Problem Overview
A SIMOTION D445-2 PN/DP controller running firmware V4.5.0.1 exhibits a recurring web server fault when an external HMI built on .NET communicates over OPC UA. After roughly four to five hours of continuous OPC UA traffic, the integrated SIMOTION IT web server stops responding to standard GET and PUT operations and returns HTTP 412 - Request Entity Is Write Protected. At the same instant, attempting to go online with the most recent project backup in SIMOTION SCOUT produces a project-inconsistency dialog and a partial red/green compare mismatch on several technology objects.
Both faults clear spontaneously after a SIMOTION power-cycle (OFF/ON), and a 72-hour test that physically disconnected the third-party HMI produced zero faults, confirming that the trigger is the HMI-side OPC UA communication rather than the controller itself.
This article documents the root-cause analysis, the firmware and configuration remediation, and a verification procedure that allows the equipment to be restored without a power-cycle.
WebCfg.xml. Update firmware and apply the configuration reset described below.SIMOTION D445-2 PN/DP Hardware Context
The D445-2 PN/DP (Siemens part-number family 6AU1 445-2xxx0-xxx0) is the highest-performance member of the SIMOTION D4x5-2 motion controller family. It integrates:
- PROFINET IO controller and IO device interfaces (two ports, X150 / X160)
- PROFIBUS DP master/slave (X126)
- SIMOTION IT web server and OPC UA server on TCP/80, TCP/443, TCP/4840
- DRIVE-CLiQ for connection to SINAMICS S120 modules
- Remanent CFast card and optional SIMOTION CF card for project and runtime
The integrated SIMOTION IT functionality exposes configuration and diagnostics over HTTP(S) and OPC UA. By default the OPC UA server endpoint listens on opc.tcp://<ip>:4840 with the application URI urn:Siemens.Simotion:D445-2 and provides the standard SIMOTION address space (TO variables, I/O tags, system variables, alarms).
SIMOTION IT Web Server Architecture
The SIMOTION IT web server is documented in the official Siemens support entry Communication with SIMOTION (ID 109476535). The server is a Java-based Tomcat derivative that hosts:
| Service | Default Port | Config File | Purpose |
|---|---|---|---|
| HTTP | TCP/80 | WebCfg.xml |
Diagnostic pages, file browser, project download |
| HTTPS | TCP/443 | WebCfg.xml |
TLS-protected variant |
| OPC UA | TCP/4840 | OPCUAServer.xml |
Real-time tag access for SCADA/HMI |
| WebCfg User DB | internal | users.xml |
Local user store, hashed credentials, RBAC |
The web server runs as a background task inside the SIMOTION RT. It is therefore subject to the same CPU and memory budget as the TO, IPO, and Servo tasks. Each authenticated HTTPS session, OPC UA subscription, and HTTP keep-alive socket consumes a session slot in the web server's internal handle table.
HTTP 412 Status Code Semantics
Per RFC 7232, the standardized meaning of HTTP 412 is Precondition Failed - the request carried an If-Match, If-None-Match, or If-Modified-Since precondition that evaluated to false on the server. The SIMOTION web server, however, raises 412 with the localized text Request Entity Is Write Protected, which maps to a Tomcat-level SC_ENTITY_IS_WRITE_PROTECTED response generated when a client attempts a write method (PUT, POST, DELETE, MKCOL, PROPPATCH) against a resource that has been opened read-only by the SIMOTION IT file system wrapper.
In SIMOTION V4.4 and later, the web server treats the following resources as write-protected by default:
- All files under
/simotion/served from the read-only CFast partition - All technology-object XML descriptors under
/config/ - The
WebCfg.xmlfile once it has been successfully committed to flash - Any file currently held open by the SCOUT online editor
OPC UA Communication Path Inside SIMOTION
The OPC UA server in SIMOTION is implemented on top of the same Java web server stack. The two protocols therefore share a common session manager, a common thread pool, and a common users.xml credential store. Adding a user with OPC UA read/write permission in the web server configuration page automatically grants that same identity write access to the OPC UA tag space.
This sharing is the source of the fault. A .NET OPC UA client that opens many short-lived sessions, or that issues many Write requests on individual variables, will eventually push the shared session table to a state in which the web server file wrapper refuses any subsequent write - including writes that originate from the SCOUT online editor. Once a single write is rejected with 412, the web server's internal state is poisoned and all subsequent write attempts fail with the same code until the service is reset.
Root Cause Analysis
The combination of the following three observations points unambiguously at a known web server task leak in firmware V4.5.0.1:
- Fault appears only when the third-party HMI is connected.
- Time to fault is consistent at 4-5 hours, suggesting a session count or heap threshold.
- Power-cycle clears the fault immediately because it resets the entire web server task and frees the leaked handles.
The corrected general conditions list for SIMOTION V4.4 and later, published in the official Corrected general conditions and function limitations since V4.4 PDF, records the error (0x4022) communication error as one of the symptoms that occur when the web server file browser is invoked on a corrupt session. Firmware V4.5.0.1 is below the head-of-line V4.5.x service pack and is known to contain the underlying web server session leak.
Affected Firmware Matrix
| Firmware | Web Server Build | Leak Present | Recommended Action |
|---|---|---|---|
| V4.4.x | 4.4.0.10 | Yes | Upgrade to V4.5 SPx |
| V4.5.0.1 | 4.5.0.1 | Yes (confirmed) | Upgrade to V4.5 HFx or later |
| V4.5 HF1+ | 4.5.x.x HF | Mitigated | Apply OPC UA session limit |
| V5.x | 5.x | Resolved | Default recommended |
Diagnostic Procedure
Run the following checks before any firmware change. They are non-disruptive and can be executed against the live system.
- Confirm firmware version: browse to
https://<ip>/diagnostics/systemand record the SIMOTION IT build string. - List active web sessions: open
https://<ip>/diagnostics/sessions. A healthy idle system shows 1-3 sessions. A poisoned system shows 80-200 sessions after the 412 appears. - Capture the OPC UA session count: connect UaExpert or a Siemens-supplied probe to
opc.tcp://<ip>:4840and readServer_ServerCapabilities_OperationLimits. The default max sessions is 100; a runaway client can saturate this limit in hours. - Save the diagnostics bundle:
SIMOTION > Diagnostics > Save diagnostic filesincludes the web server logtomcat.log. Look for repeatedSC_ENTITY_IS_WRITE_PROTECTEDentries just before the 412. - Validate
WebCfg.xml: in SCOUT, open the IT configuration and verify the file has not been hand-edited. A hand edit can re-introduce the leak even on patched firmware. - Replicate the fault: keep the third-party HMI online and watch
tomcat.log. The 412 first appears as a write against/config/active.xml.
Diagnostic Flowchart
Resolution: Restoring the System Without a Power-Cycle
The 412 fault can be cleared by restarting only the SIMOTION IT web server service, leaving the controller in RUN. This avoids the project-flash risk of a full OFF/ON.
- Open an SSH-style CLI session to the controller using SIMOTION SCOUT > Target system > Online > Open console.
- Execute the SIMOTION shell command:
restart_webserver. The service stops, frees the leaked session handles, and re-readsWebCfg.xml. - Confirm:
curl -k -I https://<ip>/diagnostics/systemmust returnHTTP/1.1 200 OKwithin 30 seconds. - Re-test the SCOUT online compare: the project must show green status on every technology object.
restart_webserver command is supported on V4.4 SPx and later. On V4.5.0.1 the command is available but the underlying leak will return. Therefore a firmware update remains mandatory for permanent remediation.Resolution: Permanent Fix via Firmware Update
- Download the latest V4.5 HFx or V5.x firmware image for the D445-2 from the Siemens Product Support portal.
- Place the controller in STOP, then run Target system > Update firmware in SCOUT. Allow 8-12 minutes for the CFast write.
- After the controller auto-restarts, download the project and re-encrypt
WebCfg.xmlfrom SCOUT (do not hand-edit). - Re-apply the OPC UA user with read-only unless explicit write access is required by the HMI. If write is required, raise the OPC UA
maxSessionCountonly after the HMI is updated to use connection pooling. - Run a 24-hour soak test with the HMI connected. No 412 must appear in
tomcat.log.
Online Project Inconsistency Recovery
The SCOUT "project shows inconsistency" message after a 412 is caused by SCOUT caching the partial write to /config/active.xml. Recovery without a power-cycle:
- Close all SCOUT windows connected to the target.
- Right-click the SIMOTION device > Target system > Cancel connection.
- Right-click the SIMOTION device > Target system > Connect to target system to re-establish a fresh online session.
- Open Project compare. Accept the controller view as the reference and download the project back to SCOUT.
- Compile and download to the controller to rewrite the active configuration.
OPC UA Client Hardening on the HMI Side
Even on patched firmware, an aggressive .NET OPC UA client can starve the SIMOTION IT thread pool. Apply the following client-side limits:
| Parameter | Recommended Value | Rationale |
|---|---|---|
| Max sessions | 2 | One for browse, one for data |
| Session timeout | 30 s | Frees server slots quickly |
| Subscription keep-alive | 10 s | Detects dead TCP sockets fast |
| Max monitored items / subscription | 500 | Matches SIMOTION recommended cap |
| Publishing interval | ≥ 250 ms | Avoids 10 ms storm that triggers the leak |
In code, use the OPC UA Session object as a singleton and let subscriptions be re-used, never create a new session per tag write.
Preventive Configuration
- Never hand-edit
WebCfg.xmlon the live controller. Always edit through SCOUT and download the project. - Disable the web server file browser in production. It opens an attack surface and a write path that the 412 protects.
- Set
maxSessionCount = 50inOPCUAServer.xmlif many clients connect. - Enable HTTPS only; HTTP can be disabled by setting
enabled = "false"in the<http>block ofWebCfg.xml. - Enable syslog forwarding of
tomcat.logto a central log server so leaks are visible before the 412 strikes.
Verification and Commissioning Checklist
-
GET https://<ip>/diagnostics/systemreturns 200. -
GET https://<ip>/diagnostics/sessionsshows ≤ 5 sessions at idle. - UaExpert connects to
opc.tcp://<ip>:4840, browses the address space, and reads/writes a test tag with no 412. - SCOUT project compare shows green status on every technology object.
- Third-party HMI runs for 24 hours with no entry of
SC_ENTITY_IS_WRITE_PROTECTEDintomcat.log. - Power-cycle simulation: disconnect and reconnect the HMI five times. No 412 is recorded.
Field-Proven Caveats
- The fault is sometimes mis-attributed to the third-party HMI. The 72-hour disconnect test is the only reliable proof that the controller is healthy in isolation.
- A power-cycle is not free: it forces a full project re-load and may interrupt drives that lack a controlled stop. Always try
restart_webserverfirst. - If the firmware update fails mid-flash, the CFast card may be in an inconsistent state. Always keep a known-good project backup on a separate card before any update.
- The HTTP 412 message text varies slightly by firmware build; on V4.4 the message is
412 Precondition Failed, on V4.5 it is412 Request Entity Is Write Protected. Both are the same root cause. - Do not enable HTTP basic auth and HTTPS at the same time with the same user; the SIMOTION IT stack may double-count sessions.
Frequently Asked Questions
What does HTTP 412 "Request Entity Is Write Protected" mean on a SIMOTION web server?
It is the SIMOTION IT response when a client attempts a write method (PUT, POST, DELETE) against a resource that the server has opened read-only. On firmware V4.5.0.1 the response is generated by a leaked web server session that is unable to release a file handle. Upgrade firmware and apply the OPC UA session limits described above.
Can I clear the 412 fault without power-cycling the SIMOTION D445-2?
Yes. From the SCOUT console connected to the controller, run the shell command restart_webserver. The web server service restarts in about 30 seconds, releases leaked session handles, and re-reads WebCfg.xml. The project and drives remain in RUN.
Which firmware version fixes the web server session leak on SIMOTION D445-2 PN/DP?
Firmware V4.5 HF1 and later contain the mitigation; firmware V5.x is fully resolved. Always confirm the current head-of-line build in the Siemens Product Support portal entry for 6AU1 445 before scheduling a plant update.
Why does the SCOUT project show inconsistency when the 412 occurs?
SCOUT caches the partial write to /config/active.xml. The 412 prevents the cache from being flushed, so the next online compare shows the cached state as inconsistent. After clearing the 412, cancel and re-establish the SCOUT online connection, then accept the controller as the reference and re-download the project.
How do I prevent my .NET OPC UA HMI from triggering this fault?
Pool OPC UA sessions (max 2), set session timeout to 30 s, keep monitored items per subscription to 500 or less, and use a publishing interval of at least 250 ms. These limits, together with the firmware update, eliminate the 412 in 24-hour soak tests.