Overview: Why Mirror Screen Changes Across Two TP1500 Panels
Two SIMATIC TP1500 Comfort HMI panels are frequently deployed on a single SIMATIC S7-300 station when an operator station is duplicated for redundant visibility, for a master/replica desk, or for a control room and a local panel side-by-side on the same machine. With STEP 7 V5.5 and WinCC Flexible 2008 SP5, the panels exchange data with the PLC over TCP/IP, but picture selection is a per-panel state. Without explicit synchronization, the second panel will keep showing its last picture while the first one has moved on, which is almost never what the operator wants.
The standard, Siemens-blessed remedy is the Screen Number area pointer, written by whichever panel the operator is using, read by every other panel, plus the Activate Screen By Number function triggered as a value-change event on that pointer. The mechanism is event-driven, deterministic, and does not require polling. Both panels switch on the same PLC clock tick without any custom protocol.
This guide covers:
- Hardware and software prerequisites for TP1500 + S7-300 + WinCC Flexible 2008 SP5
- Network topology and S7 connection planning
- Configuring the Screen Number area pointer in STEP 7 V5.5 and in the HMI
- Wiring the Activate Screen By Number event on both panels
- Bidirectional synchronization with collision handling and panel lock-out
- Commissioning tests, diagnostics, and fault matrix
- Migration to TIA Portal / WinCC (TIA Portal) when the project is eventually ported
Prerequisites
| Item | Required Specification | Notes |
|---|---|---|
| SIMATIC S7-300 CPU | CPU 31x PN/DP or 31x with CP 343-1 | Must support S7 communication; classic MPI/PROFIBUS is also acceptable but TCP/IP via PROFINET interface is preferred for TP1500. |
| SIMATIC TP1500 Comfort | 15" widescreen, 6AV2 124-1QCxx | Comfort line; supports PROFINET and is the only line still serviced by WinCC Flexible 2008 SP5. |
| Engineering PC | STEP 7 V5.5 + SPx (HF7 or later recommended) | Project must be opened in classic STEP 7, not TIA Portal, to match the runtime files. |
| HMI configuration | WinCC Flexible 2008 SP5 | SP5 is the last release that supports Comfort Panels. Update HF1 to HF8 depending on panel image. |
| Network | TCP/IP, single subnet recommended | All three devices on the same subnet avoids router hops and shortens event latency. |
| Project cycle | OB1 (main) cycle < 250 ms | Area pointer polling is event-driven; the OB1 scan only affects the PLC-side hand-shake reset. |
System Architecture and Network Topology
The reference setup is a star topology with a managed switch at the centre. Each TP1500 and the S7-300 CPU has a fixed IP address on the same /24 subnet. Two S7 connections are configured in WinCC Flexible: HMI_1 → PLC and HMI_2 → PLC. The PLC holds a single shared data block (DB100 in the example) that is the synchronization mailbox for both panels.
Two independent S7 connections are required; the panels must not be cascaded through one another. Each connection has its own partner IP, rack/slot, and connection resource (S7 connection ID) on the CPU.
The Screen Number Area Pointer: How It Works
The Screen Number area pointer is a fixed 4-byte region in the PLC memory (2 data words, 16 bits each) with the following layout:
| Offset | Width | Direction | Meaning |
|---|---|---|---|
| Word n | 16 bits | HMI → PLC (write), PLC → HMI (read) | Current screen number (1 .. 500 for TP1500) |
| Word n+1 | 16 bits | HMI → PLC (write, 1 = new value), PLC → HMI (write, 0 = acknowledged) | Acquisition / acknowledge bit-field. Bit 0 toggles on each new value. Other bits reserved. |
Mechanism step-by-step:
- Operator on HMI_1 presses a navigation button. The WinCC Flexible runtime writes the new screen number to word n and sets bit 0 of word n+1 to
1. - The PLC sees the new value, copies the screen number to a shared register, and clears bit 0 of word n+1 to
0on the way back. - HMI_2 polls the area pointer on every cycle. When it sees a new screen number in word n, its configured Change Value event fires.
- The event calls the system function ActivateScreen with the new value as the parameter, switching HMI_2 to the same picture.
The acknowledge word is the safety net: it forces the HMI to consider the new value as "consumed" and prevents the value-change event from firing repeatedly while the pointer stays at the same value.
PLC Configuration in STEP 7 V5.5
Create a shared data block to hold the synchronization mailbox. The simplest viable structure uses two words per panel so each panel can write its own number without overwriting the other:
| Address | Name | Type | Initial Value | Comment |
|---|---|---|---|---|
| DB100.DBW0 | HMI1_Screen | WORD | W#16#0001 | Current picture on HMI_1, written by HMI_1 |
| DB100.DBW2 | HMI1_Ack | WORD | W#16#0000 | Acquire flag from HMI_1, cleared by PLC |
| DB100.DBW4 | HMI2_Screen | WORD | W#16#0001 | Current picture on HMI_2, written by HMI_2 |
| DB100.DBW6 | HMI2_Ack | WORD | W#16#0000 | Acquire flag from HMI_2, cleared by PLC |
| DB100.DBW8 | Sync_Screen_HMI1 | WORD | W#16#0001 | Target picture that HMI_1 must display (read by HMI_1) |
| DB100.DBW10 | Sync_Screen_HMI2 | WORD | W#16#0001 | Target picture that HMI_2 must display (read by HMI_2) |
| DB100.DBX12.0 | Lock_HMI1 | BOOL | FALSE | 1 = HMI_1 does not follow, HMI_2 has independent control |
| DB100.DBX12.1 | Lock_HMI2 | BOOL | FALSE | 1 = HMI_2 does not follow |
The hand-shake logic lives in OB1 and copies the partner panel's last acknowledged screen into the local panel's Sync_Screen word. Ack flags are always cleared by the PLC after the copy so the HMI can re-trigger the event on the next change.
OB1 ladder excerpt (FBD view):
// HMI_1 acknowledged new screen
A DB100.DBX2.0 // HMI1_Ack bit 0
JCN _NoNew_HMI1
L DB100.DBW0 // HMI1_Screen
T DB100.DBW10 // Sync_Screen_HMI2
L 0
T DB100.DBW2 // clear HMI1_Ack
_NoNew_HMI1: NOP 0
// HMI_2 acknowledged new screen
A DB100.DBX6.0
JCN _NoNew_HMI2
L DB100.DBW4 // HMI2_Screen
T DB100.DBW8 // Sync_Screen_HMI1
L 0
T DB100.DBW6 // clear HMI2_Ack
_NoNew_HMI2: NOP 0
// Lock-out: if HMI_1 is locked, never overwrite HMI_2's target
A DB100.DBX12.0 // Lock_HMI1
JC _SkipHMI1
L DB100.DBW0
T DB100.DBW10
_SkipHMI1: NOP 0
If the lock-out feature is not required, the four hand-shake lines above (without the lock-out check) are enough. The lock-out path is recommended for any installation where one panel is on a maintenance screen and the other is on a process screen; otherwise an operator on the maintenance panel will pull the production panel into maintenance.
DB100.DBW0, DB100.DBW4, DB100.DBW8, and DB100.DBW10 on every cycle. A permanent DB100.DBW2 <> 0 with a stale DB100.DBW0 means the HMI has lost the connection to that area pointer and is not refreshing; this is the single most common commissioning error.
HMI Configuration in WinCC Flexible 2008 SP5
Both TP1500 projects are built in WinCC Flexible 2008 SP5 and downloaded to the panels. The procedure is identical for HMI_1 and HMI_2 except for the IP addresses and the variable names.
Step 1: Define the S7 Connection
- In the project tree, open Connections under HMI_1 → Communication → Connections.
- Create a new connection, choose SIMATIC S7 300/400 as the PLC, set the partner IP to
192.168.0.1, rack 0, slot 2 (typical for CPU 315-2 PN/DP), and the S7 connection ID assigned by STEP 7 (default: 1 for HMI_1, 2 for HMI_2). - Repeat for HMI_2 with a different connection ID, e.g. 2.
Step 2: Declare the Tags
Create the following external tags on both panel projects. Address resolution is the same; only the connection name differs.
| Tag Name (HMI_1) | Tag Name (HMI_2) | PLC Address | Type | Length |
|---|---|---|---|---|
| own_screen_no | own_screen_no | DB100.DBW0 (HMI_1) / DB100.DBW4 (HMI_2) | Word | 2 bytes |
| own_ack | own_ack | DB100.DBW2 (HMI_1) / DB100.DBW6 (HMI_2) | Word | 2 bytes |
| sync_screen | sync_screen | DB100.DBW8 (HMI_1) / DB100.DBW10 (HMI_2) | Word | 2 bytes |
| lock_local | lock_local | DB100.DBX12.0 (HMI_1) / DB100.DBX12.1 (HMI_2) | Bool | 1 bit |
Step 3: Configure the Screen Number Area Pointer
- Open the connection HMI_1 → PLC.
- Switch to the Area Pointers tab.
- Enable Screen Number, set the PLC address to
DB 100 DBB 0(start of the local write area; this is what the HMI uses to push its own screen number back to the PLC). - Acquire flag bit: leave at the default (bit 0 of the second word, i.e.
DB100.DBX2.0). - Confirm with OK. The pointer automatically adds the
+2byte offset for the acquire flag, so the resulting layout matches the DB100 layout from the PLC section. - Repeat for HMI_2 with PLC address
DB 100 DBB 4.
Step 4: Configure the Activate Screen By Number Event
- Open the Project → Screens folder and select the root screen (e.g. Screen_1).
- In the screen's Events tab, add a new event: On Loaded is not what you want; you want a value-change event on the sync_screen tag. WinCC Flexible exposes that through Scheduler → Tag-Triggered Tasks (older builds: Events → Value change on the tag itself).
- Create a new tag-triggered task named
Sync_Screen, trigger tag sync_screen, cycle: On change. - In the task body, call the system function ActivateScreen. Parameter: Screen number = tag sync_screen. Parameter: Screen object = leave blank (the function switches to the picture with the corresponding screen number).
Repeat the same task on HMI_2. The task runs only when the value of sync_screen changes, which is exactly when the partner panel wrote a new screen number.
Step 5: Wire the Lock-Out (Optional)
On the HMI, add a button tagged Local control on the root screen. On press:
- Toggle lock_local using SetBit / ResetBit system functions.
- Update a text field to show "Independent" or "Follow partner".
This is what the operator uses when a maintenance screen must remain on one panel only. Without this feature, both panels will mirror every navigation, including intentional excursions.
Bidirectional Sync Sequence and Collision Handling
The classic race condition happens when both operators press navigation buttons within a few hundred milliseconds. With the four-word mailbox (HMI1_Screen, HMI1_Ack, HMI2_Screen, HMI2_Ack) and the OB1 hand-shake, the PLC arbitrates the order: whichever acknowledge bit is seen first is copied to the partner's sync_screen, and the partner's ActivateScreen task fires. The other panel's acknowledge is processed in the next OB1 scan and reflects the partner's value back. There is no lost update because the PLC always uses the most recent acknowledged value.
Edge cases to verify in commissioning:
- Same screen pressed twice in a row. The acquire bit toggles only when the value actually changes. A repeat press does not re-trigger, which is correct.
- Operator switches a panel to a screen that does not exist on the partner. The ActivateScreen function will fall back to the start screen if the screen number is out of range. Use a uniform screen-numbering scheme on both panels from day one.
- Power-cycle of one panel. When the panel comes back, it reads the current sync_screen value and is already on the right picture. No startup script is required.
- Connection break. The area pointer stops updating. When the connection re-establishes, the HMI re-reads sync_screen and catches up automatically on the next poll.
Verification and Commissioning Tests
-
Tag-watching test. In WinCC Flexible's Tag Simulation or in STEP 7's Monitor / Modify, write the screen number
10toDB100.DBW0. Both panels must switch to picture 10. Reset to1. Both return to the root screen. - Navigation test. Operate HMI_1 only. Verify HMI_2 follows on every screen change, including back-navigation and to the alarm buffer.
- Reverse test. Operate HMI_2 only. HMI_1 must follow.
- Concurrent test. Two operators press different screen numbers at the same time. Confirm the PLC processes both and both panels end on the same picture (the one processed last by OB1). Document the expected order if it matters.
-
Lock-out test. Set lock_local on HMI_1 to
TRUE. HMI_1 navigation must not affect HMI_2. Clear the lock. Sync resumes immediately. - Disconnect test. Pull the PROFINET cable on HMI_2. HMI_1 keeps working. Reconnect. HMI_2 must snap to the current picture within one poll cycle.
- Cold start test. Cycle power on both panels. Both must start on the root screen regardless of which one was on the field screen before power-down.
Troubleshooting Matrix
| Symptom | Likely Cause | Fix |
|---|---|---|
| HMI_2 does not follow HMI_1 | Screen Number area pointer not enabled on HMI_2's connection, or wrong DB / offset | Re-open the connection, Area Pointers tab, enable Screen Number pointing to DB100.DBB4. |
| Both panels switch on the first change, then stop | Acquire bit not cleared by the PLC | Verify the OB1 reset block runs every cycle. Add a one-shot on the acknowledge bit if the OB1 is conditional. |
| ActivateScreen reports "screen not available" on the runtime | Screen number outside 1..500 range, or picture is hidden | Limit the sync_screen tag to a valid range with the Linear scaling property in WinCC Flexible. |
| Both panels flicker between two pictures | Race condition: panel A is reacting to B and B is reacting to A | Add a dead-band timer (e.g. ignore sync_screen changes for 200 ms after a local navigation). Use the lock-out feature for problematic pictures. |
| HMI shows a stale picture after PLC restart | PLC data block has retentive behavior turned on, or the HMI never re-reads after reconnect | Set DB100 to non-retentive (UNLINK) and verify the area pointer polling cycle. |
| No tag values update at all on HMI_2 | Wrong S7 connection ID or wrong partner IP | Open Connections → HMI_2 → PLC → Properties → Station, check IP and rack/slot. |
| Compiler warning: "area pointer overlaps process data" | Screen Number pointer start address collides with another pointer's range | Re-lay out DB100 with explicit offsets and rebuild. |
| HMI switches to wrong picture occasionally | Network jitter causing duplicate polling reads | Use the Minimum cycle setting on the tag-triggered task, e.g. 500 ms minimum between firings. |
Migration to TIA Portal
When the project is eventually migrated to TIA Portal and WinCC (TIA Portal), the synchronization pattern remains unchanged in principle but the configuration moves:
- The Screen Number area pointer is configured under HMI Device → Connections → Area Pointers in the device configuration.
- The system function in TIA Portal is ActivateScreen (or ActivateScreenByNumber depending on the version) inside a tag-triggered scheduled task.
- STEP 7 V5.5 blocks can be imported as a source file via Export to TIA Portal or manually re-typed in the TIA Portal editor. The hand-shake logic in OB1 is identical.
- The WinCC Migration Guide (TIA Portal) covers the import sequence in detail and lists the area pointer name changes between the two tool families.
After migration, retest the commissioning checklist end-to-end. The most common regression is the area pointer default checkbox being off in the imported project; the symptom is identical to the original "HMI_2 does not follow HMI_1" issue and is fixed the same way.
Engineering Notes and Best Practices
- Use one DB per project for synchronization. Avoid scattering the screen-number tags in M area or in different DBs; the area pointer needs a contiguous 4-byte block.
- Keep the OB1 hand-shake unconditional. Conditional logic (e.g. only in OB35) breaks the acknowledge timing and causes flickering.
- Document screen-number ranges. Both panels should have the same picture-numbering scheme. Renumber pictures with Tools → Renumber Screens before commissioning.
- Reserve picture number 1 for the start screen. The hand-shake initialises both sync registers to 1 so a fresh start always lands on the root picture.
- Audit changes. After every screen-number change in WinCC Flexible, recompile and redownload both panels. The PLC and the HMI configurations are tightly coupled.
Which PLC address should I assign to the Screen Number area pointer on each TP1500?
Point it at the start of the local write region for that panel. For HMI_1, use DB100.DBB0; for HMI_2, use DB100.DBB4. WinCC Flexible reserves the next two bytes for the acquire flag, so the layout becomes Word 0 screen / Word 2 ack / Word 4 screen / Word 6 ack with no overlap.
How many screens does the TP1500 support in this configuration?
The TP1500 Comfort supports up to 500 pictures in WinCC Flexible 2008 SP5. The screen number field is a 16-bit WORD; the runtime rejects values outside 1..500 with a system alarm and falls back to the start screen.
Do I need a special system function or just the standard ActivateScreen?
You need the standard ActivateScreen system function. Configure it inside a tag-triggered scheduled task that fires on value change of the sync_screen tag. Do not use the On Loaded screen event; it does not run on value change.
What happens if one panel is on a maintenance screen and the other is on a process screen?
By default the maintenance panel will pull the process panel into maintenance. Add the lock-out path described in the PLC section: set DB100.DBX12.0 (or DBX12.1) to TRUE from the HMI that wants independent control. The PLC then stops copying the partner's screen into the local sync register.
Can I migrate this to TIA Portal later without re-engineering?
Yes. The hand-shake logic in OB1 and the area pointer configuration are conceptually identical in WinCC (TIA Portal). The WinCC Migration Guide (TIA Portal) documents the import steps and the area pointer name changes. Re-run the full commissioning checklist after migration because the most common regression is the area pointer being disabled by default in the imported project.