Resolving Simatic Net Multi-NIC Hardware Error on Dual Network

David Krause15 min read
Industrial NetworkingSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

Symptom set reported on engineering stations running SIMATIC NET PC Software Edition 2005 v6.3 SP3 (build 3228) on Windows XP SP2 with two Ethernet adapters installed:

  • Wired NIC: 192.168.100.162 / 255.255.255.0, gateway 192.168.100.254
  • Wireless NIC: 192.168.105.202 / 255.255.255.0, gateway 192.168.105.254
  • ping from one subnet to a host in the other subnet returns "Hardware error" instead of "Destination host unreachable" or a normal timeout.
  • Station Configuration Editor logs "CP with index 2 is not operational" and "The components could not create a default SDB."
  • Configuration Console shows both NDIS adapters with green status; the fault is not visible there.

The same workstation pings across both subnets without fault when SIMATIC NET is uninstalled, isolating the issue to the SIMATIC NET stack rather than the hardware or the Windows TCP/IP driver.

Field definition: Hardware error in ping.exe is the Windows Sockets mapping of WSAENETDOWN (10050) – "Network is down." It is raised when the sending path cannot bind to a usable source address, not when the destination is missing. Treat it as a local-stack error, not a remote problem.

Root Cause Analysis

Three independent SIMATIC NET behaviours combine to produce the failure on a dual-NIC PG/PC:

  1. Single-NDIS coupling. SIMATIC NET IE-PG coupling for v6.x binds to a single NDIS miniport through the OPC-Server/CP-IE Schnittstelle. The second card has no SDB (System Data Blocks) projection and is therefore flagged "not operational" in the Station Configuration Editor.
  2. SDB generation failure. The "components could not create a default SDB" error is raised by S7wnSub (the S7 communication service) when it cannot resolve a routable interface for the configured CP IE General slot. Without an SDB, S7 communication over the second card cannot initialise.
  3. TCP/IP(Auto) auto-binding. With two adapters in different subnets, the PG/PC interface selection TCP/IP(Auto) -> ... walks the binding order and may attach a route through the wrong interface. The ping command then submits the ICMP echo to a source address whose outgoing adapter is administratively bound to a different SIMATIC NET CP, producing WSAENETDOWN.

Why the wired card fails when the wireless card is active

Windows XP routes based on the longest prefix match first, then on metric. With both 192.168.100.0/24 and 192.168.105.0/24 on the host, traffic to a 192.168.105.x destination should leave on the wireless NIC. The SIMATIC NET S7 service, however, registers a raw socket on the bound NDIS index. If the SIMATIC NET CP IE General is mapped to the wired index (index 1) and the IE-PG Access setting is "Assign IP addresses unique to the project", the service actively rejects traffic originating on the wireless index. The ICMP stack inherits the rejection and returns Hardware error rather than a normal TTL expiry.

Why Configuration Console is silent

Configuration Console interrogates the NDIS layer (ndisuio user-mode IOCTL) and reports link state, MAC, and IP. SIMATIC NET's SDB/CP faults sit one layer above NDIS, in the S7 communication engine (S7wnSvr.exe, s7oiehsx.exe). Configuration Console cannot see them, which is why the cards appear healthy while S7 communication is broken.

Affected Versions and Compatibility

Component Version Status
SIMATIC NET PC Software Edition 2005 v6.3 SP3 (build 3228) Reproduces issue on dual-NIC
SIMATIC NET v6.4 / v7.0 / v7.1 (later SPs) Same root cause; mitigations improved
STEP 7 / NCM S7 V5.4 + SP3 and later SDB generation path
Operating system Windows XP SP2 (NDIS 5.1) Reproduction platform
Operating system Windows 7 / Server 2008 R2 (NDIS 6.x) Different binding order, same SDB error
CP module CP 1612 / CP 1613 / CP 1623 / CP IE General Affected equally
OPC layer SIMATIC NET OPC Server v6.3 / v6.4 Slow writes if index bound to wrong NIC
SIMATIC NET v6.3 SP3 predates general IEEE 802.11 SIMATIC NET support. Wireless adapters are not qualified as an S7 transport in this version. If the wireless NIC is used only for office/diagnostics traffic, it must be isolated from the fieldbus path.

Diagnostic Procedure Before You Touch Anything

  1. Capture ping output from both subnets with the wireless card enabled and disabled.
  2. Open Configuration Console, export the active module list, and note the Index assigned to each NDIS adapter.
  3. Open Station Configuration Editor, export the Station file (*.sdf or *.cfg), and record the CP IE General index, ring position, and SDB reference.
  4. Run cmd > route print and save the interface table; verify metric and binding order.
  5. From Start > SIMATIC > SIMATIC NET > Commissioning PC Station (or Start > Station Configuration Editor > Diagnostics), capture the local event log filtered to source S7 and OPC.
  6. Verify the PG/PC interface assignment in Set PG/PC Interface (Control Panel). Screenshot the active Access Point and the assigned parameter set.

Step-by-Step Resolution

Step 1 – Disable the second NDIS path for S7 traffic

If you need two physical networks on the engineering station (for example, a plant network and an office network), use a routing-capable gateway device or a VLAN-aware switch instead of binding two NICs into the SIMATIC NET station. On the SIMATIC NET side, keep only one adapter indexed as CP IE General.

Configuration Console
  > Modules
    > Index 1  -> Wired NIC        (assign to CP IE General, slot 0)
    > Index 2  -> Wireless NIC     (do NOT assign to any SIMATIC NET component)

Step 2 – Set IE-PG Access to "Do not assign IP addresses automatically"

  1. Open Set PG/PC Interface.
  2. Select the active access point, for example S7ONLINE (STEP 7) -> TCP/IP(Auto) -> <your wired NIC>.
  3. Click Properties.
  4. Switch to the IE-PG Access tab.
  5. Select the radio button "Do not assign IP addresses automatically".
  6. Click OK and exit.

The default "Assign IP addresses unique to the project" radio button makes SIMATIC NET assume it owns the IP layer and reject frames that do not match the projected SDB. On a station that also has a wireless card, this rejection is the direct cause of the Hardware error.

Why this matters: the IE-PG Access setting is a per-access-point flag, not a global registry key. If you switch the access point from TCP/IP to TCP/IP(Auto) after a project download, the setting reverts to its default. Re-check it after every project change.

Step 3 – Pin the active access point to one adapter

  1. In Set PG/PC Interface, point S7ONLINE at TCP/IP -> <wired NIC only>.
  2. Avoid TCP/IP(Auto) on a multi-NIC host. The Auto wrapper binds against the first enumerated adapter, which on a wireless-first BIOS is the wrong card.
  3. Save the assignment.

Step 4 – Rebuild the SDB from a fresh project

  1. Open STEP 7 / NCM S7.
  2. Create a new PC station project with one CP IE General on slot 0 and one IE General on the operator station index.
  3. Compile and download the SDB to the local PC station.
  4. Restart Station Configuration Editor.

The error "components could not create a default SDB" is almost always traceable to a project-side corruption when two CPs are configured in slots that do not correspond to physical modules. Removing the orphan slot and recompiling is the standard fix.

Step 5 – Re-test

  1. Open a command prompt: ping -S 192.168.100.162 192.168.105.1 (forces the source address to the wired card).
  2. Repeat with ping -S 192.168.105.202 192.168.100.1.
  3. Confirm that both directions return Reply from rather than Hardware error or Destination host unreachable.
  4. Open Station Configuration Editor > Diagnostics. CP with index 2 is not operational should now be absent or should appear only for the unassigned wireless index, which is acceptable.

Station Configuration Editor Error Reference

Message text Source module Likely cause Corrective action
CP with index 2 is not operational S7wnSvr Second CP slot has no matching NDIS adapter, or SDB is missing Bind S7 to one NIC only, recompile SDB
The components could not create a default SDB NCM S7 / S7sdbgen Project corruption, missing CP-IE slot mapping Rebuild PC station project, redownload SDB
No licence for CP-IE found LicenseLog Authorisation key not present for v6.3 Reinstall authorisation, see Siemens support article 16666606
OPC server not started OPC.SimaticNET Dependent S7 service failed to start Resolve upstream CP error first, restart OPC.SimaticNET
Hardware error (ping) Windows Winsock, surface from SIMATIC NET binding TCP/IP(Auto) bound to wrong NIC, or IE-PG Access rejecting traffic Pin access point to one adapter, set IE-PG Access to Do not assign automatically

Multi-NIC Configuration Best Practices

  • One SIMATIC NET, one NIC. Do not map two physical Ethernet adapters into a single PC station. SIMATIC NET PC Software v6.3 to v7.1 expects a single ring of CP modules per station; the second card is not a routable peer.
  • Disable the second card for S7. If the engineering station also needs office internet, leave the wireless adapter in Windows but exclude it from the S7ONLINE access point. Set its metric higher so default Windows routing prefers the wired card only when both subnets are reachable.
  • Use a static IP on the SIMATIC NET card. DHCP renewals on the SIMATIC NET-bound NIC can interrupt SDB sessions and produce transient CP not operational events. Use a fixed 192.168.x.y address and reserve it on the DHCP server.
  • Never enable IE-PG address assignment on a multi-NIC host. "Assign IP addresses unique to the project" was designed for single-NIC stations and is the dominant source of the Hardware error symptom.
  • Match subnet mask with gateway scope. The reported configuration has each NIC's gateway pointing at a router in its own subnet (192.168.100.254 and 192.168.105.254). This is correct, but the host only needs a default gateway for the subnet that is the primary S7 path. Remove the gateway from the office-facing NIC if S7 traffic is not expected to leave the plant subnet.
  • Sequence adapters in Device Manager. On Windows XP the binding order is set in Network Connections > Advanced > Advanced Settings > Connections. Put the SIMATIC NET-bound adapter first in the bind order; this controls which card TCP/IP(Auto) chooses.
  • Keep STEP 7, NCM S7, and SIMATIC NET versions aligned. A v5.4 STEP 7 with a v6.3 SP3 SIMATIC NET is supported, but a STEP 7 v5.5 with v6.3 is not. Mismatch produces SDB format errors that surface as CP not operational.

OPC Communication Verification

After the S7 stack is healthy, validate the OPC layer. The OPC Scout (bundled with SIMATIC NET v6.x) is the fastest way to confirm that the fix reached the application layer.

  1. Launch OPC Scout from Start > SIMATIC > SIMATIC NET > OPC Scout.
  2. Add a new OPC-DA group named VERIFY.
  3. Add an item, for example S7:[S7 connection_1]DB1,W0.
  4. Subscribe at 250 ms update rate.
  5. Confirm that read/write round-trip stays under 50 ms on a healthy local S7 connection.

If OPC writes are slow despite a green S7 connection, the binding has reverted to a low-priority NIC. Re-check Step 2 (IE-PG Access setting) and Step 3 (access point pin). The same fault pattern surfaces in third-party OPC clients, including OPC UA .NET clients that resolve the SIMATIC NET server by Application URI – a stale or self-signed certificate forces the client to fall back to discovery, which can look like slow writes if the network binding is wrong.

OPC UA certificate checks

For SIMATIC NET v8 and later (OPC UA server), verify the following after fixing the NIC binding:

  • The Application URI in the certificate matches the SIMATIC NET station's Station name exactly.
  • The certificate is placed in %ProgramData%\Siemens\Automation\OPC UA\PKI\Trusted on every client.
  • The trust chain is intact; a broken chain (intermediate CA missing) causes clients to reject the server and silently retry discovery.

Verification Checklist

# Check Expected result
1 ping across both subnets from wired card Reply from destination, <10 ms on local segment
2 ping from wireless card to plant subnet Reply from destination or clean Destination host unreachable
3 Station Configuration Editor diagnostics Only the assigned CP is Operational; no SDB errors
4 Configuration Console All NDIS adapters green, no warning triangles
5 Set PG/PC Interface > IE-PG Access Radio button set to Do not assign IP addresses automatically
6 OPC Scout round-trip Read/write under 50 ms, no stale items
7 Windows Event Log > Application No S7wnSvr warnings in last hour

Troubleshooting Matrix

Symptom Layer Most likely cause First action
ping Hardware error across subnets TCP/IP binding TCP/IP(Auto) on wrong NIC Pin S7ONLINE to one wired adapter
Hardware error only when SIMATIC NET started SIMATIC NET S7 service IE-PG Access set to auto-assign Switch to Do not assign automatically
CP with index 2 is not operational SDB / PC station project Orphan CP slot or no SDB Rebuild PC station, recompile SDB
Components could not create a default SDB STEP 7 / NCM Project corruption New PC station project, redownload
Configuration Console green but S7 fails Layer above NDIS S7 service mis-bound Set PG/PC Interface, restart S7 service
OPC Scout reads OK, writes very slow OPC / binding Wrong NIC bound, or certificate chain broken (v8+) Re-pin access point, repair OPC UA trust
Wireless card works for office, kills S7 Routing SIMATIC NET rejecting cross-NIC traffic Remove S7 gateway from office NIC, raise metric

Reference: Windows Sockets Error Codes Seen on SIMATIC NET Stations

Code Symbol Meaning in ping context
10050 WSAENETDOWN Network is down – surfaces as Hardware error in ping.exe
10051 WSAENETUNREACH Network is unreachable – Destination host unreachable
10065 WSAEHOSTUNREACH Host unreachable – Reply from router: Host unreachable
10060 WSAETIMEDOUT Connection timed out – Request timed out
10049 WSAEADDRNOTAVAIL Cannot assign requested address – forced ping -S mismatch

Hardware error in ping is almost always 10050. If the customer reports any other text, the issue is not a binding problem but a routing or firewall one.

Edge Cases and Field Notes

  • USB-to-Ethernet adapters. Some USB NICs enumerate as NDIS adapters but are not in the SIMATIC NET hardware compatibility list. They appear in Configuration Console, but CP IE General cannot bind to them. Symptom: SDB downloads succeed, but CP not operational appears on next restart.
  • VPN clients. A Cisco AnyConnect or OpenVPN TAP adapter behaves like a third NIC. If it is enabled while SIMATIC NET is running, the binding order shifts and the IE-PG Access flag resets. Add VPN adapters only after the SIMATIC NET stack is fully loaded, or use split-tunnel rules to exclude the plant subnet.
  • IPv6 on Windows XP. SP2 enables IPv6 by default after a hotfix. If the wired NIC has an IPv6 link-local address and the wireless does not, TCP/IP(Auto) prefers the wired card for IPv4 and breaks S7-on-wireless assumptions. Disable IPv6 on the SIMATIC NET-bound adapter to stabilise routing.
  • VMware / VirtualBox bridges. Bridged virtual NICs enumerate as additional NDIS adapters and steal the Auto-binding. Exclude them from Network Connections > Bridge or disable before commissioning.
  • Antivirus firewalling. Some endpoint protection suites block ICMP from non-default adapters. Confirm with netsh firewall set icmpsetting 8 enable (Windows XP) and rule out a side effect before deeper diagnosis.
  • Service start order. S7wnSvr depends on RPCSS, EventSystem, and COM+ Event System. If a service start race produces the CP not operational error on first boot, a manual restart of the SIMATIC NET S7 service resolves it without project changes.

Alternate Controller and Platform Notes

The Hardware error symptom is not unique to SIMATIC NET PC Software. The same NDIS binding root cause is documented for:

  • S7-1200 / S7-1500 TIA Portal stations – the TIA Portal PC station has the same single-CP rule. Adding a second Ethernet adapter in the device configuration produces a similar not operational warning.
  • WinCC Runtime stations – WinCC uses the same OPC-SimaticNET layer; mis-binding breaks WinCC channel diagnostics with the same S7 event log signature.
  • WinAC RTX – Soft-PLC runtime relies on the same S7wnSvr; a multi-NIC host will fail to load the RTX slot if the access point is not pinned.
  • Third-party OPC DA bridges – Kepware, Matrikon, and Softing use the SIMATIC NET S7 driver. Binding fixes on the SIMATIC NET side propagate automatically.

On S7-300 / S7-400 the equivalent fix is in STEP 7's PC Interface assignment, not TIA Portal. The IE-PG Access tab exists only in the SIMATIC NET access point; the S7-CPU side does not have an equivalent flag.

Safety and Operational Considerations

Do not change the IE-PG Access radio button or the S7ONLINE access point on a station that is the only engineering interface to a running process. A mis-click that drops the binding to the wrong NIC will interrupt all online connections, including open HMI tag browsers and active downloads. Schedule the change in a maintenance window with a known-good backup of the PC station project.

When commissioning a new PC station, validate S7 communication on a bench test rig with one NIC and one S7-300/S7-400 CPU before adding the office/wireless adapter. The NDIS bind order is the single most common reason that stations fail first commissioning and pass follow-up.

FAQ

Why does ping show "Hardware error" after installing SIMATIC NET on a dual-NIC PC?

"Hardware error" maps to Windows Sockets error 10050 (WSAENETDOWN). SIMATIC NET v6.3 binds the S7 service to a single NDIS adapter; the IE-PG Access setting "Assign IP addresses unique to the project" then rejects ICMP traffic whose source does not match the projected SDB, surfacing as 10050. Set IE-PG Access to Do not assign IP addresses automatically and pin S7ONLINE to one adapter to clear the error.

What does "CP with index 2 is not operational" mean in Station Configuration Editor?

It means the second CP slot in your PC station project has no matching NDIS adapter, or the SDB for that slot failed to compile. SIMATIC NET expects one CP-IE per station; an orphan second slot is reported as not operational. Remove the orphan slot, recompile the SDB, and redownload to the local PC station.

How do I fix "The components could not create a default SDB"?

Rebuild the PC station project in STEP 7 / NCM S7 with a single CP IE General assigned to a real NDIS adapter, then download the SDB. The error is project-side, not driver-side, and is not resolved by reinstalling SIMATIC NET alone.

Is TCP/IP(Auto) safe to use with SIMATIC NET on a multi-NIC host?

No. TCP/IP(Auto) walks the NDIS bind order and may attach to a NIC that has no SIMATIC NET role, which routes S7 traffic to the wrong adapter. Use TCP/IP -> <specific wired NIC> and verify the selection in Set PG/PC Interface after every project change.

Does SIMATIC NET v6.3 support a wireless Ethernet adapter as a CP IE?

No. SIMATIC NET PC Software Edition 2005 v6.3 SP3 does not qualify wireless adapters as a CP IE transport. Use a wired Ethernet adapter for the CP IE General slot and isolate the wireless card to office traffic with a higher interface metric.

My OPC writes are slow after rebuilding a PC station with SIMATIC NET – what should I check first?

Re-verify the S7ONLINE access point pin, the IE-PG Access radio button, and the NDIS bind order. A re-bound S7 service on the wrong NIC adds 50–500 ms per write. If you are on SIMATIC NET v8 or later, also verify the OPC UA certificate chain on every client, because a broken chain forces clients back to discovery which presents as slow writes.

Back to blog