Problem Overview
Field reports describe the following sequence on TIA Portal V20 cells that combine a SIMATIC Unified Comfort Panel (UCP) with an S7-1500 CPU. The cell is commissioned, time is set on both devices, and the line runs for weeks or months without issue. After an extended shutdown (operators regularly see the fault after one month of power-down; the panel's capacitor backup is rated for approximately six weeks), the panel is re-energized and immediately shows a corrupted or default date and time. Within minutes, the WinCC Unified runtime logs show secure-communication failures: TLS handshakes abort, certificate validation rejects the panel, and writes from the HMI to the PLC are blocked.
Until the clock is set again, either manually on the panel or by an NTP poll that succeeds, the HMI is effectively blind to the PLC. Some plant operators do not notice until the next shift, because the system logs the error rather than raising an alarm. Others see the panel freeze at the connection screen or display a generic connection-interrupted banner.
Affected Hardware and Software
| Component | Description | Notes |
|---|---|---|
| HMI - Unified Comfort Panel | SIMATIC HMI MTP700 / MTP1000 / MTP1200 / MTP1500 / MTP1900 / MTP2200 Unified Comfort, and TP Unified variants | No internal RTC battery; capacitor-backed retentive RTC, typical retention 6 weeks |
| PLC | SIMATIC S7-1500 / S7-1500F / ET 200SP CPU (firmware V2.5 and later recommended for LSNTP) | Acts as controller, time master, or NTP server |
| Engineering | TIA Portal V20 with WinCC Unified V20 and STEP 7 V20 | Single project for PLC and HMI configuration |
| Bootloader | UCP bootloader firmware | Pre-fix revisions contained an RTC corruption bug; corrected per SIOS entry 109973587 |
| Communication library | Libraries for Communication for SIMATIC Controllers (LSNTP block) | Used to publish the PLC's time as NTP service |
| Time-sync documentation | TIA Portal V20 help - WinCC Unified - Basics of time synchronization (RT Unified) | Reference: Time synchronization RT Unified |
Root Cause Analysis
The symptom (HMI boots with wrong or default time after a power-down) has two independent root causes that can both appear in the field. Treat them as separate failure modes and verify which one applies before changing configuration.
Root Cause A - Bootloader RTC Bug
Older bootloader revisions of the Unified Comfort Panel corrupted the retentive RTC value after an extended power-down. The capacitor that backs the RTC was not exhausted; instead, the bootloader wrote an invalid value into the RTC register on the first boot after power restoration. Siemens documented this behavior and shipped a corrected bootloader. The fix is delivered through the Siemens Industry Online Support entry 109973587. Engineering teams that skipped the bootloader update on legacy UCPs deployed before the fix will see this failure mode.
Root Cause B - Capacitor-Backed Retention Window Expired
UCPs use an on-board supercapacitor to retain the RTC during power-down. Siemens rates the typical retention at approximately six weeks at room temperature. At higher ambient temperatures (above 40 degC inside a cabinet), the retention window shrinks. After the capacitor is exhausted, the panel boots with a default time (often a date in the year 2000 or the last power-down timestamp). The bootloader update in SIOS 109973587 does not extend this retention window - it only fixes the corruption bug. The retention window is a hardware limit.
Why the Wrong Time Breaks Communication
Secure HMI/PLC communication in WinCC Unified relies on TLS. TLS in turn validates certificates, and certificate validation requires a system clock that falls within the certificate's notBefore / notAfter validity window. When the panel's clock is months or years in the past, the panel sees every certificate as not yet valid and rejects the connection. The PLC, which has its own (correct) time, sees the panel's handshake as coming from the future or from a deeply skewed peer and rejects it as well. The result is a mutual rejection: no data flows between the two devices. WinCC Unified documentation for TIA V20 explicitly states that an incorrect system time can cause communication partners to reject connections, and that several communication protocols rely on certificate-based security or encryption. The full reference is the TIA Portal V20 help - WinCC Unified - Basics of time synchronization (RT Unified) at Time synchronization RT Unified.
Diagnostic Procedure
- Capture the exact panel model and article number from the system information screen (Operator Control - System - About). Note the firmware version and the bootloader version.
- Cross-reference the bootloader version against the affected list in SIOS 109973587. If the panel is below the corrected revision, Root Cause A is likely.
- Record the actual duration of the power-down that produced the fault. If the duration was less than 6 weeks and the clock is wrong on first boot, suspect Root Cause A. If the duration was more than 6 weeks, suspect Root Cause B or both.
- Read the S7-1500 local time (online - diagnostics - time). Compare to wall-clock time and to the UCP time after reboot.
- Open the WinCC Unified runtime diagnostic buffer (System Logs - Connections, or the alarm log) and look for certificate-validation errors, TLS handshake aborts, or secure connection rejected entries. Note the timestamps.
- Read the HMI device configuration for the time source: HMI device configuration - Time / Time synchronization. Confirm whether the panel is configured to use NTP, follow the PLC, or run as a free-running clock.
- If NTP is configured, ping the NTP server from a service laptop on the same subnet. Verify that UDP/123 is not blocked between the panel and the NTP source.
Solution 1 - Apply the Bootloader Update
The bootloader update from SIOS 109973587 is the first-line remedy because it fixes the corruption behavior. It does not, however, replace a proper time-synchronization architecture.
Update Procedure
- Open the SIOS entry 109973587 and identify the exact bootloader image for the affected panel model. Do not assume that one image fits all Unified Comfort Panels.
- Place the bootloader image in a known folder on the configuration PC.
- Connect the configuration PC to the panel's service interface (X1) or to the panel's PROFINET port on the cell network.
- In TIA Portal V20, open the HMI device and select Online - Accessible nodes to confirm connectivity.
- Use the Update firmware / Update bootloader path under the panel's online menu. Select the image you downloaded.
- Allow the flash to complete without interrupting power. A typical flash takes 5 to 15 minutes; do not cycle power during this window.
- When the panel reboots, set the time manually once even if NTP is configured. A single clean boot is required for the new bootloader to clear the corrupted RTC value.
- Re-run the verification procedure starting with a 24-hour power-down, then a week, then the operator's typical outage.
Solution 2 - Implement Time Synchronization
The bootloader update prevents RTC corruption. It does not extend the retention window. To keep the panel's clock accurate across arbitrary outages, implement a real time-synchronization architecture. Three architectures are common in TIA Portal V20 cells.
| Architecture | Time Master | Sync Method | Best For | Drawback |
|---|---|---|---|---|
| A | Plant NTP server | NTP from external stratum-1 / stratum-2 server | Sites with corporate time infrastructure, multi-cell plants | Requires reachable UDP/123 path and a corporate NTP policy |
| B | S7-1500 CPU | LSNTP block from Libraries for Communication for SIMATIC Controllers makes the CPU an NTP server | Stand-alone cells without corporate NTP, retrofit projects | CPU must have an accurate upstream time source or be set manually |
| C | UCP local clock | PLC synchronizes to the panel (PLC as NTP client) | Not recommended | Panel is the least reliable element; the bug being fixed makes this a circular dependency |
Architecture B - Detailed Procedure (PLC as NTP Server with LSNTP)
The LSNTP block is part of the official Siemens library Libraries for Communication for SIMATIC Controllers available in the TIA Portal library catalog. It implements a minimal NTP server on the S7-1500 that responds to NTP polls from any client on the plant network.
PLC-Side Configuration
- In TIA Portal V20, open the project and navigate to Options - Global Libraries - Libraries for Communication for SIMATIC Controllers catalog.
- Find the LSNTP block (typically under Communication / Time Synchronization) and drag it into the S7-1500 program.
- Place an instance DB (LSNTP_DB) and connect the block's I/O:
-
EN- tie to a startup tag or to the OB1 cycle. -
LISTEN_PORT- default 123 (NTP); change if your network policy requires a non-standard port. -
SRC_IP_ADDR- the IP address of the CPU (the server's own IP). Read this from the CPU's PROFINET interface configuration. -
STRATUM- set to 2 if the PLC synchronizes to an external NTP source, set to 1 if the PLC is the root time source for the cell. -
UTC_OFFSET- local offset from UTC in seconds (for example, -18000 for US Eastern Standard Time).
-
- If the PLC is to be a stratum-2 server (most common), configure the CPU device properties - Time of day - NTP mode and point it at the plant NTP server.
- Compile and download the program to the CPU. Confirm that no compile errors block the LSNTP block.
HMI-Side Configuration
- Open the Unified Comfort Panel device configuration in TIA Portal V20.
- Navigate to Time / Time synchronization.
- Switch the time source to NTP.
- Enter the S7-1500's IP address as the NTP server address. IPv4 unicast.
- Set the synchronization interval. A 60-second interval is a good starting point for cell networks; increase to 300 to 600 seconds if the network is shared with motion or vision traffic.
- Set the time zone to the plant time zone. Disable automatic daylight-saving handling if your cell must not shift its clock during DST transitions.
- Download the HMI configuration.
Sample LSNTP Block Wiring
// OB1 - cycle
// LSNTP_DB is the instance DB placed by the library
LSNTP_DB.EN := TRUE;
LSNTP_DB.LISTEN_PORT := 123;
LSNTP_DB.SRC_IP_ADDR := "CPU_IP_Addr"; // IP address of S7-1500
LSNTP_DB.STRATUM := 2; // PLC is downstream of plant NTP
LSNTP_DB.UTC_OFFSET := -18000; // US Eastern Standard Time
LSNTP_DB(); // call block
Architecture A - Plant NTP Server
- Confirm UDP/123 is open from the cell network to the plant NTP server.
- On the S7-1500: CPU device configuration - Time of day - NTP mode. Enter the plant NTP server address. Set synchronization interval (typical: 60 s).
- On the UCP: HMI device configuration - Time / Time synchronization - NTP. Enter the same plant NTP server address.
- Configure a redundant NTP server address if your plant runs redundant time servers.
- Download both configurations.
Configuration Parameters (TIA Portal V20)
| Parameter | Location in TIA Portal | Typical Value | Comment |
|---|---|---|---|
| HMI time source | HMI device configuration - Time | NTP | Use NTP for unattended cells |
| HMI NTP server | HMI device configuration - Time | CPU IP or plant NTP IP | IPv4 unicast; supports two servers |
| HMI sync interval | HMI device configuration - Time | 60 s - 600 s | Lower values increase network load |
| HMI time zone | HMI device configuration - Time | Plant time zone | Match PLC configuration; consider DST policy |
| CPU time source | CPU device configuration - Time of day | NTP | Align with HMI source |
| CPU NTP server | CPU device configuration - Time of day | Plant NTP IP | Set if Architecture A |
| LSNTP listen port | LSNTP_DB.LISTEN_PORT | 123 | Standard NTP port |
| LSNTP stratum | LSNTP_DB.STRATUM | 1 or 2 | 1 only if PLC is the root time source |
| LSNTP UTC offset | LSNTP_DB.UTC_OFFSET | Plant offset | Seconds from UTC |
Verification Procedure
- Confirm the bootloader is updated and the time-synchronization architecture is configured.
- Force a power-down of the UCP. The duration must be at least equal to the operator's worst-case outage. A typical first verification is 24 hours; the second is one week; the third is the operator's actual maximum outage.
- Re-energize the panel and let it complete its boot sequence. Do not perform manual time correction - the panel must re-acquire time from the configured source.
- Read the panel's local time from the system information screen within 30 seconds of boot completion. Record the value.
- Read the S7-1500 local time via online diagnostics. Record the value.
- Compute the delta. For NTP it should be less than 1 second once the first poll completes. For manual sync it should be less than 5 seconds at most.
- Trigger a write operation from HMI to PLC that uses certificate-based secure communication. If the write succeeds without a TLS rejection in the diagnostic buffer, the clock skew is within bounds.
- Review WinCC Unified logs for any TLS or certificate errors.
- Repeat steps 2-8 for each panel in the cell.
Edge Cases and Field Notes
Mixed-Vintage Cells
If a cell contains both Unified Comfort Panels (no battery) and older Comfort Panels (with CR2032 / 1/2 AA battery), plan for both worlds. The Unified panels need bootloader updates and NTP. The older Comfort Panels need preventive battery replacement on a 3 to 5 year cycle. Do not assume that the cell's time is correct just because one panel reports a plausible time.
Firewall Blocking NTP
UDP/123 must be open between NTP clients and the server. Some plant networks block UDP/123 by default because NTP amplification attacks are a known DDoS vector. Verify with a port scan or by enabling NTP diagnostic logs on the panel. If the firewall cannot be opened, use Architecture B (LSNTP on a non-standard port if your firewall permits).
Daylight Saving Transitions
Disable automatic DST handling if your cell operates in a region or application where DST causes shift handover confusion (for example, an audit log that crosses 02:00 on the DST changeover). Configure the time zone explicitly with a fixed UTC offset and document the policy in the operating procedure.
Security Certificates Installed Before Sync
If security certificates are installed on the panel before NTP is configured, the panel may reject them at install time due to clock skew. The notBefore field of a freshly minted certificate is now, and the panel's now can be years off if its RTC is corrupted. Always configure NTP first, force a sync, then install certificates.
HMI That Remains on Wrong Time After Update
If the panel keeps the wrong time after the bootloader update, reset the time manually once and then let NTP take over. A single boot cycle may be required to clear the stale retentive value. If the wrong value persists across two boot cycles, the panel's supercapacitor is exhausted and the panel needs hardware replacement.
S7-1500 CPU Without Upstream NTP
If the cell has no upstream NTP and you use Architecture B, the PLC is the root time source. Document the PLC's commissioning time as the cell's reference. Schedule a periodic check (typical: quarterly) to verify that the PLC's time has not drifted beyond acceptable bounds. Some plants install a battery-backed RTC module on the CPU rack; verify with the CPU's hardware manual whether your specific CPU model supports an RTC battery.
Communication Failure Despite Correct Time
If the time is correct on both devices and the connection still fails, the problem is not the RTC. Inspect the certificate store on both sides for expired certificates, check the TLS policy on the PLC (CPU properties - Security - TLS), and verify that the PROFINET or Ethernet cable path has not changed. WinCC Unified logs distinguish between time errors and certificate errors in the diagnostic buffer.
Commissioning Checklist
- Confirm bootloader version on every Unified Comfort Panel; update if below the SIOS 109973587 revision list.
- Confirm time source configuration on every panel (NTP preferred).
- Confirm time source configuration on every PLC (NTP preferred, or manually set with documented drift rate).
- Confirm UDP/123 is reachable on the cell network.
- Trigger a panel power-down and reboot; verify time within tolerance.
- Verify a TLS-protected write from HMI to PLC succeeds.
- Document the time-architecture choice (A, B, or C) and the upstream time source in the plant's network topology record.
FAQ
Does the Unified Comfort Panel have a replaceable RTC battery?
No. Unified Comfort Panels ship without a user-replaceable RTC battery. Time retention relies on a capacitor-backed RTC with a typical retention of approximately six weeks. Beyond that window, or after the bootloader bug described in SIOS 109973587, the panel needs to re-acquire time from an external source such as NTP.
Which SIOS entry documents the Unified Comfort Panel bootloader fix?
Siemens Industry Online Support entry 109973587 describes the bootloader bug and the update procedure for affected Unified Comfort Panels.
Why does a clock mismatch between the panel and the PLC break communication?
WinCC Unified and S7-1500 secure communication rely on TLS and certificate validation. When the panel's system time falls outside the certificate's notBefore / notAfter window or differs from the PLC's time beyond the configured skew, both peers reject the handshake and no data flows. The TIA Portal V20 documentation for WinCC Unified (Basics of time synchronization RT Unified at Time synchronization RT Unified) states explicitly that an incorrect system time can cause communication partners to reject connections.
How do I synchronize the panel to the PLC without a plant NTP server?
Use the LSNTP block from the Siemens library Libraries for Communication for SIMATIC Controllers. The block makes the S7-1500 act as an NTP server. Point the Unified Comfort Panel's NTP client at the CPU's IP address.
How long does the Unified Comfort Panel retain time without power?
Siemens rates the capacitor-backed retentive RTC at approximately six weeks under typical conditions. Actual retention varies with cabinet temperature and panel age. Plan a reboot cycle shorter than six weeks for unattended cells, or implement NTP time synchronization.