Resolving S7-PLCSIM V17 HMI Simulation Errors on S7-1200

David Krause15 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving S7-PLCSIM V17 HMI Simulation Errors on S7-1200

When a SIMATIC S7-1200 program compiles and downloads cleanly into S7-PLCSIM V17, but the HMI portion of the same TIA Portal project refuses to start, returns a download error, or produces an "unauthorized" / "connection interrupted" dialog, the fault almost always sits at the boundary between two distinct simulators: PLCSIM for the controller and WinCC Runtime for the HMI. This reference walks through the full diagnostic and resolution path, including the controller/HMI separation, license/elevation requirements of TIA Portal V17, PG/PC interface selection, PN/IE connection routing, and the differences between S7-PLCSIM and S7-PLCSIM Advanced when bringing an S7-1200 HMI panel online without physical hardware.

1. Problem Definition and Symptom Set

The reported failure mode for an S7-1200 / TIA Portal V17 / S7-PLCSIM V17 workstation is consistent and repeatable:

  • The S7-1200 PLC program downloads successfully into the PLCSIM instance and runs in Run/Run-P.
  • The HMI configuration (e.g., KTP700 Basic, TP900 Comfort, or WinCC Runtime Advanced/Professional) either fails to compile, fails to download, or pops a dialog stating that the target device is unreachable / unauthorized / already in use.
  • A second PLCSIM instance is sometimes auto-spawned when the HMI is started, which can also fail with the same family of errors.
  • Error codes frequently observed: 33:0:207, "Connection to target system failed", "HMI device is not reachable", or a WinCC dialog "The HMI Runtime has been terminated unexpectedly".

Because the user can see a real S7-PLCSIM instance running in the system tray, the assumption is that the HMI should be able to attach to it. That assumption is the root of the issue: in TIA Portal V17 with PLCSIM, the PLC simulator and the HMI simulator are two independent processes that must be connected by an explicit S7 connection, not by an implicit link.

2. Root Cause Analysis

There are five distinct root-cause families that produce the symptom above. Each must be ruled out before assuming a TIA Portal bug.

2.1 Mistaking "Download to HMI" for "Start HMI Runtime Simulation"

In TIA Portal, the HMI device editor exposes two completely separate actions:

  • Download to HMI device — pushes the compiled HMI project into a physical panel or a real runtime station. This action fails while PLCSIM is active on the same PN/IE interface if the HMI is also configured against PLCSIM, because the download path attempts to reach a non-existent target.
  • Start Runtime (or "Start simulation") — launches the WinCC Runtime simulator on the engineering PC. This is the path required for HMI-only simulation against PLCSIM.

If the HMI configuration is set to a physical panel and the user clicks "Download", the error dialog is the correct response: the panel is not on the network. The fix is to switch the HMI to its simulator or to use the Runtime start path.

2.2 Missing HMI Simulation Add-On / License

WinCC Runtime simulation in TIA Portal V17 requires the corresponding simulation add-on for the HMI flavor in use:

  • WinCC Basic (KTP/Basic panels) — RT Simulator included with TIA Portal but must be installed as a feature.
  • WinCC Comfort/Advanced — RT Advanced Simulator package.
  • WinCC Professional/ES — RT Professional Simulator (typically a separate install).

Without the matching simulator package installed, the "Start Runtime" menu entry is greyed out, or the runtime aborts immediately with a license fault.

2.3 PLCSIM vs. PLCSIM Advanced Selection

S7-PLCSIM (the version bundled with STEP 7 Basic / TIA Portal) supports the S7-1200 family but historically uses a different communication path than the full S7-PLCSIM Advanced runtime, which speaks TCP/UDP via the Softbus. If the HMI's HMI connection is typed as "SIMATIC S7-1500" with PLCSIM Advanced, but only the bundled PLCSIM V17 is installed, the HMI times out trying to reach the Softbus endpoint.

Conversely, on S7-1200 targets, only the bundled PLCSIM is valid. PLCSIM Advanced does not support S7-1200 — it is restricted to S7-1500, ET 200SP CPU, and a limited set of S7-1500 software controllers. Trying to simulate an S7-1200 against PLCSIM Advanced will return a "device type not supported" dialog.

2.4 PG/PC Interface and Subnet Routing

Both PLCSIM and the WinCC Runtime Simulator attach to a virtual subnet. The HMI connection in the project tree must reference the same subnet as the S7-1200 device, and the PG/PC interface assigned to that subnet must point at "PLCSIM" or "S7PLCSIM". If the connection is set to the physical Ethernet adapter, the runtime will not find the simulated CPU.

2.5 Elevation / User Account Control

TIA Portal V17 plus PLCSIM and the HMI Runtime Simulator all expect to be launched with the same elevation level. If PLCSIM was started elevated (Run as administrator) but TIA Portal was started normally (or vice versa), the Softbus / RPC bridge between the two cannot cross the integrity boundary and the HMI returns "connection failed". The same applies if TIA Portal was installed as a non-elevated user and PLCSIM was started elevated: the simulator service handshake is broken.

3. Prerequisites and Environment Check

Before attempting the fix, validate the following. Each is a hard prerequisite for V17 HMI/PLCSIM co-simulation on S7-1200.

Item Required How to Verify
TIA Portal V17 (STEP 7 Basic V17 + WinCC Basic V17, or STEP 7 Professional V17 + WinCC Professional V17) Yes Help > About > Show Installed Software
S7-PLCSIM V17 (bundled) Yes for S7-1200 Start > Siemens Automation > SIMATIC > S7-PLCSIM
WinCC Runtime Simulator matching HMI flavor Yes Start > Siemens Automation > SIMATIC > WinCC > Runtime Simulator
Windows user in local Administrators group Yes Control Panel > User Accounts > Manage User Accounts
Same elevation (UAC) for PLCSIM and TIA Portal Yes Both started with "Run as administrator", or both started normally
PLCSIM instance active and in RUN/Run-P Yes PLCSIM main window shows green RUN LED
PG/PC interface set to PLCSIM for the project's subnet Yes Control Panel > Set PG/PC Interface
Note: Mixing elevated and non-elevated sessions is the single most common cause of "connection interrupted" dialogs that list an error code starting with 0xFFFE or 33:0:207 on a fully licensed, fully installed TIA Portal V17 station.

4. Step-by-Step Resolution

Follow this sequence in order. Do not skip steps — each one rules out a root cause and the verification command at the end of each step is the gate to the next.

Step 1 — Confirm the S7-1200 simulation is alive

  1. Open TIA Portal V17 and the project containing the S7-1200 station.
  2. Select the S7-1200 device, right-click, choose Start simulation.
  3. Wait for the PLCSIM instance to open and report RUN.
  4. From the project tree, open Online > Online & diagnostics on the S7-1200 and confirm Operating mode: RUN.

Verification: If the S7-1200 is not in RUN, fix that first. The HMI cannot attach to a stopped simulated CPU.

Step 2 — Switch the HMI from "Download" to "Start Runtime"

  1. In the project tree, right-click the HMI device (e.g., KTP700 Basic, TP1200 Comfort, or the WinCC Runtime Advanced PC station).
  2. Choose Start runtime — not "Download to device".
  3. If "Start runtime" is greyed out, the matching WinCC Runtime Simulator package is not installed. Close TIA Portal, run the TIA Portal V17 installer in modify mode, and add the appropriate simulator feature.

Verification: The WinCC Runtime Simulator window opens and shows the configured HMI screens. If the simulator crashes immediately, check the Windows Event Viewer > Application log for "WinCC" or "RTsim" sources.

Step 3 — Verify the HMI-to-PLC connection is an S7 connection on the same subnet

  1. Open the HMI device > Connections editor.
  2. Confirm the connection to the S7-1200 has Type: S7 connection, not PROFINET I/O or OPC UA.
  3. Confirm the Station field points at the S7-1200 PLC station, and the Subnet field matches the S7-1200 device's PN/IE_1 subnet name.
  4. Open the S7-1200 device > Properties > PROFINET interface [X1] > Ethernet addresses and note the IP. The HMI connection's partner IP must match.

Verification: Right-click the HMI connection and choose Check consistency. TIA Portal reports an error if the partner does not exist on the named subnet.

Step 4 — Assign the PLCSIM PG/PC interface

  1. Close TIA Portal.
  2. Open the Windows Control Panel > Set PG/PC Interface (the Siemens shortcut, not the Windows network settings).
  3. For the access point S7ONLINE, select the entry named PLCSIM or S7PLCSIM.S7DOS.1. Click OK.
  4. Reopen TIA Portal and reload the project.

Verification: In TIA Portal > Online > Accessible nodes, the simulated S7-1200 appears in the list. If it does not, the interface is wrong.

Step 5 — Align UAC elevation

  1. Close TIA Portal and PLCSIM completely.
  2. Right-click the TIA Portal shortcut and choose Run as administrator (or do the same for the standard user if you are signed in as a non-admin and have credentials).
  3. From within the elevated TIA Portal, start the simulation. PLCSIM and the HMI Runtime will inherit the same elevation.

Verification: The HMI Runtime Simulator starts without a connection dialog, and the live tags from the S7-1200 begin updating on the screen.

Step 6 — Reinstall only if the steps above fail

If after steps 1–5 the error persists, capture the exact dialog text and the contents of %ProgramData%\Siemens\Automation\PLCSIM\Logs and %TEMP%\Siemens\WinCC\RTLogs. Submit a Support Request through the Siemens Industry Online Support portal with the project archive and logs attached. Do not attempt a clean reinstall until Siemens confirms the behavior, as the source data is needed for them to reproduce the fault.

5. S7-PLCSIM vs. S7-PLCSIM Advanced — When to Use Which

For an S7-1200, the choice is forced: S7-PLCSIM Advanced does not support the S7-1200 family. But the HMI flavor and the HMI connection type change which PLCSIM path works. Use the table below to confirm that the project is wired to a supported combination.

Controller PLCSIM Variant HMI Flavor HMI Connection Type Supported
S7-1200 S7-PLCSIM V17 (bundled) WinCC Basic / Comfort / Advanced S7 connection Yes
S7-1200 S7-PLCSIM Advanced Any Any No — device not supported
S7-1500 S7-PLCSIM V17 (bundled) WinCC Comfort / Advanced / Professional S7 connection Yes
S7-1500 S7-PLCSIM Advanced WinCC Professional / ES S7 connection or Softbus Yes (preferred for large OPs)
ET 200SP CPU S7-PLCSIM Advanced WinCC Professional S7 connection Yes
Note: If the project will be migrated to S7-1500 in the future, plan the HMI connection now as a vanilla S7 connection with no gateway, because S7-PLCSIM Advanced requires the Softbus transport that is only available on S7-1500 class controllers.

6. HMI Runtime Simulation Workflow on the S7-1200

The correct flow for an S7-1200 HMI test in TIA Portal V17 is shown in the sequence diagram below.

TIA Portal V17 S7-PLCSIM V17 WinCC RT Simulator Start PLC sim Start RT S7-1200 program Simulated CPU (RUN) HMI screens live Load via PLCSIM S7 connection (PN/IE subnet) (via S7ONLINE = PLCSIM)

The dashed S7 connection between the simulated CPU and the WinCC Runtime Simulator is what users frequently forget to establish. The HMI's connection editor must point at the S7-1200 station, and the project must be compiled with that connection intact before the Runtime is started.

7. Connection Configuration Reference

The HMI connection in TIA Portal V17 is a property block on the HMI device. The minimum fields to populate for PLCSIM co-simulation on S7-1200 are shown in the table below.

Field Value Notes
Name HMI_Connection_1 (or user choice) Project-local
Type S7 connection Not PROFINET, not OPC UA
Station PLC_1 (the S7-1200) Must resolve in project tree
Slot 1 S7-1200 CPU slot
Connection resource OP connection (default) Auto-assigned
Subnet PN/IE_1 Must match the PLC's PROFINET subnet
Partner IP 192.168.0.1 (example) Matches PLC IP
TSAP (local / partner) 03.01 / 03.01 Default for S7-1200 OP connections
TSAP reminder: For an HMI-to-S7-1200 OP connection, the local TSAP is normally 03.01 (rack 0, slot 1) and the partner TSAP is 03.01 as well. Modifying TSAPs without a documented reason is a common cause of "connection refused" dialogs that report no further detail.

8. Common Error Codes and Their Meanings

Error / Code Likely Cause Fix
33:0:207 / "Connection to target system failed" PLCSIM not running, or PG/PC interface set to physical NIC Start PLCSIM; set S7ONLINE to PLCSIM
"The HMI device is not reachable" Wrong HMI connection target or HMI connection uses real panel IP Repoint HMI connection to PLC station; rebuild HMI
"HMI Runtime has been terminated unexpectedly" WinCC RT Simulator package missing or wrong flavor Run TIA Portal installer in modify mode, add matching RT Simulator
"Unauthorized / license missing" WinCC RT Simulator license or floating license not present on this PC License the package via Automation License Manager
"PLCSIM does not support this device type" PLCSIM Advanced selected for S7-1200 Use bundled S7-PLCSIM V17 for S7-1200
Popup with no detail on HMI "Download" Clicking "Download to HMI" against a non-existent physical target Use "Start runtime" instead, or set HMI to its simulator

9. Verification Checklist

After completing the resolution, run the full verification set below. All items must pass before signing off the simulation environment.

  1. PLCSIM V17 is running with the S7-1200 visible and showing RUN or RUN-P.
  2. From TIA Portal > Online > Accessible nodes, the simulated S7-1200 appears under the PLCSIM interface.
  3. The HMI device > Connections editor passes "Check consistency" with no errors.
  4. "Start runtime" on the HMI opens the WinCC Runtime Simulator within 5 seconds and shows the configured start screen.
  5. Toggle a tag in the S7-1200 (set a marker M0.0 = TRUE) and confirm the HMI value changes within the configured polling cycle (default 1 s).
  6. Stop the simulation cleanly: TIA Portal > Online > Stop simulation. Both PLCSIM and the WinCC Runtime close.
  7. Re-run the simulation. The HMI comes back up automatically against the same PLCSIM instance — this confirms the connection settings are persisted, not transient.

10. Field-Commissioning Notes and Edge Cases

Antivirus and endpoint protection. Some endpoint security suites (CrowdStrike, SentinelOne, Defender with strict ASR rules) block the Softbus / local RPC channels used by PLCSIM and the WinCC Runtime Simulator. If the HMI returns "connection failed" immediately on an otherwise correct configuration, add the Siemens installation directory and the %ProgramData%\Siemens tree to the AV exclusion list. The behavior is identical to a UAC elevation mismatch.

Multiple PLCSIM instances. V17 allows multiple PLCSIM instances for S7-1500 only. For S7-1200 there is exactly one PLCSIM instance. If the HMI is configured against a second instance, the first instance will not be the connection target.

Project migration from V16 to V17. After upgrading a TIA Portal project from V16 to V17, recompile both the PLC and the HMI before launching the simulation. Stale compiled HMI binaries sometimes survive an upgrade and report a phantom connection target.

Using a real panel alongside PLCSIM. If a physical KTP panel is on the desk and a PLCSIM instance is also active, the panel's connection will be ambiguous. Disable the HMI tag connection to the physical panel during simulation, or run the simulation on a separate engineering station that is not bridged to the panel's subnet.

ProTool/WinCC Flexible legacy projects. PLCSIM V17 does not support WinCC Flexible Runtime simulation. Migrate the legacy HMI project to a TIA Portal HMI device before attempting the co-simulation.

11. When to Escalate to Siemens Support

Escalate to Siemens via the Support Request link in the Global Support portal if any of the following hold after completing steps 1–5 above:

  • The exact same TIA Portal project runs the HMI against a physical S7-1200 but fails only against PLCSIM.
  • The PLCSIM log file at %ProgramData%\Siemens\Automation\PLCSIM\Logs shows an unhandled exception or a hex error code starting with 0x8007, 0x8009, or 0xC000.
  • Reinstalling the TIA Portal V17 packages (modify mode) does not restore the "Start runtime" entry on the HMI device context menu.
  • Multiple engineering PCs on the same site exhibit the identical symptom, indicating a license server, group policy, or image issue rather than a local install problem.

Include the project archive (TIA Portal > Project > Archive), the PLCSIM log directory, and the WinCC RT log directory when filing the support request.

12. Summary

S7-PLCSIM V17 simulates the S7-1200 CPU. The WinCC Runtime Simulator simulates the HMI. The two must be wired together by an explicit S7 connection on a shared PROFINET subnet, and both must be launched at the same UAC elevation, on a workstation with the matching WinCC Runtime Simulator package installed, and with the S7ONLINE access point set to the PLCSIM interface. S7-PLCSIM Advanced is not a valid alternative for S7-1200 and will return a "device not supported" condition. Once the connection is in place and the elevation is aligned, the standard "Start runtime" path on the HMI device replaces the failing "Download to HMI" path and the simulated panel comes online in seconds.

Why does clicking "Download to HMI" fail when S7-PLCSIM V17 is already running?

"Download to HMI" targets a physical panel or runtime station and is not the correct action for HMI simulation. Use "Start runtime" on the HMI device in TIA Portal V17, and confirm the WinCC Runtime Simulator package for the HMI flavor is installed.

Can I use S7-PLCSIM Advanced with an S7-1200 HMI project?

No. S7-PLCSIM Advanced supports S7-1500, ET 200SP CPU, and a limited set of S7-1500 software controllers only. For S7-1200, use the bundled S7-PLCSIM V17 included with STEP 7 Basic / Professional V17.

Which PG/PC interface should be assigned to S7ONLINE for PLCSIM co-simulation?

Set S7ONLINE to the PLCSIM access point (typically listed as "PLCSIM" or "S7PLCSIM.S7DOS.1") in the Windows "Set PG/PC Interface" tool, not the physical Ethernet adapter. The simulated CPU must be reachable through this virtual interface.

What causes the "HMI Runtime has been terminated unexpectedly" dialog?

It usually means the matching WinCC Runtime Simulator package is missing, the license is not present, or TIA Portal and PLCSIM are running at different UAC elevation levels. Reinstall the matching simulator via the TIA Portal V17 modify mode, license it through the Automation License Manager, and start both TIA Portal and PLCSIM at the same elevation.

Do I need a license for the WinCC Runtime Simulator?

Yes. Each WinCC flavor's runtime simulator requires its own license, typically delivered through the Automation License Manager. Without a valid license, the runtime starts in a degraded mode and the HMI shows a license violation dialog instead of the project screens.

Back to blog