Siemens HMI IP Address: Transfer Settings vs. TIA Portal Connection Settings
Overview
Siemens Basic, Comfort, and Mobile Panels (KTP, TP, MP families) operating with WinCC (TIA Portal) maintain two logically distinct IP configurations: the Transfer Settings configured from the panel's Control Panel → Network menu, and the Connection Settings defined inside the TIA Portal project under HMI device → Connections. Confusion between these two values is one of the most common commissioning issues on PROFINET/Ethernet networks because only one of them is the active Layer-3 identity of the panel at any given moment.
This reference documents the exact precedence rules, the effect on MPI/Profibus baudrate negotiation, the runtime behavior of the KTP600 Basic Mono PN and TP177B PN/DP, and the verification steps required to confirm which IP is in service.
The Two-IP Model on Siemens Panels
Every Siemens HMI panel holds three independent IP-related data records in non-volatile storage:
| Data Record | Where Set | Purpose | When Active |
|---|---|---|---|
| Control Panel IP (Transfer Settings) | Loader → Control Panel → Network → IP Address | Boot-time interface identity, used by Loader, Transfer, and any tooling that connects to the panel while Runtime is stopped | Always active at power-up until Runtime is started |
| Project IP (Connection Settings) | TIA Portal → HMI device → Properties → Connections → Ethernet → Address | Configuration that WinCC writes into the running project so Runtime knows the partner (PLC) and its own address | Becomes the panel's active IP only after Runtime has been started successfully |
| PROFINET device name | Control Panel → PN IO → Device Name | Used by PROFINET IO controller for LLDP-based name assignment; not the same as IP | Independent of IP; required for PROFINET IO operation |
Transfer Settings (Control Panel IP)
The Control Panel IP is the real address of the panel's network interface. It is the address that:
- Responds to
pingfrom any PC on the same subnet. - Listens on PROFINET for the IO controller discovery frames.
- Is advertised in the Loader's "Transfer" dialog.
- Survives a project delete, project update, and factory reset.
To change the Control Panel IP, navigate the touch screen menu on the panel:
- Stop Runtime (Loader is shown).
- Open Control Panel.
- Open Network and Dial-up Connections → PN[x].
- Open Internet Protocol (TCP/IP) → Properties.
- Enter IP address, subnet mask, and (if used) default gateway.
- Tap OK, then Close and confirm save.
TIA Portal Connection Settings (Project IP)
The Connection IP configured in TIA Portal is not a command that writes to the panel's network stack at compile time. Instead, it is:
- Compiled into the project file (.im/..ret) that is transferred to the panel.
- Loaded into a runtime configuration block when the Runtime starts on the panel.
- Applied to the network interface only if the Control Panel does not lock the address (KTP600 and most Basic Panels).
The path in TIA Portal to locate the setting is:
- Open the HMI device in the project tree.
- Double-click Connections.
- Select the connection to the S7 PLC (default name: "HMI_Connection_1").
- On the right pane, the Address field shows the partner (PLC) IP; the HMI device → Properties → Communication → Interfaces area shows the own HMI IP used in the project.
Typical values used in a default TIA Portal project for a KTP600:
| Device | Default IP | Location Configured |
|---|---|---|
| PLC (S7-1200 CPU) | 192.168.0.1 | Device → Properties → PROFINET interface → Ethernet addresses |
| HMI (KTP600, project value) | 192.168.0.10 | HMI device → Connections → Connection_1 → Address |
| Engineering Station | 192.168.0.220 | |
| Control Panel IP (KTP600 default) | 192.168.0.2 | Loader → Control Panel → Network |
Runtime IP Precedence
Siemens firmware enforces the following precedence rules on the panel's TCP/IP stack:
| Runtime State | Active IP | Ping Responds? | Editable From Loader? |
|---|---|---|---|
| Loader only (Runtime stopped) | Control Panel IP | Yes (on Control Panel IP) | Yes |
| Runtime starting / started | Project IP (from Connections) for most Comfort Panels; Control Panel IP retained for KTP600 and most Basic Panels | Yes (on whichever address is the active one) | No (Basic) / Limited (Comfort) |
| Runtime stopped (via stop command) | Returns to Control Panel IP | Yes (on Control Panel IP) | Yes |
On the KTP600 Basic Mono PN, the Control Panel IP always has priority. The Project IP configured in TIA is used by TIA Portal to preconfigure the transfer direction (so the compiler knows which interface to send the project to) but is not written to the interface. The panel's interface identity remains 192.168.0.2 (or whatever the Control Panel IP is) throughout Runtime.
ping 192.168.0.2 from the engineering station will succeed when the HMI is in Loader or Runtime, and ping 192.168.0.10 will time out, because 192.168.0.10 is only a project-time configuration constant on Basic Panels, never an active socket address.MPI / PROFIBUS Baudrate Behavior
On panels that support MPI or PROFIBUS, the baudrate configured in the TIA project connection is not applied to the Loader. The Loader keeps whatever baudrate is set in Control Panel → MPI/DP. When Runtime starts, the panel re-initializes the bus to the project baudrate. This causes the sequence described in field testing:
- PG/PC adapter is set to MPI 187.5 kbit/s (matches Control Panel transfer setting).
- Project is downloaded successfully at 187.5 kbit/s.
- Runtime starts, panel auto-negotiates MPI to 1.5 Mbit/s (matches Connection Settings).
- PG/PC attempts a second download: fails because adapter is still at 187.5 kbit/s.
- PG/PC adapter is changed to 1.5 Mbit/s: download succeeds.
The baudrate swap is one-way: a "Stop Runtime" command from TIA Portal returns the panel to the Loader, but the Loader defaults to the Control Panel transfer baudrate, not the project baudrate. The panel must be reloaded with the new baudrate before any further transfer can occur at the original Control Panel speed.
Ethernet / PROFINET Behavior
For Ethernet / PROFINET, the precedence is different from MPI/PROFIBUS because the IP address is a layer-3 identity, not just a bus speed. On a Comfort Panel (TP700…TP2200, TP1900, TP2200), the Project IP can be written to the interface at Runtime start. On a Basic Panel such as the KTP600, the Control Panel IP is locked. The table below summarizes:
| Panel Family | Runtime Applies Project IP? | Control Panel Editable at Runtime? | PROFINET IO Affected? |
|---|---|---|---|
| KTP400 Basic / KTP600 Basic / KTP700 Basic | No | No | No (PROFINET IO not supported on these models) |
| KTP900 Basic / KTP1200 Basic | No | No | No |
| Comfort Panels (TP700..TP2200) | Yes (Runtime writeable) | Yes (limited) | Yes — PROFINET IO may be affected briefly during re-init |
| Mobile Panels (KTP Mobile, KTP Mobile 2nd Gen) | Yes | Limited | Yes |
| TP177B PN/DP (legacy) | No — Control Panel IP locked | No at Runtime | Only on PN variant |
Configuring the KTP600 Step-by-Step
The following procedure delivers a deterministic configuration in which the active IP at all times equals the value shown in TIA Portal.
Prerequisites
- TIA Portal V15.1 or later with WinCC Basic/Comfort installed.
- KTP600 Basic Mono PN (6AV6 647-0AA11-3AX0) or any KTP/TP in scope.
- S7-1200 (or S7-1500, S7-300/400 with Ethernet) PLC on the same subnet.
- Ethernet cable between the panel's PN port and the engineering station / PLC.
Step-by-Step
-
Configure PLC IP. In TIA Portal, open the PLC device → Properties → PROFINET interface → Ethernet addresses, set
IP address: 192.168.0.1,Subnet mask: 255.255.255.0. Compile and download to the PLC. -
Configure HMI Project IP. In TIA Portal, open the HMI device → Connections, set the HMI address to
192.168.0.10and partner to192.168.0.1(PLC). The PG/PC interface must be set to PN/IE in the project properties. -
Configure Control Panel IP on the panel. Boot the panel, enter the Loader, open Control Panel → Network → PN[x1], set the IP to
192.168.0.2with mask255.255.255.0. Save and exit. -
Configure the engineering PC. Set the PC Ethernet adapter to
192.168.0.220 / 24. Disable any other active network interfaces on the PC to avoid routing ambiguity. - Compile the HMI project. Right-click the HMI device → Compile → Software (rebuild all). Resolve any warnings about subnet mismatch.
-
Download the project. Right-click the HMI device → Download to device → Configure PG/PC interface: select the Ethernet adapter bound to
192.168.0.220. TIA will discover the panel at192.168.0.2(the Control Panel IP) and transfer the project. - Start Runtime. The panel will reboot into Runtime. The PLC communication tag list will turn green in TIA Portal's "Online → Accessible Nodes" if Runtime is healthy.
Verification and Diagnostics
After download, perform the following checks in order:
| Check | Method | Expected Result |
|---|---|---|
| Control Panel IP responds |
ping 192.168.0.2 -t from PC |
Reply <1 ms; works in both Loader and Runtime |
| Project IP responds (Basic Panel) | ping 192.168.0.10 -t |
Request timed out (Basic Panel does not apply the Project IP) |
| PLC IP responds | ping 192.168.0.1 -t |
Reply <1 ms; independent of panel state |
| AR / Connection visible | TIA Portal → Online → Accessible nodes → HMI | HMI node shows online, type "KTP600 Basic" |
| HMI ↔ PLC tag traffic | TIA Portal → HMI tags → Monitor | Tag values update; "Connection status" = OK |
| PROFINET IO AR (Comfort only) | PLC → Online → Diagnostics → PROFINET IO | HMI shown as IO device (if IO configured) |
On a Comfort Panel that has applied the Project IP, the opposite is true: ping 192.168.0.10 succeeds in Runtime, and ping 192.168.0.2 times out once Runtime has overwritten the interface. The Control Panel entry still displays 192.168.0.2, but the stack has a different address until Runtime is stopped.
Troubleshooting Matrix
| Symptom | Likely Cause | Resolution |
|---|---|---|
| Ping to Control Panel IP fails at power-up | PC and panel in different subnets, or PC firewall blocking ICMP | Verify both are in 192.168.0.0/24; allow vmnetBridge or relevant adapter through Windows Defender Firewall |
| TIA Portal cannot find the panel during "Download to device" | Loader transfer mode not enabled, or panel in Runtime | Open Loader → Transfer, enable "Transfer" checkbox; if Runtime is running, schedule transfer from TIA via "Online → Download to device" with the "Stop Runtime" option |
| Project downloads but PLC tags remain red | Project IP set to a different subnet than the PLC; PG/PC interface bound to wrong adapter | Match subnets; in TIA → Options → Set PG/PC interface, select the adapter connected to the panel/PLC |
| Second download fails after first successful one (MPI/DP) | Runtime overwrote baudrate to 1.5 Mbit/s; PG adapter still at 187.5 kbit/s | Set PG/PC adapter baudrate to match the project's MPI/DP connection speed |
| Factory reset required | Control Panel password forgotten, or repeated transfer failures | Loader → Control Panel → System → Reset → Factory reset (KTP600: hold the area to the right of the screen during power-up for 10 s) |
| PROFINET device name conflict | Two panels with same PROFINET name on the network | Assign a unique PROFINET name from the PLC's PROFINET IO topology editor |
| Project IP applied but partner unreachable | Default gateway misconfigured; PLC on a different subnet than Comfort Panel Runtime IP | Either remove default gateway entries or add a route consistent with the subnetting |
Common Pitfalls
- Assuming the Project IP is the active address. On Basic Panels, it is not. Always test with the Control Panel IP first.
-
Mixing subnet sizes. A panel at
192.168.0.2/24and a PLC at192.168.0.1/16can route incorrectly on some PC stacks. Keep the prefix length identical. - Forgetting the PROFINET device name. For PROFINET IO, the device name is required even if the IP is set correctly. The device name and IP are independent.
- Stopping Runtime leaves stale IP. On Comfort Panels, a "Stop Runtime" returns the interface to Control Panel IP after a short transition; during the transition, the panel may be unreachable for several seconds.
- Using DHCP without a server. Basic Panels default to DHCP. If no DHCP server is present, the panel falls back to its last known IP, which may be unrelated to the TIA project. Set static addresses for production.
Related Siemens Documentation
For additional context, refer to the WinCC (TIA Portal) Information System inside TIA Portal (Help → Show Help), the SIMATIC HMI Panels operator manuals, and the S7-1200/1500 system manuals. The "Communication" chapter of the WinCC Information System contains the full description of the connection editor and IP precedence rules.
FAQ
Why does the KTP600 keep its Control Panel IP instead of the IP I set in TIA Portal?
On Basic Panels (KTP400, KTP600, KTP700, KTP900, KTP1200) the Control Panel IP is locked; the project IP is compiled into the project and used by TIA to preconfigure the transfer, but it is never written to the network interface. The active address at all times is the value entered at Loader → Control Panel → Network.
Can I change the HMI IP while Runtime is running?
No on KTP600 Basic and other Basic Panels. The Control Panel is only reachable from the Loader, so Runtime must be stopped first. Comfort Panels allow a limited change at Runtime but it triggers a brief communication interruption.
Why does the second download fail at MPI/DP after the first one succeeds?
When Runtime starts, the panel re-initializes the bus to the baudrate configured in the TIA project connection. The PG/PC adapter must be set to the same baudrate (for example 1.5 Mbit/s) for subsequent transfers, even though the Control Panel transfer baudrate is still 187.5 kbit/s.
I can ping 192.168.0.2 but not 192.168.0.10. Is 192.168.0.10 still valid?
On a Basic Panel, 192.168.0.10 is only a project-time configuration constant used by TIA to know where to send the project; it is never a live socket address. On a Comfort Panel, 192.168.0.10 becomes the active IP once Runtime starts and 192.168.0.2 stops responding.
Do I need a PROFINET device name if I set the IP manually?
Yes, for PROFINET IO operation the device name is mandatory and is independent of the IP. Assign it from the PLC's PROFINET IO topology editor in TIA Portal, or from Loader → Control Panel → PN[x1] → PROFINET IO → Device name.