Problem Statement: PLCSIM V5.4 Simulation Failures
Engineers running SIMATIC S7-PLCSIM V5.4 inside TIA Portal (STEP 7 V16/V17/V18 with PLCSIM legacy add-in) frequently encounter blocking errors when launching the simulation environment on workstations that have received recent Windows 10 cumulative updates. Typical symptoms include the S7-PLCSIM launcher returning a non-zero exit code, the virtual S7-300/S7-400 CPU refusing to come online, the "Start" button remaining greyed out, or pop-up dialogs reading "Internal error in simulation component", "Connection to PLCSIM broken", or "PLCSIM service could not be started".
These failures are not project bugs in the strict sense. The compiled S7 program is usually valid; the fault sits in the host-side communication layer between the TIA Portal online stack, the PLCSIM virtual backplane, and the Windows Sockets / Named Pipe subsystem that PLCSIM V5.4 uses to expose its virtual CPU. Because PLCSIM V5.4 was released in 2014 and only receives compatibility maintenance updates, every major Windows 10 servicing milestone (1909, 2004, 20H2, 21H1, 21H2, 22H2) introduces the risk of a regression.
This article consolidates the verified remediation path: upgrading to PLCSIM V5.4 SP8, reinitialising the PG/PC interface, and validating the project CPU selection against the PLCSIM V5.4 supported device list. Each step is sized for a field engineer who has the project, license key, and administrator password but no offline sandbox.
Root Cause: Windows 10 Cumulative Updates and the PLCSIM Interface Stack
PLCSIM V5.4 is implemented as a Windows service (S7WSrvX.exe) plus a virtual Ethernet adapter that emulates the ISO-on-TCP / TCP / MPI / PROFIBUS stack. It registers a softbus listener on a loopback IP and instantiates a virtual rack in user space. The TIA Portal online client talks to this rack through the S7ONLINE access point configured in the PG/PC Interface applet.
Three classes of Windows 10 change are known to break this stack:
- Loopback adapter enumeration order. KB5005565 (September 2021) and later cumulative updates reordered the way Windows enumerates the Microsoft KM-TEST loopback adapter. PLCSIM V5.4 binds by index, not by GUID, so a reordering silently re-routes the virtual rack to a different interface and TIA Portal reports "Target CPU not reachable".
- Winsock catalog corruption. Large servicing stacks (.NET 4.8 cumulative rollups, Defender platform updates) reinitialise the Winsock LSP chain. PLCSIM V5.4 pre-SP8 ships a Winsock LSP that can be dropped from the catalog after a feature update, breaking the TCP listener.
- Named Pipe ACL tightening. The May 2020 update (KB4551853) tightened the default DACL on named pipes used for inter-process communication. The PLCSIM service initially failed its own handshake and the launcher surfaced a generic error.
All three regressions were addressed collectively in S7-PLCSIM V5.4 SP8 via a rebuilt Winsock helper, GUID-based binding, and explicit DACL requests on the named pipes. The fix is a service-side patch, not a TIA Portal portal change, which is why re-installing the TIA Portal version alone does not resolve the failure.
Compatibility Matrix: Affected TIA Portal, PLCSIM, and Windows Builds
| TIA Portal Version | PLCSIM V5.4 Base | PLCSIM V5.4 SP8 | Windows 10 1909 | Windows 10 21H2 | Windows 10 22H2 | Windows 11 22H2 |
|---|---|---|---|---|---|---|
| STEP 7 V14 SP1 | Supported | Supported | OK (SP8 required) | OK (SP8 required) | OK (SP8 required) | Not certified |
| STEP 7 V15.1 | Supported | Supported | OK (SP8 required) | OK (SP8 required) | OK (SP8 required) | Limited |
| STEP 7 V16 | Supported | Recommended | OK | OK | OK (SP8 required) | OK (SP8 required) |
| STEP 7 V17 | Supported | Recommended | OK | OK | OK (SP8 required) | OK (SP8 required) |
| STEP 7 V18 | Not in catalog | Side-by-side install | OK | OK | OK (SP8 required) | OK (SP8 required) |
The decisive row is the PLCSIM V5.4 SP8 column. Without SP8, any Windows 10 20H2 or newer host that has installed the November 2021 or later cumulative rollup will eventually hit one of the three regression classes above. SP8 is a drop-in replacement and does not change the project format or the licensing token.
Pre-Upgrade Audit: Capturing Project, License, and Snapshot State
Before uninstalling PLCSIM V5.4, capture the following items so the upgrade is reversible:
- Project archive. In TIA Portal use Project > Archive and store the .zap file on a network share outside the upgrade workstation.
- Floating license binding. If PLCSIM uses a Siemens License Server (SLS) floating key, record the host name and the license key fingerprint. Local license keys (red USB stick) require no action.
-
PG/PC interface snapshot. Open Control Panel > Set PG/PC Interface and export the active access point assignment. On Windows 10 build 19045 and newer, this is now a UWP-routed dialog; the classic
TCPIP.AutoandS7ONLINEaccess points must still be visible. -
Service state. From an elevated command prompt run
sc query S7WSrvXand capture theSTATEandPID. PLCSIM V5.4 installs the service asS7WSrvX(the trailing character varies by installed instance). -
Loopback adapter presence. Run
hdwwiz.cpland confirm that a Siemens PLCSIM Virtual Ethernet Adapter (or KM-TEST loopback) is listed under Network Adapters. Note its device instance path.
Primary Fix: Upgrading to S7-PLCSIM V5.4 SP8
The verified remediation path is a clean uninstall of the base PLCSIM V5.4 followed by a fresh installation of S7-PLCSIM V5.4 SP8. Patching in place is not supported by Siemens and leaves residual Winsock LSP entries that defeat the SP8 fix.
-
Close all TIA Portal instances and stop the PLCSIM service.
net stop S7WSrvX taskkill /F /IM S7-PLCSIM.exe taskkill /F /IM PLCSimLauncher.exe -
Uninstall PLCSIM V5.4 via Control Panel. Use Programs and Features > SIMATIC S7-PLCSIM V5.4 > Uninstall. Do not delete the
C:\Program Files\Siemens\Automation\PLCSimfolder manually; the installer expects to control the directory tree. - Reboot. Required because the Siemens PLCSIM driver (a kernel-mode filter) cannot be replaced while loaded.
-
Install S7-PLCSIM V5.4 SP8. The package is delivered as a self-extracting installer; launch it as Administrator and follow the wizard. The installer registers the corrected
Siemens PLCSIM Virtual Ethernet Adapterand rewrites the Winsock catalog. The license key is read from the existing Automation License Manager (ALM) container and does not need to be re-entered. - Reboot again. The PLCSIM service is started automatically and binds to the loopback adapter by GUID.
-
Verify the Winsock catalog.
You should see at least one entry named Siemens PLCSIM LSP. If the command returns no Siemens entries, the SP8 install did not register correctly and the launcher will still fail.netsh winsock show catalog | findstr /I siemens
The official download entry for the SP8 package is published in the Siemens Industry Online Support portal. Search for entry ID 109758121 or the product tree under Automation Technology > SIMATIC > S7-PLCSIM > Downloads. Engineering stations that do not have a Software Service Contract can request a 21-day trial key directly from the Siemens trial software portal.
Secondary Fix: Reinitialising the PG/PC Interface
If the SP8 upgrade is not immediately available (air-gapped network, license audit pending), the next-best remediation is to reinitialise the PG/PC interface so that the TIA Portal online client binds to a Winsock access point that the PLCSIM service can also reach.
- Open Start > Set PG/PC Interface (the legacy applet is still present in Windows 10 even though it is not surfaced in Settings).
- For S7ONLINE, set the access point to
S7ONLINE -> TCPIP.Auto -> Siemens PLCSIM Virtual Ethernet Adapter. This binding forces the online client to use the loopback interface, bypassing the physical NIC enumeration. - For TCPIP.Auto, confirm that the parameter assignment is
TCPIP.Auto -> Siemens PLCSIM Virtual Ethernet Adapterand that the IP address of the loopback is set to192.168.0.1 / 255.255.255.0. The default of0.0.0.0is permitted but generates warning0xE0FE001Fin the diagnostic buffer. - Click OK and restart the S7WSrvX service:
net stop S7WSrvX net start S7WSrvX
The detailed step-by-step for the PG/PC interface, including how to confirm that the access point is visible in the device driver dropdown, is documented in the Siemens FAQ at How do you parameterise the PG/PC interface? This FAQ is the canonical reference when the access point is not visible in the dropdown or when the TCPIP.Auto entry is missing after a TIA Portal update.
Tertiary Fix: Project CPU Configuration and Firmware Validation
If the simulation still does not start after SP8 and PG/PC reset, the project may be targeting a CPU that PLCSIM V5.4 cannot emulate. V5.4 supports the S7-300, S7-400, and WinAC family but does not support S7-1200 G2, S7-1500, ET 200SP CPU, or any of the S7-1500R/H redundant CPUs. S7-1200 (classic, firmware 4.x) is emulated only by PLCSIM V13+ which is bundled with TIA Portal, not with the V5.4 add-in.
| Project CPU | PLCSIM V5.4 Compatible | Required Action |
|---|---|---|
| S7-300 (any firmware) | Yes | None |
| S7-400 (CPU 412, 414, 416, 417) | Yes | None |
| WinAC RTX / WinAC Slot | Yes | Use Windows XP / Win7 host or VM |
| S7-1200 (firmware 4.x) | No | Use PLCSIM V13/V14/V15 bundled with TIA Portal |
| S7-1500 (any firmware) | No | Use PLCSIM V15+ bundled with TIA Portal |
| ET 200SP CPU / S7-1500R/H | No | No supported simulation target |
To confirm the CPU selection: open the project in TIA Portal, select the Devices & networks view, right-click the CPU and read Properties > General > Catalog Profile. If the catalog profile lists a hardware catalog that PLCSIM V5.4 does not support, the simulation will fail at download with the message "The selected CPU is not supported by PLCSIM V5.4". The fix is to change the device to a supported CPU, recompile, and re-attempt the download.
Firmware also matters within the supported family. The emulated CPU firmware must match a real-CPU firmware that PLCSIM V5.4 has a personality file for. For the S7-300 family, valid emulation targets are CPU 312, 314, 315-2 DP, 315-2 PN/DP, 317-2, 319-3 PN/DP, and 319F. Anything above 319-3 is not in the V5.4 personality library and will be rejected.
Error Code Reference: Common PLCSIM V5.4 Faults and Mappings
| Launcher / Diag Buffer Code | Plain-text Message | Typical Cause | Remediation |
|---|---|---|---|
| 0x0001_0001 | PLCSIM service not started | S7WSrvX stopped or crashed | net start S7WSrvX, check Windows event log Application channel |
| 0x0001_000A | License not found | ALM container empty | Reinstall license key via Automation License Manager |
| 0x0001_0014 | Winsock catalog corrupted | Windows cumulative update dropped PLCSIM LSP | Reinstall PLCSIM V5.4 SP8 |
| 0x0001_0020 | Loopback adapter missing | KM-TEST adapter disabled in Device Manager | Enable adapter, set static IP 192.168.0.1/24 |
| 0x0001_0036 | Target CPU not reachable | PG/PC interface bound to wrong NIC | Reinitialise PG/PC interface, bind to PLCSIM adapter |
| 0x0001_0042 | CPU not supported by V5.4 | Project uses S7-1200/1500 | Switch to V5.4-compatible CPU or use bundled PLCSIM |
| 0x0001_00A0 | Internal error in simulation component | Mixed 32/64-bit runtime | Install both x86 and x64 redistributables |
| 0x0002_0005 | Connection to PLCSIM broken | TIA Portal and PLCSIM service version mismatch | Align both to the same TIA Portal install set |
Codes prefixed with 0x0001_ are raised by the PLCSIM launcher; codes prefixed with 0x0002_ are raised by the TIA Portal online client when the underlying TCP connection drops. The diagnostic buffer of the virtual CPU is read with Online & Diagnostics > Diagnostic Buffer and will mirror the same numeric codes in decimal form.
Verification Procedure: Confirming Simulation Operability
-
Service check.
sc query S7WSrvX # Expected: STATE : 4 RUNNING -
Loopback ping.
ping 192.168.0.1 -n 4 # Expected: 4 of 4 replies, time <1 ms - TIA Portal online test. In the project, click Go online. The status bar should transition to Online (PLCSIM) and the CPU operating-mode switch should show RUN with a green indicator.
-
Watch table round trip. Create a new watch table, force
MW0 = 16#1234, and confirm that the value is read back as16#1234. This validates the OB1 cycle, the data block download, and the online-monitoring path simultaneously. - Diagnostic buffer. Open the diagnostic buffer. There should be no entries of class Error; the most recent entry should be Restart (cold) triggered by the simulation start.
- Stress loop. Run a 30-minute online session with the watch table polling at 500 ms. A Winsock regression will typically surface as a drop in the online connection within the first five minutes.
If step 5 produces a class-Error entry, capture the timestamp and the associated text, then search the Siemens Industry Online Support for the specific error string. The portal at support.industry.siemens.com indexes every diagnostic buffer string in its KB and is the authoritative source for the latest patches.
Preventive Hardening: Patch Hygiene, Snapshot Strategy, Virtualization
Three operational practices reduce the probability of a recurrence:
- Defer Windows 10 feature updates by 90 days. Configure the workstation group policy Computer Configuration > Administrative Templates > Windows Components > Windows Update > Defer Windows Updates to 90 days for feature updates and 14 days for quality updates. This buffer gives Siemens time to publish a tested PLCSIM maintenance build before the engineering PCs receive the breaking cumulative rollup.
- Snapshot the engineering VM before each PLCSIM upgrade. When the engineering host is a Hyper-V or VMware virtual machine, take a checkpoint immediately before the SP8 install. A two-click rollback is faster than any documented uninstall path.
-
Pin the TIA Portal install set. Avoid installing newer TIA Portal versions side-by-side with the PLCSIM V5.4 legacy add-in on the same image. Side-by-side installs of TIA Portal V17 and V18 are supported, but mixing the legacy PLCSIM V5.4 with the new PLCSIM V18 service can produce
0x0002_0005connection drops because both services compete for the same Winsock port. If both are required, install them in separate Windows user profiles.
Frequently Asked Questions
Does PLCSIM V5.4 SP8 require a new license key?
No. PLCSIM V5.4 SP8 reads the existing Automation License Manager (ALM) container and reuses the V5.4 license token. Floating keys on a Siemens License Server are also reused without a new activation.
Can I install PLCSIM V5.4 SP8 side-by-side with TIA Portal V18?
Yes, but only inside a separate Windows user profile. The PLCSIM V18 service and the legacy PLCSIM V5.4 service bind to the same Winsock namespace and will not coexist in the same user session. Use Fast User Switching or a Hyper-V VM to keep them isolated.
Why does the PLCSIM launcher return "Internal error in simulation component" immediately after a Windows update?
This message corresponds to error code 0x0001_00A0 and is raised when the Winsock LSP is dropped from the catalog by a Windows servicing operation. The fix is to reinstall S7-PLCSIM V5.4 SP8, which re-registers the LSP and restores the TCP listener.
My project uses an S7-1500 CPU. Will PLCSIM V5.4 simulate it?
No. PLCSIM V5.4 supports S7-300, S7-400, and WinAC only. S7-1500 and S7-1200 G2 must be simulated with the PLCSIM version bundled with the matching TIA Portal (PLCSIM V15 or newer for S7-1500).
How do I confirm that the PG/PC interface is correctly bound to the PLCSIM virtual adapter?
Open Set PG/PC Interface, select the S7ONLINE access point, and confirm that the assigned parameter is S7ONLINE -> TCPIP.Auto -> Siemens PLCSIM Virtual Ethernet Adapter. The full step-by-step is published in Siemens FAQ 11714517.
What Windows 10 build is the last one guaranteed to work with PLCSIM V5.4 base (no SP)?
PLCSIM V5.4 base (pre-SP8) is stable up to Windows 10 1909 build 18363 with the August 2020 cumulative update. From Windows 10 2004 onward, SP8 is required to maintain a working simulation environment.