S7-1200 Webserver Bit Change Failed: Admin Login Fix

David Krause10 min read
S7-1200SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

A common complaint when commissioning the S7-1200 standard web server with user-defined pages is that monitored values render correctly in the browser yet the operator cannot toggle a bit or write an integer back to the CPU. Symptoms include:

  • Numeric tags refresh in real time on the user-defined page (polling visible).
  • Clicking a write button, slider, or text-input submits the form but the tag never updates in TIA Portal watch table or online monitoring.
  • No PLC diagnostic buffer entries are produced; no SF/BF LED activity changes.
  • Behavior is identical across Google Chrome, Microsoft Edge, and Internet Explorer 10/11.

This fault is reported on the 6ES7 214-1AG31-0XB0 (CPU 1214C DC/DC/DC) with firmware V3.0.2 after installing the Siemens example project "Web Server - Creating and using user-defined web pages on S7-1200" (Siemens Support entry ID 58862931). The root cause is not a defective AWP page, not a browser defect, and not a hardware defect. The CPU is enforcing its role-based access model correctly; the HTML page is being served to an anonymous session that has read-only rights.

Affected Hardware and Firmware

CPU Order Number Model FW Tested Behavior
6ES7 214-1AG31-0XB0 CPU 1214C DC/DC/DC V3.0.2 Anonymous read, writes silently rejected
6ES7 214-1BG31-0XB0 CPU 1214C AC/DC/RLY V3.0.2 Same
6ES7 215-1AG31-0XB0 CPU 1215C DC/DC/DC V3.0.x Same
6ES7 211-1AE31-0XB0 CPU 1211C DC/DC/DC V3.0.x Same
Any S7-1200 CPU 121xC / 1215C / 1217C V4.0 – V4.6 Same unless "Permit access with PUT/GET" and HTTPS configured

The fault is independent of signal module (SM), communication processor (CP), or signal board (SB) configuration. Adding SMs does not change the access policy.

Root Cause Analysis

The S7-1200 web server uses three privilege levels defined in the CPU's Web server configuration object in TIA Portal:

  1. Anonymous - read-only. Default. Activated automatically when the Web server is enabled.
  2. Standard user - read-only access to additional pages if explicitly granted; cannot write variables.
  3. Administrator ("admin") - read/write to all CPU variables and tags exposed via AWP commands.

When a browser hits the standard web page (http://<cpu-ip>/) without credentials, the session token is anonymous. Any subsequent HTTP GET or POST to a user-defined page (/awp/<file>.html) inherits that anonymous session. The CPU parses the AWP_In_Variable and AWP_Out_Variable tags inside the HTML and answers GETs (reads) with current values, but POSTs that contain an AWP_In_Variable field with the := operator are silently discarded because the session role is not authorized for writes.

Field-proven caveat: The CPU does not return HTTP 401 Unauthorized for the POST. The browser shows the page refreshed with the old value. This silent rejection is the reason the issue looks like a programming bug rather than an authentication issue.

The Siemens S7-1200 System Manual explicitly states that writes from user-defined pages are only permitted after the operator has successfully authenticated against the standard web page. See the Web server chapter in the S7-1200 Programmable Controller System Manual on the Siemens Industry Online Support portal.

Resolution: Enable the Administrative Login

Step 1 - Confirm Web server is activated

  1. In TIA Portal, select the S7-1200 CPU in the project tree.
  2. Open Properties > Web server.
  3. Verify Activate web server on this CPU is checked.
  4. Note the IP address shown under Ethernet interface PROFINET [X1].

Step 2 - Configure the administrator password

  1. In the same Web server dialog, switch to the User management section.
  2. Confirm the user admin exists with role Administrator.
  3. Set a password (8–32 characters, case-sensitive). The firmware V3.0.2 ships with admin no password by default; V4.x and later require a password to be set before the admin role can write.
  4. Compile and download the project to the CPU.

Step 3 - Download the user-defined pages

  1. Right-click the CPU in the project tree and choose Web server > Download user-defined pages.
  2. Confirm the HTML files (e.g., index.html, script.js) are transferred to the CPU's internal load memory under the WWW directory.

Step 4 - Authenticate from the browser

  1. Open a browser and navigate to http://<cpu-ip>/ (the standard Siemens welcome page).
  2. Locate the Log in link on the left navigation pane.
  3. Enter admin as the user name and the configured password.
  4. Wait for the page to confirm successful login (the upper-right corner changes from "Anonymous" to "admin").

Step 5 - Navigate to user-defined page

  1. In the left navigation pane under User-defined pages, click the page link (e.g., index).
  2. Verify the URL now begins with /awp/index.html and that the session cookie siemens_automation_token is present (visible in browser DevTools > Application > Cookies).
  3. Toggle a write control. The tag now updates in TIA Portal watch table within one scan cycle.

AWP Command Reference for User-Defined Pages

Automation Web Programming (AWP) commands are HTML comments parsed by the CPU. The following table summarizes the canonical commands used in the Siemens example project 58862931.

AWP Command Direction HTTP Verb Sample Snippet Notes
:="MotorStart" Read (tag → browser) GET <!-- AWP_Out_Variable Name="MotorStart" --> Replaced with current tag value on each refresh
<form ...> with hidden input Write (browser → tag) POST <form action="" method="POST"><input name='"Speed"' type="text"><input type="submit"></form> Single quotes around name are mandatory
AWP_In_Variable Write (browser → tag) POST <!-- AWP_In_Variable Name="Speed" --> Declares variable as writable
AWP_Enum_Def Symbolic GET <!-- AWP_Enum_Def Name="States" Values="0:Off,1:On" --> Improves readability of integer states
AWP_Start_Sequenz / AWP_End_Sequenz Block POST <!-- AWP_Start_Sequenz -->...<!-- AWP_End_Sequenz --> Groups multiple writes into one request
AWP_Variable_Default Read fallback GET <!-- AWP_Variable_Default Name="Mode" Value="0" --> Used when tag has no value yet
Critical syntax detail: The form input name must use double quotes inside single quotes, e.g., name='"Speed"'. This is the most common reason a write form fails even after a successful login. TIA Portal's HTML parser requires the embedded string exactly.

Implementing a Secure Login Page

From firmware V4.0 onward the CPU supports HTTPS (TLS 1.2) and certificate-based login. V3.0.x only supports HTTP. To harden a V3.0.2 deployment while you still cannot enable TLS, restrict network exposure:

  • Place the CPU on a dedicated VLAN with no Internet egress.
  • Use PROFINET port-based isolation or a managed switch ACL.
  • Set a non-trivial admin password (12+ characters, alphanumeric + symbols).
  • Disable Permit access with PUT/GET (from remote partner) in the CPU protection dialog unless absolutely required.

When upgrading to V4.2 or later, switch the standard page to HTTPS by importing a self-signed certificate via TIA Portal > Web server > Certificate management. The browser will warn on the first connection; the operator must add the certificate to the trusted store.

Verification Procedure

  1. In TIA Portal, open the Watch table containing MotorStart and Speed.
  2. Click Monitor all to display live values.
  3. From the logged-in browser session, click the toggle / change the integer / submit the form.
  4. Confirm the watch table reflects the new value within 1 second.
  5. Open a second browser (private/incognito window) and repeat the write attempt without logging in. Confirm the write fails - this validates the access control model.

Acceptance criterion: writes succeed only when an authenticated admin session cookie is present.

Firmware-Specific Behavior (V3.0.x vs V4.x)

Behavior V3.0.x V4.0 – V4.1 V4.2 – V4.6
HTTPS support No Yes (TLS 1.0/1.1) Yes (TLS 1.2)
Default admin password Empty Must be set Must be set
Anonymous read of AWP pages Allowed Configurable Configurable
Web DB syntax DB only DB + global tags DB + global tags + data blocks with optimized access (subject to retain attribute)
Web API (REST) No No Yes (limited)
PUT/GET for S7 communication Always permitted Toggle required Toggle required

If upgrading V3.0.2 to V4.x, recompile the user-defined pages and re-download them. AWP syntax is backward compatible; old pages work, but encrypted upload requires the certificate infrastructure.

Browser Compatibility Matrix

Browser V3.0.2 HTTP V4.x HTTPS Notes
Internet Explorer 10 Works Limited (TLS 1.2 requires IE11) Old Web Browser Control in WinCC flex legacy panels emulates IE7 - avoid
Internet Explorer 11 Works Works Disable Enhanced Protected Mode for legacy web server pages
Google Chrome (Chromium 90+) Works Works Block third-party cookies does not affect Siemens session cookie (same origin)
Mozilla Firefox ESR Works Works Verify ESNI not blocking self-signed cert
Microsoft Edge (Chromium) Works Works Same behavior as Chrome
Safari (iOS / macOS) Works Works with cert trust override Self-signed certs must be added to keychain manually
Browser caveat: When the CPU has a self-signed certificate and the browser caches the rejection, clear HSTS state or use a fresh profile. The Siemens token cookie is HTTP-only by default on V4.x, so JavaScript cannot read it - this is by design, not a fault.

Common Related Faults and Workarounds

Symptom Likely Cause Workaround
Write form returns blank page Wrong form input name syntax Use name='"Tag"' (single-quote outer, double-quote inner)
Tag value resets after submit Tag declared in non-retain DB and CPU cycles Move tag to a retain DB or set retain attribute on the global tag
Login button greyed out Web server not activated in project Enable Web server in device configuration and download
404 on /awp/index.html User-defined pages not downloaded Right-click CPU > Web server > Download user-defined pages
403 Forbidden after login Standard user role used instead of admin Log out and log in as admin
Page loads but JS console shows mixed-content errors HTML references HTTP resources on HTTPS page Reference external CSS/JS via HTTPS or relative URLs
CSS layout broken on mobile Fixed pixel widths in original example Add viewport meta and use max-width: 100%
Login prompt reappears every refresh Browser blocks session cookie Disable SameSite=strict enforcement or use same-origin navigation only

Security Configuration Best Practices

  • Principle of least privilege: Create one operator user with read-only access. Reserve the admin role for commissioning engineers only.
  • Disable PUT/GET in the CPU protection dialog if you are not using legacy S7 communication.
  • Rotate passwords at each major commissioning phase. Use a credential manager to avoid sticky notes on control cabinets.
  • Audit CPU diagnostic buffer for "Web server login successful" entries - the V4.x firmware logs every authentication event.
  • Hide the standard welcome page if the user-defined page is the only intended operator HMI: this prevents curious operators from poking at tag lists and diagnostic buffers.
  • Network segmentation: Place the control LAN on a non-routable VLAN behind a managed switch. The S7-1200 web server has no rate limiting; an attacker on the same Layer-2 segment can attempt credential brute-force without any throttling.

Migration Path: User-Defined Pages to Modern Web API

For new deployments on V4.2 or later, evaluate whether user-defined HTML pages are still the right tool. The S7-1200 exposes a JSON-over-HTTPS web API that allows GET/POST of tag values directly. The endpoint pattern is:

https://<cpu-ip>/api/json?var=Speed&value=1500

This approach removes the need for AWP syntax entirely, integrates cleanly with Node-RED, Ignition, Grafana, and custom React front-ends, and benefits from the TLS infrastructure already built into the firmware. It is, however, still subject to the same admin-login requirement - the operator must authenticate before any write is honored.

Why does the S7-1200 user-defined web page monitor variables but refuse to write them?

The browser session is anonymous. The CPU only honors POSTs that contain AWP_In_Variable fields if the HTTP session carries an authenticated admin token. Log in at http://<cpu-ip>/ as user admin with the configured password, then open the user-defined page from the left navigation. Writes will then succeed.

Which AWP syntax is mandatory for a working write form on firmware V3.0.2?

Declare the tag with <!-- AWP_In_Variable Name="Tag" -->, and use <form method="POST"><input name='"Tag"' type="text"><input type="submit"></form>. The form input name must use single quotes outside and double quotes inside, e.g. name='"Speed"'. Any deviation causes the CPU to ignore the POST silently.

Does upgrading firmware from V3.0.2 to V4.x break existing user-defined pages?

No. AWP syntax is backward compatible. However, after the upgrade you must recompile the TIA Portal project, re-download the user-defined pages, and explicitly set an admin password (V4.x ships with no empty-password admin). Optionally migrate to HTTPS by importing a certificate.

How can I confirm the browser is sending an authenticated session?

Open browser DevTools > Application (or Storage) > Cookies and inspect the cookie named siemens_automation_token for the CPU's IP. If the cookie exists, the session is authenticated. If it is missing or expired (default 30 minutes idle), the next POST will be rejected.

Is the S7-1200 web server vulnerable to brute-force attacks on the admin password?

The CPU has no rate limiting on failed login attempts. Mitigation requires network segmentation (dedicated VLAN, ACLs, no Internet egress), a strong password of 12+ characters, and disabling the Web server when the panel is not in service. For higher assurance, upgrade to V4.2+ and enable HTTPS with a CA-signed certificate so credentials are not transmitted in cleartext.

Back to blog