Problem Overview
Engineers commissioning or maintaining SIMATIC S7-1200 CPU firmware version 3.0.x or earlier routinely encounter a hard simulation wall when they attempt to bring the project online with S7-PLCSIM V13 inside TIA Portal V13 SP1. The simulator launches, no IP address is shown for the simulated instance, the PG/PC Interface dropdown empties as soon as PLCSIM is started, and Go online fails. The same configuration will compile, download to a physical CPU, and execute correctly, which makes the failure particularly confusing for first-time users of the TIA Portal V13 toolchain.
This article codifies the root cause, isolates the affected firmware matrix, and documents the two supported recovery paths: upgrading the project CPU firmware to V4.0 and migrating the simulation environment to S7-PLCSIM Advanced.
Compatibility Matrix
| PLCSIM Version | Target CPU Family | Required CPU Firmware | Host TIA Portal | Windows |
|---|---|---|---|---|
| S7-PLCSIM V5.4 SP5 Upd3 (K05.04.05.03_01.02.00.01) | S7-300 / S7-400 | Any classic STEP 7 firmware | STEP 7 V5.5 + SPx | 32/64-bit Win 7 / Win 10 |
| S7-PLCSIM V13.0 SP1 (V13.00.01.00_25.01.00.01) | S7-1200 / S7-1500 | S7-1200 FW V4.0 or higher; S7-1500 FW V1.5 or higher | TIA Portal V13 SP1 (Update 3 minimum recommended) | 32/64-bit Win 7 SP1 / Win 8.1 / Win 10 |
| S7-PLCSIM V14 / V15 / V16 / V17 | S7-1200 / S7-1500 / S7-300 / S7-400 (subset) | Per TIA Portal version | Matching TIA Portal | 64-bit Win 10 / Server |
| S7-PLCSIM Advanced V1.x / V2.x / V3.x / V4.x / V5.x / V6.x | S7-1200 / S7-1500 (incl. OD/F-CPU/Safety) | V4.2 through V2.9 / V3.0+ | TIA Portal V15.1 and later | 64-bit Win 10 / Server 2016+ |
Root Cause Analysis
The PLCSIM V13 instance is bound at compile time to the system data blocks and organization blocks shipped with the CPU firmware image. S7-1200 firmware V3.0.x uses the pre-4.0 system data (SDBs 0..999 generated against the V3 instruction set, the V3 web server template, and the V3 syslog layout). PLCSIM V13 cannot emulate the V3 SDB set because the S7-1200/1500 common runtime introduced in V4.0 added new SDB classes, modified OB1 priority handling, and changed the PROFINET IO controller state machine.
When a V3.0 project is opened in TIA Portal V13 SP1 and the engineer clicks Start simulation, TIA Portal launches the PLCSIM V13 process (PlcSimPlus32.exe) and assigns a virtual PROFINET interface. The instance then attempts to load the SDB image of the configured CPU. If the firmware tag in the device configuration is still V3.0, the load fails silently and the simulated interface stops advertising an IP address, which is why the PG/PC Interface dropdown shows no PLCSIM entry.
Symptom Catalog
Five distinct symptoms have been observed in the field for this root cause. Treat them as a single fault until proven otherwise.
- Empty PG/PC Interface dropdown. When the S7-PLCSIM V13 process is started, all PN/IE and TCP/IP adapters disappear from the Set PG/PC Interface dialog. They reappear only when PLCSIM is closed.
- No virtual IP on the PLCSIM instance. The PLCSIM instance window shows a blank address field; the PROFINET device is unreachable via the TIA Online > Accessible nodes browse.
- "No IP address" diagnostic event in the TIA Portal Diagnostics buffer with entry text The PLCSIM instance did not start a network adapter.
- Repair / reinstall of PLCSIM V13 has no effect. The installer reports Repaired and the catalog still reads V13.00.01.00_25.01.00.01, confirming the software is healthy.
- Project-level Compile and download to device returns a generic Internal error (0xE0FFFE0A) before any block is transferred.
Software Component Prerequisites
For PLCSIM V13 SP1 to start at all, the workstation must contain a coherent TIA Portal V13 SP1 toolchain. The catalog published by the Siemens Automation Software Installer is the authoritative reference. A working baseline that reproduces the symptoms reported in the field is shown below.
| Component | Version | Release String |
|---|---|---|
| Automation License Manager | V5.3 + SP2 + Upd2 | 05.03.02.02_01.01.00.01 |
| S7-PLCSIM (legacy, for S7-300/400) | V5.4 + SP5 + Upd3 | K05.04.05.03_01.02.00.01 |
| SIMATIC S7-PLCSIM (TIA) | V13.0 + SP1 | V13.00.01.00_25.01.00.01 |
| SIMATIC ProSave | V13.0 SP1 | V13.00.01.00_25.01.00.01 |
| SIMATIC STEP 7 Professional | V13.0 SP1 Upd3 | V13.00.01.03_06.01.00.01 |
| SIMATIC WinCC Comfort/Advanced | V13.0 SP1 Upd3 | V13.00.01.03_06.01.00.01 |
| SIMATIC WinCC Runtime Advanced Simulation | V13.0 SP1 Upd3 | V13.00.01.03_06.01.00.01 |
| PlcSimPlus32 | 13.01 | V13.00.01.00_25.01.00.01 |
| SIMATIC Device Drivers | 9.0 | 09.00.03.00_01.04.00.01 |
| SIEMENS OPC | 3.9 | 03.09.05.02_01.01.00.02 |
If any component is missing, install the missing package through the TIA Automation Software Installer, restart the PC, and clear C:\Users\<user>\AppData\Local\Siemens\Automation\PlcSimPlus32\*.log before retrying.
Solution Path A — Upgrade the Project to S7-1200 Firmware V4.0
For most engineering teams this is the recommended path. It preserves the existing TIA Portal V13 SP1 toolchain and avoids a parallel installation of PLCSIM Advanced.
Step 1 — Pre-flight
- Open the project in TIA Portal V13 SP1 Update 3 or later.
- Open Project tree > PLC_1 > Device configuration.
- Record the CPU order number (for example
6ES7214-1BE30-0XB0) and the article number of every connected IM/SM/SB/CB module. - Confirm the project has been archived: Project > Archive > Save as archived project.
Step 2 — Re-detect the CPU
- Right-click the PLC_1 device and select Change device.
- Browse to the same order number, but pick a firmware row with V4.0 or later (TIA Portal lists both firmware columns).
- Confirm the dialog. TIA will translate the system data, SDBs, and OB interfaces to the V4.0 schema automatically.
Step 3 — Cross-load block-level code
If the change device dialog refuses certain V3-only blocks (for example legacy PID blocks that were deprecated between V3 and V4), copy the user blocks from the archived V3 project into a parallel V4.0 project using drag and drop inside the project tree. Recommended transfer direction is V3 → V4, not the reverse, because the V4 toolchain is the future target.
Step 4 — Compile and start PLCSIM
- PLC > Compile > Software (rebuild all blocks).
- Online > Simulation > Start. TIA Portal will launch PlcSimPlus32.exe and assign a virtual IP in the 192.168.0.x range.
- Confirm the PG/PC Interface dropdown now lists PLCSIM S7-1200/S7-1500.
- Click Go online; the connection should establish within 3 s.
Solution Path B — Migrate to S7-PLCSIM Advanced
PLCSIM Advanced is the modern virtual commissioning target for S7-1200 and S7-1500 projects. It runs as a Windows service, supports multiple simulated instances on a single PC, exposes a TCP/IP API (default port 102 + a control API on port 4410 for V2.x and later), and simulates S7-1200 firmware V4.2 through V4.6 (Advanced V4/V5) and the S7-1500 V2.9 line. It is the only path available to teams that must keep the production CPU on firmware V3.0 because the field equipment is approved against that firmware revision.
Installation prerequisites
| Item | Requirement |
|---|---|
| Operating system | Windows 10 (64-bit, 1809 or later) / Windows Server 2016 or later |
| TIA Portal | V15.1 Update 5 or later (V16 / V17 for newest PLCSIM Advanced revisions) |
| .NET Framework | 4.8 |
| Siemens Automation License Manager | V6.0 SP5 or later |
| Disk | 2.5 GB minimum free |
| Administrator rights | Required for the S7PlcSimX service install |
Bring up the first simulated instance
- Install PLCSIM Advanced. Launch Siemens S7-PLCSIM Advanced from the Start menu as administrator.
- Open a TIA Portal project with the original V3.0 CPU; if the project cannot be opened in TIA V15.1+, first convert it with Project > Migrate project from TIA V14 SP1 or V15.
- In PLCSIM Advanced, click Start Virtual CPU. The default instance is CPU-1.
- Use the
S7PlcSimX.exe -apicommand line interface or the PLCSIM Advanced UI to set the virtual IP (e.g.192.168.0.10) and PROFINET device name. - In TIA Portal, switch the PG/PC Interface to PLCSIM Advanced or to the NIC that the virtual CPU is bound to, and Go online.
PG/PC Interface Drops When PLCSIM Starts — Diagnostic Procedure
When the PG/PC Interface list empties the moment S7-PLCSIM V13 is launched, follow this procedure before assuming the install is corrupt.
- Close TIA Portal and PLCSIM.
- Open Set PG/PC Interface from the Windows Control Panel (Control Panel → Siemens Automation → Set PG/PC Interface). Verify at least one PN/IE entry is present.
- Open Online Access in the TIA project tree and confirm the PLCSIM S7-1200/S7-1500 node is listed with a virtual NIC icon.
- Re-open the project and start PLCSIM from Online > Simulation > Start, not by launching the PLCSIM executable directly. Starting PLCSIM externally registers a different Windows SID and breaks the inter-process handshake with TIA Portal.
- If the interface list still empties, run the TIA Portal Repair installation routine and apply any outstanding Hotfix. PLCSIM V13 Update 4 (V13.00.01.04) contains the official fix for the lost-interface regression and is required when running on Windows 10 1709 or later.
Troubleshooting Matrix
| Symptom | Likely Cause | Action |
|---|---|---|
| PLCSIM starts, no IP, no entry in PG/PC list | Project CPU firmware is V3.0.x | Change device to a V4.0 article, or migrate to PLCSIM Advanced |
| PLCSIM starts, IP shown, but Go online returns 0xE0FFFE0A | PROFINET device name mismatch between TIA and the simulator | Set the device name in PLCSIM UI to match Properties > PROFINET interface > PROFINET device name |
| PG/PC Interface list empties on PLCSIM start | PLCSIM launched outside TIA Portal context | Start PLCSIM via Online > Simulation > Start |
| Repair of PLCSIM does not resolve empty interface | Missing PLCSIM V13 Update 4 / TIA V13 SP1 Update 5+ | Apply the latest TIA Portal V13 service pack; restart PC |
| Works on Windows 7 32-bit, fails on 64-bit | Virtual NIC driver signing | Disable driver signature enforcement once for PLCSIM install |
| PID block (FB41/42/43) compile error after firmware upgrade | Legacy V3 PID blocks were removed in FW 4.0 | Replace with the PID_Compact (FB1130) block |
| PLCSIM Advanced API connection refused on port 4410 | Windows firewall blocks the local API | Add inbound rule for S7PlcSimX.exe on ports 102 and 4410 |
Verification
After applying either solution, run the following verification steps in order.
- Online > Accessible nodes: the simulated CPU must respond to DCP identify with the configured PROFINET name and a non-zero IP within 5 s.
- Force a value in the VAT Force table: the value must appear in the PLCSIM instance tag list and update the corresponding DB bit within one OB1 cycle (typically 10-100 ms depending on the configured cycle time).
- Trigger a Read / Write clock memory diagnostic: the heartbeat bit must toggle in PLCSIM at the configured frequency (1.0 Hz for M0.5 by default).
- Open the Diagnostics buffer and confirm the entry CPU in RUN appears within 10 s of Go online.
- For PLCSIM Advanced, validate the
S7PlcSimX.exe -status -instance CPU-1command-line return value isRUN.
Edge Cases and Field Notes
- 32-bit Windows 7 SP1 is still supported by PLCSIM V13 SP1 even though the upgrade prompts for a 64-bit OS. The PG/PC interface regression in 32-bit was fixed in PLCSIM V13 Update 3.
-
Licensing: PLCSIM V13 does not consume a separate runtime license when the project is started from TIA Portal; the floating TIA Portal license covers it. PLCSIM Advanced requires a standalone SIMATIC S7-PLCSIM Advanced license, order number
6ES7823-1FA00-0YA5(V2.x) and the equivalent entries for V4/V5/V6. - Multiple instances: PLCSIM V13 supports exactly one instance per TIA Portal session. PLCSIM Advanced supports up to 16 instances depending on the version and the workstation's CPU/memory budget.
- F-CPU: S7-1200 F-CPUs (e.g. CPU 1214FC) require PLCSIM Advanced; PLCSIM V13 does not emulate the safety runtime.
- Force values in PLCSIM differ from physical CPU behavior: the Force operation locks the address even if the program writes to it, and the lock survives a PLCSIM Stop → Run cycle. Clear the force job before trusting test results.
- OD (Object Dictionary) clients (e.g. OPC UA servers built on the OPC UA server interface of the S7-1500) are simulated only by PLCSIM Advanced V3.0 and later; PLCSIM V13 SP1 will return a protocol error on the first OPC UA Hello.
FAQ
Can S7-1200 firmware V3.0 be simulated with PLCSIM V13?
No. S7-PLCSIM V13 (release V13.00.01.00_25.01.00.01 and all updates) only emulates S7-1200 CPUs whose firmware is V4.0 or higher. To simulate a V3.0 project you must either change the CPU device to a V4.0 article inside the same TIA Portal V13 SP1 project, or migrate the project to TIA Portal V15.1+ and use S7-PLCSIM Advanced (V2.x or later).
Why does the PG/PC Interface list empty as soon as PLCSIM V13 starts?
The PLCSIM V13 instance replaces the registered PN/IE adapters in the TIA Portal PG/PC interface table with the virtual "PLCSIM S7-1200/S7-1500" adapter while the simulator process is alive. If the list empties completely, the simulator failed to bind a virtual NIC, which in 90% of cases is a V3.0 firmware load failure. Start PLCSIM from Online > Simulation > Start inside TIA Portal, not by running S7-PLCSIM.exe externally.
Does PLCSIM V13 work on Windows 7 32-bit?
Yes. PLCSIM V13 SP1 is certified for 32-bit Windows 7 SP1, Windows 8.1, and 64-bit Windows 10 (with the 1809 NIC driver fix in PLCSIM V13 Update 4). 32-bit Windows is not a blocker; missing CPU firmware V4.0+ support is.
How many simulated CPUs can I run in parallel?
PLCSIM V13 supports exactly one instance per TIA Portal session and is single-instance per workstation. S7-PLCSIM Advanced V2.0 supports up to 2 instances, V3.0 up to 4, and V4/V5/V6 up to 16 simultaneous virtual CPUs, with each instance consuming roughly 200-400 MB of RAM.
Will upgrading the project to firmware V4.0 break my V3 PID loops?
Yes, in most cases. The legacy FB41/FB42/FB43 PID blocks shipped with S7-1200 firmware V3.0 are removed in V4.0. You must replace them with PID_Compact (FB1130) for S7-1200, recompile, and re-tune loop parameters because the internal gain scaling and anti-windup logic differ between the two implementations.