Problem Overview
The error message "Download (13:4046) internal error 65549" is reported by SIMATIC Manager (STEP 7 V5.x) and the TIA Portal download dialog when the engineering station fails to transfer hardware configuration, system data, or blocks (OB, FB, FC, DB, SFB, SFC) to a SIMATIC S7-300, S7-400, ET 200, or WinAC target. The error is logged in the STEP 7 diagnostic buffer and the Windows Application Event Log, and is typically associated with one of the following fault classes:
- Corrupted STEP 7 project database (S7P, S7L, S7M, S7D, _TMP files).
- Blocked transport channel between the PG/PC interface and the PLC (MPI, PROFIBUS, Industrial Ethernet / ISO-on-TCP / TCP / S7 Communication).
- Operating system, .NET runtime, or DCOM permission state incompatible with the installed STEP 7 version.
- Damaged STEP 7 installation files (S7BIN, S7RTM, S7WKSEXA, S7OFFICE, S7USIEX, S7JOBST).
- Background services not started: S7DOS, SIMATIC Device Drivers, S7TrcSrv, CP_HMI_Internet_Service, SQL Server (SIMATIC Logon / S7-DB).
The error is most often observed when commissioning a brand-new Siemens-supplied Field PG, when migrating an old STEP 7 V5.4 / V5.5 project to a Windows 10 / Windows 11 PC, or after the engineering PC has been replaced following hardware failure. The behavior is identical whether the target is reached over TCP/IP, PROFIBUS DP, MPI, or a telecontrol adapter (e.g., SINAUT MD720).
Error Code Structure
The dialog text "Download (13:4046) internal error 65549" contains three distinct identifiers that should be recorded for the support ticket:
| Field | Value | Meaning |
|---|---|---|
| Operation | Download | Direction PC → PLC (write service) |
| Step number | 13 | Internal service counter (online sub-step) |
| Sub-code | 4046 | STEP 7 resource manager fault |
| Internal error | 65549 = 0x1000D | OS / installation-level fault returned to S7API |
The internal value 65549 is the HRESULT-style return code from the S7 communication layer (S7ONLINE / S7DOS). It maps to a Windows-level fault such as E_FAIL raised when the S7API DLL chain (e.g., S7API32.DLL, S7E32EX.DLL, S7OLEA32.DLL) cannot bind to the device driver, or when a transient buffer allocation fails because the STEP 7 process does not have the required privilege on the local Windows account.
Confirmed Root Causes
Field cases consistently converge on five root causes. Each must be ruled out in the order shown, from least invasive to most invasive.
-
Project database corruption caused by interrupted saves, antivirus locking
.s7parchive files, or moving a project across UNC paths with a stale reparse point. - Incomplete STEP 7 installation – usually missing the Automation License Manager service, missing the S7-300 / S7-400 option package, or an interrupted install because Windows Defender Real-Time Protection was not yet disabled.
- PC environment mismatch – STEP 7 V5.5 SP2 / SP2 HF1 is approved for Windows 7 SP1, Windows Server 2008 R2 SP1, and Windows 10 1709 / 1803. STEP 7 V5.7 is the first release certified for Windows 10 1909 and higher. New Siemens Field PGs frequently ship with Windows 10 21H2 or Windows 11, which will install STEP 7 V5.7 only. Older projects opened in a non-certified OS will compile but throw internal errors on download.
- PG/PC interface mis-configuration – the active access point points at a virtual adapter, a TAP-Win32 driver, or a USB serial adapter (PC-Adapter USB A2 / 6ES7972-0CB20-0XA0) without a real PROFIBUS cable attached.
-
Windows security and DCOM – User Account Control (UAC) is at the default level, the SIMATIC Manager is not run as administrator, the Windows Firewall is blocking
S7DOS.exe, or DCOMCNFG is not configured for the SIMATIC HMI and SIMATIC NET service accounts.
Pre-Diagnostic Checklist
Before changing the installation, validate the following so the support team can isolate the fault in a single iteration.
| # | Check | How | Expected |
|---|---|---|---|
| 1 | STEP 7 version | SIMATIC Manager → Help → About | e.g. V5.6 + HF3, V5.7 |
| 2 | OS build | winver |
1809 / 21H2 / 22H2 only with V5.7 |
| 3 | Project file integrity | Open project on the original PC | Download succeeds on original PC |
| 4 | Online reachability | PG/PC Interface → Diagnostics → Test | All nodes reachable |
| 5 | CPU operating mode | Mode selector or PG online view | STOP or RUN-P |
| 6 | Free CPU memory | PLC → Module Information → Memory | RAM ≥ 1 KB free, Flash ≥ 2 KB |
| 7 | Password / access level | PLC → Accessible Nodes | CPU password matches |
| 8 | Antivirus / EDR | Open Defender → Virus & threat protection | Folder exclusions present |
If the project can be downloaded on the original PC but not on the new PC, the fault is environmental, not in the project. If the project cannot be downloaded on either PC, the project itself is the suspect and Reorganize (slow) plus Save As should be attempted first.
Step-by-Step Resolution
Step 1 – Recover the Project Database
- Open the project on the new PC in SIMATIC Manager.
- Right-click the project → Save As to a local path (e.g.,
C:\Siemens\S7Proj). Saving across a network share or OneDrive is the most common cause of 65549 because the project files are continuously re-hydrated by the sync client. - From the same dialog choose Reorganize (slow). The slow reorganizer rebuilds the offline DB views and the System Data container. A full reorganize of a 30 MB project typically takes 5–10 minutes on a Core i5-1145G7.
- If the re-organizer itself returns an error, open NetPro and HW Config in isolation. A standalone fault in HW Config (e.g., a missing GSD file) is enough to abort the entire download sequence with 65549.
- Re-attempt the download to the CPU. If the error persists, the project is clean; the fault is in the PC.
Step 2 – Validate Windows Account Privileges
- Close SIMATIC Manager.
- Right-click the SIMATIC Manager icon → Run as administrator. Confirm by checking that the title bar shows SIMATIC Manager – [Project – Online] with no yellow warning bar.
- Open Control Panel → Administrative Tools → Local Security Policy → Local Policies → Security Options and set User Account Control: Run all administrators in Admin Approval Mode to Disabled if the PC is a single-user Field PG. Re-enable before delivering the PG to a customer with multiple users.
- Set DCOM: Machine Access Restrictions to allow Everyone for the following DCOM applications: SIMATIC NET Framework Server, SIMATIC S7 DOS Service, S7ActiveX, and SCSIMR. This is the most frequent finding on a new Siemens Field PG that has not been pre-imaged with the engineering suite.
Step 3 – Validate the PG/PC Interface
- Open Start → Siemens Automation → PG/PC Interface.
- Set Application Access Point to S7ONLINE (STEP 7) -> <your real adapter>. The default PN-IO is correct for TCP/IP; CP 5611 (MPI) is correct for PROFIBUS; PC Adapter USB A2 is correct for the 6ES7972-0CB20-0XA0 USB-to-MPI adapter.
- Click Diagnostics. If a warning icon appears, the selected interface cannot be opened, the driver is missing, or the USB cable is unplugged.
- For Industrial Ethernet, validate with Ping:
ping 192.168.0.1should return <1 ms; if the IP is on a different subnet, the download will time out and the resource manager will surface the failure as 65549 after 30–90 seconds. - For PROFIBUS, run PLC → Accessible Nodes. The target CPU should appear with its MPI / PROFIBUS address (default 2). If it does not, the physical layer is broken (terminator, shielding, baud rate, address conflict).
Step 4 – Repair or Reinstall STEP 7
If the project, privileges, and interface are all validated and the error persists, repair the STEP 7 installation:
- Insert or mount the STEP 7 installation media corresponding to the licensed version (V5.5 SP2 DVD, V5.6 DVD, V5.7 USB). The license key on the Automation License Manager (ALM) dongle or the hardlock USB stick is preserved during a repair.
- Run
Setup.exeand choose Modify / Repair. The repair replaces corrupted runtime files:S7API32.DLL,S7DOS_S.exe,S7WM78XA.DLL,ccstart.exe, the Microsoft SQL Server Express instance used by S7-DB, and the OPC-DA bridge. - If Modify / Repair does not clear the error, perform a full Uninstall followed by a clean install. The official Siemens Industry Online Support portal publishes the STEP 7 installation manuals that include the post-install checklist (reboot, license transfer, re-attach project archive, re-run the Station Configuration Editor).
- After reinstall, copy the
S7E32EX.DLLfrom a known-good installation if you suspect a broken component. Verify the file version withright-click → Properties → Detailsand compare against the version published in the Siemens Support entry list.
C:\Program Files\Siemens\Automation directory and the C:\Siemens\S7Proj project directory before reinstalling. The Automation License Manager database is normally retained in %ProgramData%\Siemens\Automation License Manager\License; copying this folder preserves floating licenses assigned to the PG.Step 5 – Re-Validate Online Connectivity
- Restart the PC. Do not skip the restart – the S7DOS driver stack does not reload until the next boot.
- Open SIMATIC Manager as administrator.
- Open the recovered project and select the S7 program.
- Choose PLC → Download or right-click the CPU in Accessible Nodes and select Download to Target System.
- Confirm that the download completes without the 65549 dialog.
Advanced Diagnostics
Event Log Inspection
Open Event Viewer → Windows Logs → Application. The S7DOS service and the SIMATIC Manager log entries with the source S7API, S7ONLINE, or SIMATIC NET. Look for event ID 5 (initialization failed), event ID 7 (license not present), or event ID 42 (transport binding failed). Each event ID has a matching knowledge base article on the Siemens Industry Online Support portal.
Wireshark Trace of the S7 Connection
Capture the TCP stream on the engineering interface. S7 Communication uses ISO-on-TCP (port 102) or the proprietary S7 protocol (port 102 with TPKT/COTP). A correctly opened session starts with CR TPDU (Connect Request) → CC TPDU (Connect Confirm) → DT TPDU (Data) and ends with DR TPDU. If the capture shows a DR TPDU immediately after the CR, the PLC rejected the session because the PG sent a Setup Communication PDU with an unknown rack/slot, which is the most common 65549 root cause when the HW Config rack layout does not match the actual physical rack.
CPU Diagnostic Buffer
From PLC → Module Information → Diagnostic Buffer, scroll to the most recent event. The relevant event classes are:
| Event class | Meaning | Typical fix |
|---|---|---|
| W#16#4560 | STOP caused by download | Re-try download; expected after Stop/Run transition |
| W#16#45A2 | Communication fault (S7 connection abort) | Check CP firmware, Ethernet cable, switch VLAN |
| W#16#42F4 | Module removed / faulty | Verify slot population matches HW Config |
| W#16#4270 | Distributed I/O failure | Check PROFIBUS terminators and baud rate |
Edge Cases and Variant Behaviour
TIA Portal vs SIMATIC Manager
The same download fault presents as "Internal error 65549 – Download to device failed" in the TIA Portal (V15.1, V16, V17, V18) when the project is migrated from a STEP 7 V5 project with the legacy S7 program container. TIA Portal requires that the target device's firmware version be identical to or higher than the version selected in Device Configuration → Properties → General. A V5.5 project opened in TIA V17 with a CPU 315-2 PN/DP (6ES7315-2EH14-0AB0) firmware V3.3 will compile, but the download to a physical CPU running firmware V3.2 will return 65549 because the Get_CpuType PDU does not match the expected family. The fix is to align the firmware in HW Config to the physical CPU, or to upgrade the CPU firmware using the SIMATIC Automation Tool.
Multi-User Engineering
In a server-based multi-user engineering (STEP 7 V5.x multi-user or TIA Portal with TIA Multiuser Server), the project is opened from a shared UNC path. The 65549 error appears if two engineers attempt to download the same S7 program simultaneously, or if the multi-user server's MSSQL database is in Restoring state after a backup. Resolve by serializing downloads via a checkout policy and ensuring the multi-user service account has db_owner on the MSSQL instance.
Hardlock / License Faults
If the Automation License Manager does not recognize the USB hardlock (e.g., 6ES7658-2XX00-0XA0) or the floating license server is unreachable, STEP 7 will still allow offline editing, but the Download to Target System command fails with 65549 because the S7API checks the license before opening the transport channel. The ALM (AlmMon32.exe) will display a yellow triangle in the system tray. The fix is to re-seat the USB hardlock, re-install the ALM driver, or restore the floating license on the server.
Verification Procedure
After the reinstall and reboot, perform the following acceptance test:
- Open SIMATIC Manager as administrator.
- Open the project and select the S7 program.
- Choose PLC → Compile and Download Objects. The compile must complete without warnings; the download progress bar must reach 100 %.
- Choose PLC → Online → Monitor / Modify and verify that the imported tags update in real time.
- Cycle power on the CPU and confirm that the user program starts in RUN. The diagnostic buffer should contain exactly one entry of class W#16#4560 (STOP → RUN after restart).
- Capture a screenshot of the successful download dialog and archive it with the project for the SAT (Site Acceptance Test) report.
If any step fails, capture the new internal error code and the most recent S7API event log entry, and repeat the pre-diagnostic checklist.
Preventive Measures
- Maintain a golden image of the engineering PC using the Siemens Field PG factory image or a sysprep-captured reference. The image should include the matching STEP 7 version, the matching .NET / SQL Server build, the SIMATIC NET drivers, the Automation License Manager, and the UAC-disabled security policy.
- Store all
.s7parchives on a local SSD, not on OneDrive, Dropbox, or a CIFS share with opportunistic locking enabled. - Exclude
C:\Siemens,C:\Program Files\Siemens, and the project directories from Windows Defender and any EDR product. - Reorganize and Save As a project at every major revision. A clean
.s7parchive is the single most effective defense against project-side 65549 errors. - Document the engineering PC hardware (manufacturer, model, OS build, STEP 7 SP level, ALM version) in the plant's PLC asset register so that field replacements can be reproduced without trial and error.
Frequently Asked Questions
What does STEP 7 internal error 65549 actually mean?
It is a generic HRESULT-style fault returned by the S7 communication layer (S7DOS / S7ONLINE) when the download sequence cannot complete. The "13:4046" prefix identifies the STEP 7 sub-step that failed. The root cause is almost always in the engineering PC (corrupted installation, blocked transport, Windows security) rather than the PLC.
Do I have to reinstall STEP 7 to clear the error?
Not always. Start with Save As → Reorganize (slow) and a privilege check (Run as administrator, DCOM, UAC). Reinstall only if the project is known good and the PC environment still produces 65549. A repair install replaces the runtime DLLs; a clean install is the last resort.
Is 65549 the same in STEP 7 V5.x and TIA Portal?
Yes – the same S7ONLINE / S7API stack backs both, so the same number appears in SIMATIC Manager and in the TIA Portal download dialog. The TIA Portal typically frames it as "Internal error 65549 – Download to device failed" and adds the offline/online device fingerprints in the details pane.
Can a firewall or antivirus cause internal error 65549?
Yes. Windows Firewall, Symantec Endpoint Protection, CrowdStrike, and similar products that block S7DOS.exe, the ISO-on-TCP port 102, or the SQL Server instance used by S7-DB will surface as 65549 because the resource manager cannot bind the transport. Add the STEP 7 installation directory and the project directory to the EDR exclusion list.
Which STEP 7 version should I install on a new Windows 11 PG?
Install STEP 7 V5.7 (or later) on Windows 10 1909 and above. STEP 7 V5.5 / V5.6 will install on Windows 10 1809 only with the official compatibility patch. The version is recorded in the Siemens Industry Online Support compatibility matrix and in the readme of the installation media.