S7-1200 Basic HMI Sm@rtServer: Mirror and Remote Access Setup

David Krause16 min read
HMI / SCADASiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview: Local Mirror vs. Remote Access on S7-1200 + Basic HMI

The SIMATIC S7-1200 paired with a SIMATIC Basic Panel (KTP400 / KTP700 / KTP900 / KTP1200 Basic) is the workhorse of the small-machine segment. When the same machine must be supervised from a second room, an office, or a remote site, two architectural paths exist, and they have very different hardware, licensing, and security implications.

Local mirror means a second Basic Panel - or a Soft Client on a PC - on the same industrial Ethernet subnet displays (and optionally operates) the screens of the source panel. This is implemented with the panel's built-in Sm@rtServer. No router, no VPN, no internet. The TCP traffic stays on PROFINET/Ethernet.

Remote access means the second client sits behind a WAN, a cellular router, or the public internet. The recommended Siemens path is SINEMA Remote Connect (SRC), a VPN concentrator that brokers IPsec tunnels between the source panel site and the client site. The license family referenced in the field for SRC is 6GK1720-0AP02 (and its variants); it is loaded on the SINEMA server and clients connect over an encrypted tunnel.

This reference walks through the local mirror in step-by-step detail, then summarizes the remote-access add-on so you can decide whether you need a second panel, a Soft Client, or a full SRC deployment.

Important architectural fact: Sm@rtServer runs inside the panel, not the PLC. The S7-1200 only carries the HMI tag data over PROFINET. The Sm@rtServer feature therefore depends on the panel's runtime, not the CPU firmware.

2. Licensing Requirements: Sm@rtServer Across TIA Portal Versions

License handling for Sm@rtServer changed twice in the TIA Portal history. The table below shows the matrix that matters when you plan a project today.

TIA Portal Version Panel Family External License Required? Where the Option Lives
V13 SP1 / V14 Comfort (KTP400/700/900/1200 Comfort, TP1500/1900/2200 Comfort) Yes - one license per panel that hosts Sm@rtServer Panel properties > Sm@rtServer
V15 / V15.1 / V16 Comfort Panels No - bundled with the panel runtime Panel properties > Sm@rtServer
V17 / V17 Update 1+ Basic Panels (KTP400 Basic, KTP700 Basic, KTP900 Basic, KTP1200 Basic) No - bundled with the panel runtime Panel properties > Sm@rtServer
V18 / V19 / V20 Basic + Comfort Panels No - bundled with the panel runtime Panel properties > Sm@rtServer

Operating consequence: if you are on TIA V17 or later (including V20) and you are running Basic Panels, you do not need to purchase a Sm@rtServer license. Enable the option in the TIA project, rebuild, and download to the source panel. The client side (mirror panel or Soft Client) does not require a separate license either.

If you are still on V14, you must transfer a Sm@rtServer license onto the panel via the Automation License Manager (ALM). Each panel that hosts a Sm@rtServer needs its own license ticket. Comfort Panel Sm@rtServer license article numbers historically belong to the 6AV2181-8XX00-0AX0 series; verify the current MLFB in the Siemens ST 80 / ST 80 PC catalog or the Industry Online Support portal at support.industry.siemens.com.

Field tip: the Sm@rtServer license is not the same as a client access license. From V15/V17, both the host role and the client role are license-free on Comfort/Basic Panels. Older V14 projects that get migrated may show "missing license" warnings on download - clear the warning in the project tree after the migration rebuilds the panel object.

3. Hardware and Network Prerequisites

Component Minimum / Recommended Purpose
S7-1200 CPU CPU 1214C, 1215C or 1217C with firmware matched to the TIA version (FW 4.4 for V17, FW 4.5 for V18, FW 4.6 for V19/V20) Holds the control program and exchanges HMI tags
Source Basic Panel KTP700 Basic, KTP900 Basic, KTP1200 Basic (PN mono or color, second generation) Hosts Sm@rtServer; serves the active project to the client
Mirror / Client Panel Same family as the source, or a PC running WinCC Runtime Professional / TIA Multipanel Runs the Sm@rtServer client; renders the same screen
Network 10/100 Mbps Ethernet switch, full duplex, Cat 5e or better Carries PROFINET HMI traffic and Sm@rtServer (TCP port 102 by default)
Remote add-on SINEMA Remote Connect server (SCALANCE M876 or MUM85x), 6GK1720-0AP02 license IPsec VPN termination for cross-site access

Sm@rtServer does not impose a strict bandwidth ceiling. The screen-update stream averages 1-2 Mbps per active client with a typical KTP700 screen at 5 Hz update. A 100 Mbps switch supports dozens of simultaneous viewers. The dominant constraint is latency:

Round-Trip Latency Operator Experience
< 1 ms (local Ethernet) Indistinguishable from the source panel
1-50 ms (campus LAN) Excellent
50-150 ms (cellular / broadband) Acceptable for monitoring; sluggish for fast bit toggles
150-300 ms Usable for monitoring only
> 500 ms (geostationary satellite) Not usable for Sm@rtServer operation

Reference: see the SIMATIC HMI Basic Panels product page at siemens.com - Basic Panels for the current hardware catalog and firmware matrix.

4. Project Configuration: Enabling Sm@rtServer on the Source Basic Panel

These steps assume TIA Portal V17 or later and a Basic Panel. Older V14/V15 projects follow the same logic but include the license transfer step described in section 2.

  1. Open the TIA project that contains the S7-1200 CPU and the source Basic Panel.
  2. Select the source panel in the project tree.
  3. Open Properties > General > Sm@rtServer (the path appears as Runtime settings > Sm@rtServer in older TIA releases).
  4. Tick "Enable Sm@rtServer". From V17 the option is always license-free on Basic Panels; no warning dialog appears.
  5. Configure the connection parameters:
    • Port: 102 (default) or any free TCP port above 1024 if 102 is occupied. Keep 102 unless you have a documented reason to change it; some plant firewalls only let 102 through.
    • Password / operator authorizations: set a strong password. Sm@rtServer must be password-protected in any plant that leaves the panel connected to a routable network.
    • User management: map the panel's local user accounts to Sm@rtServer roles if you want the client to authenticate with the same operator rights as a local operator.
  6. Compile (rebuild all) and download the project to the source panel.
  7. On the panel, open Control Panel > Sm@rtServer and verify the service is active. The status should read Started and show the configured port.
Watch out: when you enable Sm@rtServer for the first time, the panel restarts the runtime. Schedule a 60-90 s maintenance window or accept a brief screen blank. A redownload of the project also resets the operator passwords - export the user list first if needed.

5. Wiring and IP Addressing: Local Mirror Within a Subnet

For a second room on the same plant floor, a single unmanaged switch is enough. The addressing example below is for an isolated machine subnet that can be replicated 1:1 across your facility.

Device IP Address Subnet Mask Default Gateway Role
S7-1200 CPU 1214C 192.168.0.1 255.255.255.0 192.168.0.254 PLC
Source Basic Panel (KTP700) 192.168.0.10 255.255.255.0 192.168.0.254 Sm@rtServer host
Mirror Basic Panel (KTP700) 192.168.0.11 255.255.255.0 192.168.0.254 Sm@rtServer client
Optional Soft Client PC 192.168.0.12 255.255.255.0 192.168.0.254 Sm@rtServer client
Managed switch (SCALANCE XB or third-party) 192.168.0.254 255.255.255.0 - Default gateway + L3 router

Wire the S7-1200 PROFINET port, the source panel, and the mirror panel into the same switch. The S7-1200 and source panel remain the same devices they were before; you only add a third PROFINET node for the mirror panel. No changes to the PLC program are required - Sm@rtServer traffic sits on top of the existing HMI connection and uses a separate TCP session on port 102.

If the second room is more than 100 m away from the source, run single-mode fiber with a SCALANCE media converter pair (e.g., SCALANCE XC-100 with SFP) or use a SCALANCE switch with a built-in fiber uplink. Do not bridge the gap with a consumer wireless extender; the latency jitter and packet loss will degrade Sm@rtServer performance even when the average bandwidth is fine.

VLAN note: if the corporate IT network and the plant network share the same physical switch fabric, place Sm@rtServer traffic in a separate VLAN and apply a firewall rule. The S7-1200's PROFINET interface is not a firewall; it will forward anything that reaches its MAC address.

6. Configuring the Sm@rtServer Client on the Second Panel

The client side is configured independently of the source. You do not have to load the source's HMI program onto the client; the client only needs a small Sm@rtClient project that points at the source.

  1. Create a new KTP700 Basic device in the TIA project (or open the existing client project if you already have one).
  2. Open the device configuration of the client panel.
  3. Navigate to Runtime settings > Sm@rtServer > Connections (the path appears as Sm@rtClient depending on TIA version).
  4. Add a new connection:
    • Connection name: descriptive, e.g., Mirror_FillerRoom.
    • Sm@rtServer address: IP of the source panel (192.168.0.10 in the example).
    • Port: 102 (must match the source panel).
    • Display mode: Sm@rtServer for full screen + operation; Sm@rtServer (read-only) if you only want monitoring.
    • User / password: match an account on the source panel.
  5. Set the start screen of the client to the Sm@rtServer connection. The client immediately renders the source panel's active screen on power-up.
  6. Compile and download the project to the client panel.
  7. On the client panel, verify the Sm@rtClient screen shows the same content as the source. Test operator buttons to confirm write-back works.

Optional refinements:

  • Configure a startup delay on the client (5-10 s) so the source panel finishes booting before the client tries to connect. Otherwise the client logs repeated connection errors during panel startup.
  • If the second panel sits in a noisy environment, enable the source panel's "Audit Trail" so you can later prove who pressed what on which client.
  • Set the client's screen saver delay to 30 minutes or longer; the default 5-minute screensaver can confuse operators who expect the source to stay visible.

7. Remote Access with SINEMA Remote Connect (6GK1720-0AP02)

If the second room is in another building across a public road, or if the maintenance technician needs to view the panel from home, the safe path is SINEMA Remote Connect - a Siemens VPN concentrator that brokers IPsec tunnels between the plant floor and remote clients.

Plant Floor S7-1200 192.168.0.1 KTP700 Src 192.168.0.10 SCALANCE M SRC client Plant LAN 192.168.0.0/24 IPsec tunnel DMZ / Office SINEMA RC Server 6GK1720-0AP02 license ALM activation Remote Client PC Sm@rtClient via VPN

Components:

  • SINEMA RC Server (typically a SCALANCE M876 or a virtual appliance on a server-class machine). Holds the user accounts and the license tickets.
  • 6GK1720-0AP02 license family. Load it on the SINEMA server with the Automation License Manager. The license determines the number of concurrent tunnels and the number of users.
  • SCALANCE M (or MUM) client on the plant side establishes the IPsec tunnel outbound to the SINEMA server. SCALANCE M-series routers include the SINEMA RC client firmware.
  • Sm@rtServer on the source panel stays the same; only the network path changes.
  • Sm@rtClient on the remote PC connects to the SINEMA RC, which then forwards traffic to the panel.

Commissioning steps (summary):

  1. Install SINEMA RC Server, accept the EULA, set the administrator password.
  2. Import the 6GK1720-0AP02 license. The number of allowed parallel users appears on the SINEMA dashboard.
  3. Create a user account for the remote operator and assign a Tunnel role.
  4. Configure the SCALANCE M on the plant side as a SINEMA RC client: enter the SINEMA server address, the plant's group name, and the shared key.
  5. Verify the tunnel is up: the SCALANCE M shows a green status LED and the SINEMA dashboard lists the device as Connected.
  6. From the remote PC, launch the Sm@rtClient application and enter the source panel's IP. The SINEMA RC server proxies the connection through the tunnel.
Security: never expose Sm@rtServer directly to the public internet by means of port-forwarding. A direct TCP/102 forward is equivalent to publishing the panel's operator controls to the entire internet. SINEMA Remote Connect puts the panel behind a managed, authenticated IPsec tunnel that the operator cannot reach without a valid credential. Reference: Siemens security advisories on the Industry Online Support portal at support.industry.siemens.com.

Bandwidth check: a single Sm@rtServer stream over an IPsec tunnel typically consumes 2-4 Mbps when the screen updates frequently. A 10 Mbps internet uplink is comfortable; 5 Mbps is the lower limit before the user experience degrades. The IPsec overhead adds about 10-15% to the raw stream size, so size the uplink accordingly.

8. PC-Based Soft Client Option (WinCC RT Professional)

If a second physical panel is overkill for a second room, the same Sm@rtServer role can be served by a Windows PC running WinCC Runtime Professional (or the older WinCC flexible RT). The PC mounts a "panel" of the matching resolution and runs the Sm@rtClient as a regular screen. This is useful when the second station is a supervisor's office, not a production floor.

Configuration steps:

  1. Install the TIA version of WinCC RT Professional on the PC.
  2. Transfer the TIA project, then open the PC station in the project tree.
  3. Add a Sm@rtClient connection pointing at the source panel's IP.
  4. Activate the runtime. The PC's monitor shows the same screen as the panel.

Advantages over a second panel: no additional hardware cost, no extra PROFINET node, full keyboard and mouse input, easier to log and audit. Disadvantages: requires a Windows license and a current WinCC RT license, and a PC on a production floor is a maintenance liability compared to an industrial panel.

9. Commissioning Verification Checklist

  1. Source panel is up. The Sm@rtServer status on the source panel's Control Panel reads Started, and the configured port (102) is listed.
  2. Source panel responds to ping from the client panel (or from the SCALANCE M on the SRC network). ping 192.168.0.10 from the client.
  3. Client panel connects. After download, the client panel automatically displays the source panel's start screen within 5-10 s of being online.
  4. Operator input round-trip works. On the client panel, press a bit button. The bit toggles in the PLC, the indicator updates, and the source panel reflects the change within one second.
  5. Authentication works. If the Sm@rtServer requires a password, log out from the source panel and verify the client panel prompts for credentials.
  6. Failover test. Disconnect the network cable on the source panel. The client panel must show a defined error (typically a yellow Connection lost banner), not a runtime crash.
  7. Restore. Reconnect the cable. The client panel should reconnect within 10-15 s without operator intervention.
  8. Audit log check. Open the source panel's audit trail and confirm operator actions from the client are recorded with the correct timestamp and source IP.

10. Troubleshooting Matrix

Symptom Likely Cause Diagnostic Remedy
"Sm@rtServer not available" on the source panel's Control Panel Sm@rtServer not enabled in the TIA project, or runtime image does not include the option Check TIA project: Properties > Sm@rtServer > Enable Enable the option, rebuild, re-download the runtime
Client shows "Connection failed" on startup Wrong IP, wrong port, or different subnet without a gateway Ping source panel from client subnet; check Control Panel > Network > IP on both panels Correct IP, align subnet masks, or add a default gateway
Client connects, screen is blank or frozen Source panel runtime is still booting, or project on source was changed and not yet downloaded Check source panel screen manually; check last download timestamp in TIA Wait 30-60 s after source panel boot; re-download the project
Operator inputs from the client are ignored Client is configured as "Sm@rtServer (read-only)" Open client project > Sm@rtServer connection > mode Switch mode to "Sm@rtServer" (read/write) and re-download
License warning on download (TIA V14 only) Sm@rtServer license missing on the source panel Check ALM for valid ticket on the panel Transfer the Sm@rtServer license to the panel via ALM
Slow screen updates over a cellular link Bandwidth or latency limit on the WAN Measure RTT with ping; check signal strength Reduce update rate; upgrade the cellular plan; switch to SINEMA RC
SINEMA RC tunnel does not come up SCALANCE M cannot reach the SINEMA server (firewall, DNS, NTP) Check the SCALANCE M's event log; check SINEMA server reachability from the WAN Open outbound UDP 500 / 4500 and TCP 443; verify the SCALANCE M has a valid certificate
Remote client connects, but the screen is grayscale or missing graphics Runtime image on the source panel does not match the project on the client Compare TIA versions used to build both projects Re-build the client project with the same TIA version as the source
Two operators write to the same tag at the same time No area lockout or key-switch in the project Check the operator authority configuration on the source panel Assign area-specific rights or install a hardware key-switch

11. Security Hardening and Operational Notes

Sm@rtServer exposes the panel's operator surface to any TCP client that can reach the port. Treat that port as a control-system boundary and harden it before going live.

  • Always set a password on the Sm@rtServer connection. Leave the default blank only on isolated test benches.
  • Bind Sm@rtServer to a specific PROFINET interface if the panel has more than one network port. Do not allow both LAN and the corporate network to reach the service.
  • Restrict the source IP range in the panel firewall (V17+ supports an integrated IP allowlist under Control Panel > Security > Firewall).
  • Do not port-forward TCP/102 on a perimeter router. The pattern "open Sm@rtServer to the internet" is the most common path to a compromised HMI in the field.
  • Use SINEMA Remote Connect for any cross-site access. The 6GK1720-0AP02 license is cheaper than one unplanned shutdown from a tampered HMI.
  • Log operator actions on the panel via the audit trail. Sm@rtServer sessions can be filtered by IP in the audit log.
  • Update firmware on the panels and the SCALANCE devices at the maintenance cycle. Siemens publishes advisories under Siemens Security Advisories (SSA) on the Industry Online Support portal.
  • Document the change. Adding a mirror panel is a topology change; update the network diagram and the PLC/HMI asset register.
Lifecycle: Basic Panels second generation (KTP700 / KTP900 / KTP1200 Basic from 2016 onwards) and the matching Comfort Panels are the current shipping hardware that supports Sm@rtServer without extra license. First-generation Basic Panels (KTP600 Basic mono) do not support Sm@rtServer; replace them if mirroring is required.

Frequently Asked Questions

Do I still need a Sm@rtServer license on a KTP700 Basic running TIA V20?

No. From TIA Portal V17, Sm@rtServer is enabled by default on SIMATIC Basic Panels (KTP400, KTP700, KTP900, KTP1200 Basic) without any extra license. The same is true for Comfort Panels from V15. Enable the option in the panel's properties, download the project, and the Sm@rtServer entry appears in the Control Panel.

Can I use Sm@rtServer without internet access - just on the shop floor LAN?

Yes. Sm@rtServer is a TCP/IP service (default port 102). Connect the source panel and the client panel to the same PROFINET/Ethernet switch on a common subnet, configure the Sm@rtServer connection in the client, and you can mirror or operate the HMI from a second station without internet or VPN infrastructure.

Which S7-1200 firmware do I need for Sm@rtServer on a Basic Panel?

Sm@rtServer runs in the panel, not the PLC. The PLC only exchanges HMI tag data over PROFINET. Use a CPU 1214C, 1215C or 1217C with the firmware that matches the TIA version you are using (firmware 4.4 for TIA V17, 4.5 for V18, 4.6 for V19/V20). The panel must run a runtime image that matches the TIA version used to build the project.

What is the 6GK1720-0AP02 license used for?

The 6GK1720-0AP02 is a Siemens SIMATIC NET license that belongs to the SINEMA Remote Connect family. It is required when the Sm@rtServer client must traverse a secure IPsec tunnel to reach a panel across a WAN or another city, instead of a local Ethernet segment. The license is loaded on the SINEMA Remote Connect server with the Automation License Manager; clients then connect through the encrypted tunnel.

Can I operate the source HMI from the mirror HMI?

Yes. Sm@rtServer on Basic Panels supports both monitoring and full operator control. The mirror (client) panel sends input events back to the source panel over the same TCP connection. Be aware of shared operator responsibility - two operators writing setpoints on the same tag at the same time is undefined; apply a key-switch or area lockout in the HMI project if needed.

Back to blog