3. Both CP 1623 cards are physically installed in the same PCIe slot position on each IPC (recommended for documentation). Record the MAC address of every port with SIMATIC NET > Commissioning > Commissioning Wizard.
  4. Latest SIMATIC NET driver package is installed. For CP 1623 use SIMATIC NET PC Software V17 or later (entry ID 109769086), recommended for PCS 7 V9.0 SP1.
  5. The H-CPU pair is in redundant mode (RUN-REDUNDANT), not solo. Both 417-5H CPUs must show H-Sync active on the HMI display.
  6. The PCS 7 project on the ES is consistent. Run Project > Check Consistency in SIMATIC Manager and resolve all warnings before downloading.

5. Step-by-Step Resolution Procedure

The procedure below restores the standby server while preserving OS redundancy. It assumes you have full administrative access to the ES and both OS servers.

5.1 Validate NetPro connections on the ES

  1. Open SIMATIC Manager and load the PCS 7 project from the ES archive.
  2. Open NetPro from Options > NetPro or by clicking the NetPro toolbar button.
  3. Select the OS Master station and confirm that an H connection (S7 connection, fault-tolerant) is configured from the OS Master to the S7-400H AS pair, not a standard S7 connection.
  4. Select the OS Standby station. Confirm that the identical H connection exists with the same connection ID, partner IP, and rack/slot.
  5. Open the properties of each H connection and verify the following parameters:
Property Required value
Connection type S7 connection fault-tolerant
Partner (AS) S7-400H station object, not a single CPU
Interface on OS CP 1623 (#1) - rack 0, slot corresponds to PCIe index
Interface on AS CP 443-1 / integrated PN interface, both H-CPUs
Connection resource Same connection ID on master and standby (e.g. 0x0001)
Establishment Active on master, mirrored to standby
  1. If the standby H connection is missing, right-click the OS Standby station, choose Insert New Connection > S7 Connection Fault-Tolerant and link it to the same AS pair. Use Save and Compile (Network > Save and Compile) to push the new XDB to all OS stations.
  2. Confirm there are no yellow or red entries in the Consistency Check dialog. A clean compile is a hard prerequisite; do not skip it.

5.2 Verify CP 1623 installation on every OS server

  1. Open SIMATIC NET > Commissioning > Configuration Console on each OS server.
  2. Confirm that both CP 1623 cards are visible under Modules > PC Station. Note the MAC address and index of every port. They must be the same physical position (same PCIe slot) on master and standby so the index mapping is identical.
  3. Assign IP addresses / subnet masks through the configuration console, not through Windows. Recommended scheme:
Server CP 1623 #1 (terminal bus) CP 1623 #2 (plant bus)
OS Master 192.168.1.10 / 255.255.255.0 192.168.2.10 / 255.255.255.0
OS Standby 192.168.1.11 / 255.255.255.0 192.168.2.11 / 255.255.255.0
CPU 417-5H #0 192.168.2.100 -
CPU 417-5H #1 192.168.2.101 -
  1. From each server, ping the partner CP 1623 and both H-CPU IPs. Ping success is necessary but not sufficient; it confirms only L3 connectivity, not S7-REDCONNECT.

5.3 Correct the WinCC channel unit on both OS servers

  1. On the OS Master, open WinCC Explorer.
  2. Right-click Tag Management > System Parameters > Unit tab.
  3. In the Logical device list, select S7ONLINE → CP 1623 (ISO) for the terminal-bus connection and S7ONLINE → CP 1623 (TCP/IP) for the plant-bus connection. The choice between ISO and TCP depends on whether your plant network uses ISO-on-TCP (RFC1006) - the default for PCS 7 plant bus is ISO-on-TCP.
  4. Repeat the same selection on the OS Standby. The same logical device name must be chosen on both servers.
  5. Save and close WinCC Explorer on both servers.
Why this fixes the read-only error: When the ES was configured with a different adapter (for example IE General), NetPro saved an interface reference that the CP 1623 driver cannot resolve at runtime. The WinCC channel layer then refuses to expose the connection as editable, even on the master, and locks it everywhere. After the channel unit is corrected, the connection becomes writable again on the master and properly shadowed on the standby.

5.4 Download the OS project to both servers

  1. On the ES, open the OS project editor for both master and standby.
  2. From the menu, choose PLC > Download > OS Servers (Complete Project). Always perform a complete download when changing connections; a delta download does not reset the channel unit binding.
  3. During download, WinCC prompts to overwrite the running project. Confirm Yes. The OS Runtime on each server stops, the project is replaced, and Runtime restarts automatically.
  4. Open WinCC Explorer > Tag Management on the standby. The S7 connections should now appear in the Connections list but remain flagged as read-only - this is the expected, correct state.
  5. If the connections still show as read-only and the underlying state is wrong, right-click the standby server and choose OS Project > Assign OS Server > Standby again, then repeat the download.

5.5 Verify the redundancy state in SIMATIC Shell

  1. On either OS server, open SIMATIC Shell from the desktop or Start > SIMATIC.
  2. Browse to OS Servers > [Project Name]. Both master and standby should be visible with the assigned role (Master / Standby) and state (Active / Passive).
  3. Right-click the partner server and choose Status. Confirm that the redundancy state reports OK and the role is correct.
  4. If you see Redundancy error, open the Redundancy.log under <Project>\Redundancy. Typical entries and meanings:
thead>
Log entry Meaning Fix
Partner not reachable on logical device Channel unit mismatch Re-run section 5.3
CRC mismatch on XDB NetPro not consistent Re-run Save and Compile in NetPro
H-CPU not in redundant state AS pair running solo Check H-CPU mode on the HMI
License missing for redundancy ASIA / redundancy license not activated Install PCS 7 OS Redundancy license

6. Why the Error Occurs on First Commissioning

The error message "Failed to edit the object. Note: The connection is read-only" is a WinCC protection layer that prevents an operator from changing a connection on the wrong station. In a fresh project this can appear immediately on the standby if any of the following conditions are true:

  • The ES compiled NetPro before the CP 1623 driver was installed on the OS servers. The runtime then finds no matching adapter and locks the connection.
  • The OS Standby was downloaded before the OS Master. PCS 7 expects the master to be downloaded first.
  • The Windows firewall on the standby blocks the SIMATIC NET redundancy port (default TCP 4410 / UDP 4411 for S7-REDCONNECT). The standby boots in a partial state and locks connections defensively.
  • The same CP 1623 MAC address is reported on both servers because of a virtualization layer or because the IPCs were cloned without randomizing MACs.

Each of these conditions is detectable with the tools in section 7.

7. Diagnostic Tools and Verification

Tool Where to find it What it confirms
SIMATIC Shell Desktop on each OS server Master/standby role and reachability
WinCC Channel Diagnosis WinCC Explorer > Tools > Channel Diagnosis Connection state at runtime
SIMATIC NET Diagnostics Start > SIMATIC > SIMATIC NET > Diagnostics CP 1623 port state, frame errors
S7-REDCONNECT Trace Configuration Console > CP 1623 > Trace Establishment / break events
Windows Event Viewer Eventvwr.msc > Applications and Services Log > Siemens WinCC startup and license errors
Redundancy.log <Project>\Redundancy State transitions and errors
Ping cmd > ping <AS IP> -t L3 connectivity (necessary but not sufficient)
arp -a cmd > arp -a Verify the AS IP is reached via the CP 1623 MAC, not a wrong adapter

7.1 Quick channel diagnosis script

The following command line check can be run on either OS server to confirm that the SIMATIC NET redundancy driver is alive:

sc query "S7RedundancyService" | findstr STATE

Expected output: STATE: 4 RUNNING. If the service is stopped, start it with sc start S7RedundancyService and rerun the OS download.

7.2 Tag liveness check

From any client, open WinCC Explorer, navigate to Tags > Internal > @Redundancy and read the tags @RedundancyState and @RedundancyLostCount. Healthy values:

Tag Healthy value
@RedundancyState 1 (redundant, partner OK)
@RedundancyLostCount 0 or near-zero during commissioning
@ServerState 1 on master, 2 on standby

8. Channel Unit Reassignment (Detailed)

Channel unit reassignment is the most frequent fix for the read-only error when the ES and the OS servers use different network adapters. The procedure below is the canonical Siemens approach and works for both CP 1623 and CP 1628.

  1. Close WinCC Runtime on the target OS server.
  2. Open WinCC Configuration Studio (WinCC V7.5) or WinCC Explorer (V7.4 and earlier).
  3. Navigate to Tag Management > SIMATIC S7 PROTOCOL SUITE > [your connection name] > System Parameters.
  4. Open the Unit tab. The list of logical devices is generated by the SIMATIC NET Configuration Console.
  5. Select the logical device that maps to the CP 1623 port bound to the plant bus. Confirm by clicking Test. A success dialog should appear; a failure indicates that the selected device is not bound to a live adapter.
  6. Repeat for each S7 connection on the master and then on the standby.
  7. Save the project and re-download to the affected server only.
If the Test button reports Device not reachable, the configuration console has not assigned an IP to that CP 1623 port. Return to section 5.2 and complete IP assignment before continuing.

9. Prevention for Future Projects

Adopt the following project conventions to avoid the read-only error on future PCS 7 V9 builds:

  1. Always commission OS servers with the same hardware revision and the same PCIe slot assignment for the CP 1623 cards. Use slot 5 (x4) on each IPC and document this in the cabinet layout drawing.
  2. Install the SIMATIC NET driver on the ES before opening NetPro. This makes the IE General adapter visible and prevents an early mismatch.
  3. Run Save and Compile > Consistent Whole Project from NetPro every time the AS or OS hardware is changed.
  4. Perform a complete OS download (master first, standby second) and never a delta download after NetPro changes.
  5. Activate the Siemens firewall rule set shipped with PCS 7 instead of the Windows default. The Siemens rules explicitly open TCP 102 (S7 communication), TCP 4410 (S7-REDCONNECT), and UDP 4411.
  6. Document the MAC address of each CP 1623 port in the PCS 7 project under PC Station > Properties > Interfaces. During commissioning, compare this against the ipconfig /all output.

10. Verification Checklist

Use the following list before declaring the OS redundancy pair healthy:

# Check Pass criterion
1 Master runtime starts without error No red entries in WinCC startup log
2 Standby runtime starts without error WinCC log shows Passive mode entered
3 Tag liveness on master Internal clock tag updates every second
4 Tag liveness on standby after master stop Same internal clock tag continues to update
5 SIMATIC Shell redundancy state OK on both servers
6 @RedundancyState 1 throughout the test
7 Fault-tolerance test (pull one H-CPU power) No tag interruption longer than 2 s
8 Failover test (stop master runtime) Standby becomes master within 5 s
9 Read-only check on standby Tag Management connections visible and read-only as expected
10 Channel Diagnosis on master All H connections show Established

11. Frequently Asked Questions

Question?

Why does WinCC show "Failed to edit the object. Note: The connection is read-only" on the OS Standby?

WinCC intentionally flags every S7 connection on the standby server as read-only because only the active server establishes connections to the AS pair. The lock is a design feature, not a fault, and protects the redundant configuration from diverging. Edit the connection on the master or in the ES project and re-download.

Question?

Does the read-only state mean the S7 connection is broken on the standby?

No. On a healthy redundant pair the standby stores a mirrored copy of the master's connection but never actively opens it. Connections are read-only because they are managed from a single source. If you also see dead tags and a "Redundancy error" in SIMATIC Shell, the cause is a NetPro mismatch or a wrong channel unit, not the read-only flag itself.

Question?

How do I select the CP 1623 channel unit on the standby server?

Open WinCC Explorer on the standby, navigate to Tag Management > System Parameters > Unit tab, and choose the logical device that maps to the CP 1623 plant-bus port (typically S7ONLINE → CP 1623 ISO). The same logical device must be selected on both OS servers and must match the interface used in NetPro.

Question?

Do I have to manually reconfigure the connection on the standby after every download?

No. With a correct NetPro compile and channel unit assignment, the standby inherits the master's configuration at download time. Manual changes on the standby are blocked on purpose; any edit must be made on the master or on the ES.

Question?

Which SIMATIC PCS 7 version first enforced the read-only behavior on standby connections?

The behavior has been part of WinCC since V6.2 SP2 with PCS 7 V8.0 SP1 and was carried forward into PCS 7 V9.0 SP1. The dialog text was refined in WinCC V7.4 SP1. The underlying mechanism is the S7-REDCONNECT driver that ships with SIMATIC NET.

Question?

Can I disable the read-only state by editing the registry?

No. The lock is enforced by WinCC at runtime, not by a registry flag. Disabling it would corrupt the redundant configuration. Always resolve the underlying NetPro or channel unit mismatch instead of attempting to bypass the protection.

Back to blog