Problem Overview
A common complaint when commissioning the S7-1200 standard web server with user-defined pages is that monitored values render correctly in the browser yet the operator cannot toggle a bit or write an integer back to the CPU. Symptoms include:
- Numeric tags refresh in real time on the user-defined page (polling visible).
- Clicking a write button, slider, or text-input submits the form but the tag never updates in TIA Portal watch table or online monitoring.
- No PLC diagnostic buffer entries are produced; no SF/BF LED activity changes.
- Behavior is identical across Google Chrome, Microsoft Edge, and Internet Explorer 10/11.
This fault is reported on the 6ES7 214-1AG31-0XB0 (CPU 1214C DC/DC/DC) with firmware V3.0.2 after installing the Siemens example project "Web Server - Creating and using user-defined web pages on S7-1200" (Siemens Support entry ID 58862931). The root cause is not a defective AWP page, not a browser defect, and not a hardware defect. The CPU is enforcing its role-based access model correctly; the HTML page is being served to an anonymous session that has read-only rights.
Affected Hardware and Firmware
| CPU Order Number | Model | FW Tested | Behavior |
|---|---|---|---|
| 6ES7 214-1AG31-0XB0 | CPU 1214C DC/DC/DC | V3.0.2 | Anonymous read, writes silently rejected |
| 6ES7 214-1BG31-0XB0 | CPU 1214C AC/DC/RLY | V3.0.2 | Same |
| 6ES7 215-1AG31-0XB0 | CPU 1215C DC/DC/DC | V3.0.x | Same |
| 6ES7 211-1AE31-0XB0 | CPU 1211C DC/DC/DC | V3.0.x | Same |
| Any S7-1200 | CPU 121xC / 1215C / 1217C | V4.0 – V4.6 | Same unless "Permit access with PUT/GET" and HTTPS configured |
The fault is independent of signal module (SM), communication processor (CP), or signal board (SB) configuration. Adding SMs does not change the access policy.
Root Cause Analysis
The S7-1200 web server uses three privilege levels defined in the CPU's Web server configuration object in TIA Portal:
- Anonymous - read-only. Default. Activated automatically when the Web server is enabled.
- Standard user - read-only access to additional pages if explicitly granted; cannot write variables.
- Administrator ("admin") - read/write to all CPU variables and tags exposed via AWP commands.
When a browser hits the standard web page (http://<cpu-ip>/) without credentials, the session token is anonymous. Any subsequent HTTP GET or POST to a user-defined page (/awp/<file>.html) inherits that anonymous session. The CPU parses the AWP_In_Variable and AWP_Out_Variable tags inside the HTML and answers GETs (reads) with current values, but POSTs that contain an AWP_In_Variable field with the := operator are silently discarded because the session role is not authorized for writes.
The Siemens S7-1200 System Manual explicitly states that writes from user-defined pages are only permitted after the operator has successfully authenticated against the standard web page. See the Web server chapter in the S7-1200 Programmable Controller System Manual on the Siemens Industry Online Support portal.
Resolution: Enable the Administrative Login
Step 1 - Confirm Web server is activated
- In TIA Portal, select the S7-1200 CPU in the project tree.
- Open Properties > Web server.
- Verify Activate web server on this CPU is checked.
- Note the IP address shown under Ethernet interface PROFINET [X1].
Step 2 - Configure the administrator password
- In the same Web server dialog, switch to the User management section.
- Confirm the user admin exists with role Administrator.
- Set a password (8–32 characters, case-sensitive). The firmware V3.0.2 ships with admin no password by default; V4.x and later require a password to be set before the admin role can write.
- Compile and download the project to the CPU.
Step 3 - Download the user-defined pages
- Right-click the CPU in the project tree and choose Web server > Download user-defined pages.
- Confirm the HTML files (e.g.,
index.html,script.js) are transferred to the CPU's internal load memory under theWWWdirectory.
Step 4 - Authenticate from the browser
- Open a browser and navigate to
http://<cpu-ip>/(the standard Siemens welcome page). - Locate the Log in link on the left navigation pane.
- Enter
adminas the user name and the configured password. - Wait for the page to confirm successful login (the upper-right corner changes from "Anonymous" to "admin").
Step 5 - Navigate to user-defined page
- In the left navigation pane under User-defined pages, click the page link (e.g.,
index). - Verify the URL now begins with
/awp/index.htmland that the session cookiesiemens_automation_tokenis present (visible in browser DevTools > Application > Cookies). - Toggle a write control. The tag now updates in TIA Portal watch table within one scan cycle.
AWP Command Reference for User-Defined Pages
Automation Web Programming (AWP) commands are HTML comments parsed by the CPU. The following table summarizes the canonical commands used in the Siemens example project 58862931.
| AWP Command | Direction | HTTP Verb | Sample Snippet | Notes |
|---|---|---|---|---|
:="MotorStart" |
Read (tag → browser) | GET | <!-- AWP_Out_Variable Name="MotorStart" --> |
Replaced with current tag value on each refresh |
<form ...> with hidden input |
Write (browser → tag) | POST | <form action="" method="POST"><input name='"Speed"' type="text"><input type="submit"></form> |
Single quotes around name are mandatory |
AWP_In_Variable |
Write (browser → tag) | POST | <!-- AWP_In_Variable Name="Speed" --> |
Declares variable as writable |
AWP_Enum_Def |
Symbolic | GET | <!-- AWP_Enum_Def Name="States" Values="0:Off,1:On" --> |
Improves readability of integer states |
AWP_Start_Sequenz / AWP_End_Sequenz |
Block | POST | <!-- AWP_Start_Sequenz -->...<!-- AWP_End_Sequenz --> |
Groups multiple writes into one request |
AWP_Variable_Default |
Read fallback | GET | <!-- AWP_Variable_Default Name="Mode" Value="0" --> |
Used when tag has no value yet |
name='"Speed"'. This is the most common reason a write form fails even after a successful login. TIA Portal's HTML parser requires the embedded string exactly.Implementing a Secure Login Page
From firmware V4.0 onward the CPU supports HTTPS (TLS 1.2) and certificate-based login. V3.0.x only supports HTTP. To harden a V3.0.2 deployment while you still cannot enable TLS, restrict network exposure:
- Place the CPU on a dedicated VLAN with no Internet egress.
- Use PROFINET port-based isolation or a managed switch ACL.
- Set a non-trivial admin password (12+ characters, alphanumeric + symbols).
- Disable Permit access with PUT/GET (from remote partner) in the CPU protection dialog unless absolutely required.
When upgrading to V4.2 or later, switch the standard page to HTTPS by importing a self-signed certificate via TIA Portal > Web server > Certificate management. The browser will warn on the first connection; the operator must add the certificate to the trusted store.
Verification Procedure
- In TIA Portal, open the Watch table containing
MotorStartandSpeed. - Click Monitor all to display live values.
- From the logged-in browser session, click the toggle / change the integer / submit the form.
- Confirm the watch table reflects the new value within 1 second.
- Open a second browser (private/incognito window) and repeat the write attempt without logging in. Confirm the write fails - this validates the access control model.
Acceptance criterion: writes succeed only when an authenticated admin session cookie is present.
Firmware-Specific Behavior (V3.0.x vs V4.x)
| Behavior | V3.0.x | V4.0 – V4.1 | V4.2 – V4.6 |
|---|---|---|---|
| HTTPS support | No | Yes (TLS 1.0/1.1) | Yes (TLS 1.2) |
| Default admin password | Empty | Must be set | Must be set |
| Anonymous read of AWP pages | Allowed | Configurable | Configurable |
| Web DB syntax | DB only | DB + global tags | DB + global tags + data blocks with optimized access (subject to retain attribute) |
| Web API (REST) | No | No | Yes (limited) |
| PUT/GET for S7 communication | Always permitted | Toggle required | Toggle required |
If upgrading V3.0.2 to V4.x, recompile the user-defined pages and re-download them. AWP syntax is backward compatible; old pages work, but encrypted upload requires the certificate infrastructure.
Browser Compatibility Matrix
| Browser | V3.0.2 HTTP | V4.x HTTPS | Notes |
|---|---|---|---|
| Internet Explorer 10 | Works | Limited (TLS 1.2 requires IE11) | Old Web Browser Control in WinCC flex legacy panels emulates IE7 - avoid |
| Internet Explorer 11 | Works | Works | Disable Enhanced Protected Mode for legacy web server pages |
| Google Chrome (Chromium 90+) | Works | Works | Block third-party cookies does not affect Siemens session cookie (same origin) |
| Mozilla Firefox ESR | Works | Works | Verify ESNI not blocking self-signed cert |
| Microsoft Edge (Chromium) | Works | Works | Same behavior as Chrome |
| Safari (iOS / macOS) | Works | Works with cert trust override | Self-signed certs must be added to keychain manually |
Common Related Faults and Workarounds
| Symptom | Likely Cause | Workaround |
|---|---|---|
| Write form returns blank page | Wrong form input name syntax | Use name='"Tag"' (single-quote outer, double-quote inner) |
| Tag value resets after submit | Tag declared in non-retain DB and CPU cycles | Move tag to a retain DB or set retain attribute on the global tag |
| Login button greyed out | Web server not activated in project | Enable Web server in device configuration and download |
| 404 on /awp/index.html | User-defined pages not downloaded | Right-click CPU > Web server > Download user-defined pages |
| 403 Forbidden after login | Standard user role used instead of admin | Log out and log in as admin |
| Page loads but JS console shows mixed-content errors | HTML references HTTP resources on HTTPS page | Reference external CSS/JS via HTTPS or relative URLs |
| CSS layout broken on mobile | Fixed pixel widths in original example | Add viewport meta and use max-width: 100%
|
| Login prompt reappears every refresh | Browser blocks session cookie | Disable SameSite=strict enforcement or use same-origin navigation only |
Security Configuration Best Practices
- Principle of least privilege: Create one operator user with read-only access. Reserve the admin role for commissioning engineers only.
- Disable PUT/GET in the CPU protection dialog if you are not using legacy S7 communication.
- Rotate passwords at each major commissioning phase. Use a credential manager to avoid sticky notes on control cabinets.
- Audit CPU diagnostic buffer for "Web server login successful" entries - the V4.x firmware logs every authentication event.
- Hide the standard welcome page if the user-defined page is the only intended operator HMI: this prevents curious operators from poking at tag lists and diagnostic buffers.
- Network segmentation: Place the control LAN on a non-routable VLAN behind a managed switch. The S7-1200 web server has no rate limiting; an attacker on the same Layer-2 segment can attempt credential brute-force without any throttling.
Migration Path: User-Defined Pages to Modern Web API
For new deployments on V4.2 or later, evaluate whether user-defined HTML pages are still the right tool. The S7-1200 exposes a JSON-over-HTTPS web API that allows GET/POST of tag values directly. The endpoint pattern is:
https://<cpu-ip>/api/json?var=Speed&value=1500
This approach removes the need for AWP syntax entirely, integrates cleanly with Node-RED, Ignition, Grafana, and custom React front-ends, and benefits from the TLS infrastructure already built into the firmware. It is, however, still subject to the same admin-login requirement - the operator must authenticate before any write is honored.
Why does the S7-1200 user-defined web page monitor variables but refuse to write them?
The browser session is anonymous. The CPU only honors POSTs that contain AWP_In_Variable fields if the HTTP session carries an authenticated admin token. Log in at http://<cpu-ip>/ as user admin with the configured password, then open the user-defined page from the left navigation. Writes will then succeed.
Which AWP syntax is mandatory for a working write form on firmware V3.0.2?
Declare the tag with <!-- AWP_In_Variable Name="Tag" -->, and use <form method="POST"><input name='"Tag"' type="text"><input type="submit"></form>. The form input name must use single quotes outside and double quotes inside, e.g. name='"Speed"'. Any deviation causes the CPU to ignore the POST silently.
Does upgrading firmware from V3.0.2 to V4.x break existing user-defined pages?
No. AWP syntax is backward compatible. However, after the upgrade you must recompile the TIA Portal project, re-download the user-defined pages, and explicitly set an admin password (V4.x ships with no empty-password admin). Optionally migrate to HTTPS by importing a certificate.
How can I confirm the browser is sending an authenticated session?
Open browser DevTools > Application (or Storage) > Cookies and inspect the cookie named siemens_automation_token for the CPU's IP. If the cookie exists, the session is authenticated. If it is missing or expired (default 30 minutes idle), the next POST will be rejected.
Is the S7-1200 web server vulnerable to brute-force attacks on the admin password?
The CPU has no rate limiting on failed login attempts. Mitigation requires network segmentation (dedicated VLAN, ACLs, no Internet egress), a strong password of 12+ characters, and disabling the Web server when the panel is not in service. For higher assurance, upgrade to V4.2+ and enable HTTPS with a CA-signed certificate so credentials are not transmitted in cleartext.