Problem Description
Engineers commissioning a new SIMATIC S7-1215C CPU and a KTP700 HMI on a Windows 7 virtual machine (VirtualBox host: Windows 10, TIA Portal V13 SP8) frequently encounter a misleading "device not compatible" error in the TIA Portal Device View. The user-visible symptom chain is reproducible:
- Online > Accessible devices lists both the S7-1215C and the KTP700.
- The MAC address displayed in the discovery dialog matches the sticker on the CPU front panel.
- The IP and PROFINET device name can be assigned from the Online > Accessible devices dialog (a PROFINET DCP write succeeds).
- When a new project is created with an Unspecified CPU 1200 placeholder and the user clicks Detect (Hardware detection), TIA Portal returns the diagnostic: "Device not compatible" in the Device View status bar.
- Manually configuring the S7-1215C from the hardware catalog and attempting to download the project to the CPU also fails with the same diagnostic text.
The error string is generated by TIA Portal's compatibility check between the selected hardware catalog entry and the target device's reported firmware, but in a VirtualBox environment it is almost always a transport-layer problem being surfaced as a compatibility fault. The CPU is not incompatible; TIA Portal cannot complete the firmware inventory read over the PROFINET channel.
Environment and Hardware Identification
The original failure scenario is summarised below. Reproducing the exact configuration helps establish the working baseline before applying the fix.
| Component | Model / Version | Notes |
|---|---|---|
| Engineering software | Siemens TIA Portal V13 SP8 (Update 8) | Last service pack of the V13 line; supports S7-1200 firmware V4.0 / V4.1 / V4.2 |
| CPU | SIMATIC S7-1215C, MLFB 6ES7215-1AG40-0XB0 (DC/DC/DC) | Two PROFINET ports, FW V4.2 out of the box |
| HMI | SIMATIC KTP700 Basic PN | Connected to the same PROFINET segment |
| Host OS | Windows 10 | Running VirtualBox 5.x |
| Guest OS | Windows 7 Professional SP1, 32-bit | TIA Portal V13 does not install on Windows 10 |
| Hypervisor | Oracle VM VirtualBox | Adapter 1 attached as "Bridged Adapter" |
| Substation IP plan | PLC 192.168.0.1, HMI 192.168.0.2, PC 192.168.0.100 | Subnet mask 255.255.255.0 |
| Legacy tool | SIMATIC Manager V5.5 SPx (also installed in the guest) | Shares the S7DOS helper with TIA Portal; see Edge Case 2 |
The SIMATIC S7-1200 CPU 1215C data sheet (6ES7215-1AG40-0XB0) confirms that the 1215C ships with two PROFINET interfaces (X1 and X2) and that the entire working memory is available for program use with no user-side restriction. The cloud-hosted Communications section of the S7-1200 CPU 1215C technical specifications lists the I-device and PROFIenergy capabilities relevant to PROFINET discovery on the X1/X2 ports.
Root Cause Analysis: Why "Device Not Compatible" Almost Never Means a Hardware Incompatibility
When TIA Portal performs hardware detection, it executes the following sequence over the PROFINET network:
- Sends a DCP (Discovery and Configuration Protocol) multicast over the configured network interface to locate all PROFINET devices. (UDP 34964, MAC 01-0E-CF-00-00-00.)
- Reads the device's "IM" data (Identification & Maintenance) and the device's GSD-equivalent module information via DCP identify.
- Compares the firmware/version vector reported by the live device against the catalog version embedded in the installed HSP (Hardware Support Package) for TIA Portal V13 SP8.
- If the catalog entry cannot be matched to the reported identity, TIA Portal returns "device not compatible" because it cannot guarantee that the offline hardware tree matches the online device state.
Any break at step 1 or step 2 is reported to the user as a compatibility error, even though the actual problem is on the wire. The following root causes are ranked by frequency in field reports:
| Rank | Root cause | Symptom | Diagnostic |
|---|---|---|---|
| 1 | Host OS assigned a dynamic IP outside the 192.168.0.x range; the bridged VM adapter inherits the host's routing; ARP/DCP multicast is dropped at the hypervisor switch. | "Accessible devices" works (uses a different broadcast domain on a VirtualBox internal pseudo-interface), but the actual TIA Portal project download fails. |
ipconfig /all on the host; check that the host IP is on the same subnet as the PLC. |
| 2 | Windows Firewall (host or guest) is blocking the S7Comm ports used by TIA Portal. | Discovery fails, download fails, accessible devices may still show entries due to DCP multicast passing before rule enforcement. | Disable firewall temporarily, re-test; check inbound rules for "S7DOS" and "SIMATIC TIA Portal". |
| 3 | VirtualBox "Bridged Adapter" attached to a Wi-Fi interface (rather than an Ethernet interface). Wi-Fi adapters on most VM implementations do not pass multicast frames cleanly, especially PROFINET DCP multicast. | Detection works sporadically; CPU not found on subsequent attempts. | Switch to a wired interface; enable "Promiscuous Mode" on the bridged adapter. |
| 4 | Multiple active network interfaces on the host confuse TIA Portal's "PG/PC Interface" selection. TIA binds to the wrong NIC. | Detection is sometimes empty, sometimes correct. | Open the Windows Control Panel "Set PG/PC Interface" and pin TIA Portal to S7ONLINE -> TCP/IP -> <NIC MAC>. |
| 5 | Antivirus or endpoint protection (Symantec, McAfee, Defender ATP, SentinelOne) injects an LSP/WFP into the socket chain and breaks TIA's ISO-on-TCP communication. | Same as #2 but isolated to security software. | Temporarily disable real-time protection; check vendor logs for blocked S7Dos.exe or S7epa.exe. |
| 6 | Simatic Manager V5.5 and TIA Portal V13 share the same S7DOS helper. If STEP 7 was opened first, it can hold the S7ONLINE access point exclusively. | First TIA Portal open fails; subsequent opens succeed. | Close STEP 7 first; or set the access point mode to "TCP/IP (auto)" in the PG/PC interface. |
| 7 | CPU firmware revision is newer than the highest HSP that V13 SP8 supports. V13 SP8 was last updated for S7-1200 FW V4.2; a V4.3 / V4.4 / V4.5 CPU is "incompatible" by catalog. | MAC discovered; firmware is rejected on inventory read. | Check the CPU's "Online > Diagnostics > Module Information" once the network is healthy. |
| 8 | Npcap / WinPcap / Wireshark installation has captured the network adapter exclusively, preventing TIA from binding to it. | TIA errors with "Interface in use" or "Cannot bind to TCP/IP". | Uninstall Npcap temporarily; reboot. |
The original case resolved the issue by changing the host OS to a static IP and disabling the host's firewall. The remaining sections reconstruct the corrective procedure in the order a Siemens support engineer would apply it.
Topology Snapshot for the Recovery Procedure
Pre-Flight Checklist Before You Start
Capture the following before changing any settings. This is the minimum dataset required to perform a structured recovery and to re-validate the network after each change.
- Open an elevated
cmd.exeon the host and runipconfig /all > C:\pre_host.txt. - Open an elevated
cmd.exeon the guest and runipconfig /all > C:\pre_guest.txt. - Run
Get-NetFirewallProfile | Format-Table Name, Enabledin PowerShell on both host and guest; export topre_fw.txt. - Run
Get-NetAdapter | Format-Table Name, Status, LinkSpeed, MacAddressto enumerate all host NICs; export topre_nic.txt. - In VirtualBox: VM > Settings > Network > Adapter 1; note the attached interface name (e.g., "Intel(R) Ethernet Connection I219-V") and the "Promiscuous Mode" setting.
- On the S7-1215C front panel, write down the MAC address, the order number (MLFB), and the firmware version visible on the display (or via "Online > Accessible devices" if available).
- Capture a screenshot of TIA Portal's Online > Accessible devices window showing the discovered devices, the Set PG/PC Interface dialog, and the TIA Portal Help > About dialog (which shows the exact build number of V13 SP8 and installed HSPs).
Step-by-Step Resolution
Step 1: Set Static IP Addressing on Host and Guest
The most common fault in a VirtualBox bridged setup is the host's DHCP client handing the host a different IP than the one the guest expects to share. TIA Portal sends PROFINET DCP multicast on the guest's bridged interface; the frames are bridged to the host's NIC and exit onto the wire. If the host's IP is not on 192.168.0.x, the CPU will respond to the ARP request for 192.168.0.100 from a host whose primary address is, e.g., 192.168.1.42, and the response gets mis-routed back to the VirtualBox pseudo-interface instead of the real Ethernet port.
Configure the host's Ethernet adapter with a static address on the PLC's subnet:
- Control Panel > Network and Sharing Center > Change adapter settings.
- Right-click the wired Ethernet adapter > Properties > Internet Protocol Version 4 (TCP/IPv4) > Properties.
- Select "Use the following IP address" and enter:
- IP address:
192.168.0.100 - Subnet mask:
255.255.255.0 - Default gateway: leave blank (no router in the engineering network)
- IP address:
- Preferred DNS:
127.0.0.1or empty (engineering networks should not have DNS).
Configure the guest (Windows 7) identically:
- Inside the VM, open
ncpa.cpl. - Right-click "Local Area Connection" (the bridged adapter as seen by Windows 7) > Properties > IPv4.
- Set IP
192.168.0.101, mask255.255.255.0, no gateway.
Step 2: Configure VirtualBox Bridged Networking Correctly
VirtualBox bridged mode binds the guest's virtual NIC to a host physical NIC. The following settings are recommended for TIA Portal traffic:
- Shut down the VM.
- VM > Settings > Network > Adapter 1.
- Attached to: Bridged Adapter.
- Name: select the wired Ethernet adapter (e.g., "Intel(R) Ethernet Connection"). Do not select a Wi-Fi adapter. PROFINET multicast on Wi-Fi is unreliable in VirtualBox 5.x and 6.x.
- Adapter Type: Intel PRO/1000 MT Desktop (82540EM). This is the default and is the only adapter type for which Siemens officially documents PROFINET discovery behaviour.
- Promiscuous Mode: Allow All. Without this, the guest's NIC will not accept frames addressed to the host's MAC, and PROFINET DCP responses to the host's IP will be silently dropped.
- Cable Connected: tick.
After saving, boot the VM. From the guest, run ping 192.168.0.1. If the CPU is reachable, the IP layer is good. If not, check the VirtualBox log (VBox.log in the VM directory) for "no link" or "carrier lost" messages — these indicate a bad NIC selection in step 3 above.
Step 3: Disable or Properly Configure the Windows Firewall
TIA Portal V13 SP8 uses several TCP and UDP endpoints for S7 communication. The exact list is documented in the Siemens Security Settings Manual, but the practical rule during commissioning is to allow all traffic on the engineering subnet for the duration of the work.
Option A (fastest): disable firewall on both host and guest.
- On the host, run PowerShell as admin:
Set-NetFirewallProfile -Profile Domain, Public, Private -Enabled False. - Reboot the host to clear any rules still applied through WFP.
- On the guest (Windows 7), run
netsh advfirewall set allprofiles state offfrom an elevatedcmd. - Reboot the guest.
Option B (production-correct): create inbound rules.
- Open
wf.mscon the host. - Inbound Rules > New Rule > Port > TCP > Specific local ports:
102, 161, 34964, 49152, 49153, 49154, 49155. - Allow the connection, apply to Domain/Private/Public, name "TIA Portal S7Comm".
- Repeat for UDP, local ports
161, 34964, 49152-49155. - Allow the executable
"C:\Program Files\Siemens\Automation\Portal V13\bin\s7epa.exe"and"C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7dos.exe"for all profiles.
Step 4: Verify TIA Portal V13 SP8 Supports Your Firmware
TIA Portal V13 SP8 is the terminal release of the V13 line. Its bundled HSPs support S7-1200 firmware V4.0, V4.1, and V4.2. Newer S7-1200 CPUs shipped in 2018 or later (e.g., 6ES7215-1AG40-0XB0 with firmware V4.4 or V4.5) require TIA Portal V15.1 or later. A V13 SP8 TIA Portal cannot be patched upward; the only path to a newer firmware support set is a new TIA Portal major version install on a newer OS image.
To determine the firmware of your CPU once the network is healthy:
- In TIA Portal: Online > Accessible devices > select the S7-1215C > Online > Diagnostics.
- Navigate to Module Information > Identification.
- Record the "Firmware" field.
If the firmware is V4.3 or later, you must upgrade TIA Portal to V15.1, V16, V17, or V18 to maintain compatibility. A downgrade of the CPU firmware is not generally possible for S7-1200 once V4.2 has been replaced by a newer factory image; the loader refuses older signed firmware images.
Step 5: Reset the S7-1200 to Factory Defaults
Sometimes the S7-1215C is shipped with a stale IP, a leftover PROFINET name, or a partially downloaded project that prevents a clean initial detection. The recommended procedure is the front-panel button sequence:
- Power off the CPU.
- Hold the "RESET" button on the front panel.
- Apply power while holding the button; wait until the LEDs cycle once.
- Release the button. The CPU will be in factory-default state: IP 0.0.0.0, no PROFINET name, all outputs off, all timers/counters cleared, program memory empty.
Alternatively, once TIA Portal can communicate, use Online > Reset to factory settings from the device context menu. This requires the CPU to be in STOP mode.
Step 6: Add the Device Manually Before Going Online
If hardware detection still fails after the network is verified, the safe engineering workflow is to add the CPU manually from the hardware catalog. This avoids the Detect path entirely and lets you build the configuration offline first, then go online only for the download.
- Project view > Project tree > Add new device.
- Select CPU > SIMATIC S7-1200 CPU > CPU 1215C DC/DC/DC > 6ES7215-1AG40-0XB0 with firmware V4.2.
- Click Add.
- Configure the PROFINET interface X1: IP 192.168.0.1, subnet 255.255.255.0, PROFINET device name "plc1".
- Drag the KTP700 from the catalog to the PROFINET subnet and assign it to the PLC as an HMI connection.
- Compile and download. The download is more reliable than the detection path because it does not require PROFINET DCP — it uses the assigned IP and S7Comm directly.
TIA Portal V13 SP8 Specific Considerations
V13 SP8 is the cumulative service pack delivered for the V13 line. It must be distinguished from V13 SP1 and V13 SP2 because each service pack added incremental HSP support:
| Portal version | HSP support for S7-1200 | Released (approx.) | Notes |
|---|---|---|---|
| TIA Portal V13 | S7-1200 FW V4.0 | 2014 | Original release |
| TIA Portal V13 SP1 | S7-1200 FW V4.1 | 2015 | Added S7-1500 firmware updates |
| TIA Portal V13 SP2 | S7-1200 FW V4.2 | 2016 | Added 1215C FW V4.2 support |
| TIA Portal V13 SP8 | S7-1200 FW V4.2 (cumulative) | 2016 | Same FW support as SP2 plus bug fixes |
| TIA Portal V14 SP1 | S7-1200 FW V4.3 | 2017 | Required for ET 200SP FW 6.0+ |
| TIA Portal V15.1 | S7-1200 FW V4.4 / V4.5 | 2018 | Required for S7-1200 G2 transition products |
A new S7-1215C purchased today ships with firmware V4.4 or later on the 6ES7215-1AG40-0XB0 base unit. If the firmware on your CPU's display is V4.3 or higher, TIA Portal V13 SP8 will report "device not compatible" even on a perfect network. In that case the only fix is to migrate to TIA Portal V15.1 or newer. There is no firmware downgrade path for the S7-1200 product line; firmware is signed by Siemens and the loader refuses older images.
S7-1215C Hardware Reference
The S7-1215C (6ES7215-1AG40-0XB0) is the highest-memory compact CPU in the S7-1200 family. For a quick commissioning reference, the following are the key technical data points extracted from the official Siemens data sheet:
| Parameter | Value (6ES7215-1AG40-0XB0) |
|---|---|
| Work memory (program + data combined) | 125 KB, fully usable |
| Bit memory (M) | 8 KB (8192 bits) |
| Integrated digital inputs | 14 (24 V DC, IEC type 1 sink/source) |
| Integrated digital outputs | 10 (24 V DC, 0.5 A, transistor) |
| Integrated analog inputs | 2 (0-10 V / 0-20 mA, 10-bit) |
| Integrated analog outputs | 2 (0-20 mA, 10-bit) |
| High-speed counters | 6 (up to 1 MHz on dedicated inputs) |
| PROFINET ports | 2 (X1: switch / IO controller, X2: switch) |
| Max PROFINET IO devices (controller mode) | 16 |
| Max PROFINET IO controllers (I-device mode) | 3 |
| Ethernet services supported | PROFINET IO, PROFIenergy, S7Comm (ISO-on-TCP), Modbus TCP, TCP/IP open user comms, UDP, Web server (HTTPS via S7-1200 FW V4.x) |
| Real-time clock retention | 20 days (typical), capacitor backed |
| Programming languages | LAD, FBD, SCL, GRAPH (V14+) |
Both PROFINET ports are functionally identical managed Ethernet switches — devices can be daisy-chained off port X2 without an external switch. In the original failure scenario, the KTP700 was likely connected to X2, and the engineering PC to X1, in a line topology. The bridged VirtualBox adapter must bridge to the same physical NIC that the line topology is wired to, or the multicast DCP frames will be lost on the wire.
Verification Procedure
After applying the corrective steps, perform the following verification sequence. The checks are designed to fail at the earliest possible point so that the root cause can be re-isolated quickly if a regression occurs.
- Layer-1 verify: The CPU and HMI are powered; the LINK LEDs on the X1 and X2 ports are green; the Ethernet port LEDs on the PC NIC are green and blinking with traffic.
-
Layer-2 verify (ping): From the guest,
ping 192.168.0.1 -tshould return 4 ms or less with no loss. -
ARP verify: From the guest,
arp -ashould show the S7-1215C's MAC address associated with 192.168.0.1. - DCP verify: In TIA Portal, Online > Accessible devices > "Flash LED" on the S7-1215C entry. The CPU's RUN/STOP, ERROR, and MAINT LEDs should blink at 2 Hz for 3 seconds.
- Online diagnostics: Online > Accessible devices > right-click the S7-1215C > Online > Diagnostics. The Module Information dialog should appear with the firmware version and serial number populated.
- Hardware detection: Project view > create a new project with an Unspecified CPU 1200 > double-click Device > Detect. The status bar should report "Detection successful" and the S7-1215C entry should be placed in Device View with the correct article number, firmware, and PROFINET port configuration.
- Compile and download: Compile the (empty) project and download. The online status icon should turn green on all configured devices.
- HMI connection: The KTP700 should display the project's start screen within 30 seconds of the PLC going to RUN.
Related Issues and Edge Cases
Edge Case 1: VirtualBox Wi-Fi Bridged Mode
Some laptops have only Wi-Fi connectivity at the engineering site. VirtualBox bridged mode to a Wi-Fi adapter works for TCP traffic but drops a significant fraction of PROFINET DCP multicast frames. Symptoms: DCP discovery lists the CPU, but the second click on the device yields "no response" or "device not compatible". Fix: use a USB-to-Ethernet adapter as a wired bridge, and select that adapter in the VirtualBox bridged configuration.
Edge Case 2: Multiple TIA Portal / STEP 7 Versions on the Same VM
STEP 7 V5.5 and TIA Portal V13 use the same S7DOS helper and the same S7ONLINE access point. If STEP 7 V5.5 was opened before TIA Portal V13, S7DOS may still hold an exclusive lock on the access point. Symptoms: TIA Portal reports "Cannot bind to access point" or "Device incompatible" intermittently. Fix: close STEP 7 first; in the Set PG/PC Interface dialog, set the access point to "TCP/IP (auto)" instead of "TCP/IP <MAC>".
Edge Case 3: VirtualBox "Paravirtualized Network (virtio-net)" Adapter
The default adapter type in newer VirtualBox versions is "Paravirtualized Network (virtio-net)". This is faster but does not pass multicast frames consistently to the guest. TIA Portal V13 SP8 was tested on the "Intel PRO/1000 MT Desktop" type. Symptoms: TCP works (you can ping the PLC), but DCP discovery returns no devices. Fix: change the adapter type to "Intel PRO/1000 MT Desktop (82540EM)" and reboot the VM.
Edge Case 4: Kaspersky / Symantec / Trend Micro Endpoint Security
Several endpoint security products inject a Windows Filtering Platform (WFP) callout driver that intercepts ISO-on-TCP traffic. TIA Portal uses ISO-on-TCP port 102 for S7Comm. Symptom: ping works; the Online > Accessible devices dialog briefly shows the CPU; download hangs and times out. Fix: add the TIA Portal executable directory to the security product's exclusion list. The Siemens Security Settings Manual lists the exact list of executables that must be excluded.
Edge Case 5: CPU Firmware Newer Than TIA Portal V13 SP8 Supports
As noted in Step 4 above, a new S7-1215C with firmware V4.3 or later cannot be configured with TIA Portal V13 SP8. This is a true compatibility error, not a network error. The fix is to upgrade TIA Portal. If upgrading is not possible, contact Siemens Industry Online Support to request a firmware downgrade (only available for warranty-replacement units, not for field units).
Edge Case 6: VMware Workstation Pro as the Hypervisor
Siemens officially documents VMware Workstation Pro as a supported TIA Portal hypervisor, with explicit support notes for the VMnet bridged networking mode. If VirtualBox continues to be problematic after all the above steps, the cleanest fix is to recreate the same Win7 SP1 guest in VMware Workstation Pro using the same bridged configuration. The TIA Portal installation is otherwise identical, and PROFINET discovery over VMware is more reliable than over VirtualBox for multicast traffic.
Edge Case 7: S7-1200 Webserver HTTPS Certificate Conflicts
Starting with firmware V4.0, the S7-1200 web server ships with a self-signed certificate. Some anti-virus products with TLS inspection will intercept the HTTPS connection on port 443. Symptom: TIA Portal reports "device not compatible" if the Webserver-based inventory path is used. Fix: disable TLS inspection for the S7-1200 IP range; or use HTTP-only firmware versions (V3.x).
Security Advisory Reference
The S7-1200 family is part of the Siemens product line tracked under CISA ICS Advisory ICSA-25-044-01. The advisory references multiple S7-1200 vulnerabilities (e.g., authentication bypass, web server XSS). When commissioning a 1215C on a production network, verify that the firmware level installed in the field matches the patch level recommended by Siemens ProductCERT and is consistent with the facility's security baseline. CISA has stated that, as of January 10, 2023, it no longer updates these advisories for Siemens; cross-reference the latest Siemens ProductCERT Security Advisory page for active advisories and patch notes.
FAQ
What does the "device not compatible" error in TIA Portal V13 SP8 actually mean?
It is TIA Portal's compatibility check between the hardware catalog entry and the firmware the CPU reports over PROFINET DCP. In a VirtualBox environment, the message almost always reflects a network problem that prevented the firmware inventory read, not a real incompatibility. Fix the network first, then re-evaluate the firmware.
Which S7-1200 firmware versions does TIA Portal V13 SP8 support?
TIA Portal V13 SP8 supports S7-1200 firmware V4.0, V4.1, and V4.2. It does not support firmware V4.3, V4.4, or V4.5. Newer S7-1215C CPUs shipping from late 2017 onward are typically V4.4 or higher; these require TIA Portal V15.1 or later.
Can I use VirtualBox for TIA Portal V13 with an S7-1200?
Yes, but with caveats. Use a bridged adapter to a wired Ethernet NIC, not Wi-Fi. Set the adapter type to "Intel PRO/1000 MT Desktop". Set the host OS to a static IP on the PLC's subnet. Disable Windows Firewall on both host and guest during commissioning, or add explicit TIA Portal rules. Siemens officially documents and supports VMware Workstation Pro for TIA Portal virtualized engineering; VirtualBox works but is not in the supported matrix.
My S7-1215C shows up under "Accessible devices" but the IP is 0.0.0.0. What should I do?
An out-of-the-box S7-1215C ships with IP 0.0.0.0 and no PROFINET name. Assign an IP and a PROFINET name from the Online > Accessible devices dialog (right-click > "Assign PROFINET device name" and "Assign IP address"). Once assigned, run Online > Diagnostics to verify the firmware version before attempting hardware detection.
How do I reset the S7-1215C to factory defaults?
Power off the CPU, hold the RESET button on the front panel, apply power, wait for the LED test cycle, and release. The CPU returns to IP 0.0.0.0, no PROFINET name, empty program. From TIA Portal, use Online > Reset to factory settings if the CPU is in STOP.
Does TIA Portal V13 SP8 run on Windows 10?
No. TIA Portal V13 officially supports Windows 7 (32/64-bit) and Windows Server 2008 R2. Running V13 inside a Windows 7 guest on a Windows 10 host is the standard workaround. For direct Windows 10 installation, upgrade to TIA Portal V15.1 or later.