Troubleshooting KTP700F 'Error While Reading the BOX ID' Fault

David Krause13 min read
Safety SystemsSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Troubleshooting the KTP700F "Error While Reading the BOX ID" Fault on SIMATIC Mobile Panels

The second-generation SIMATIC KTP Mobile Panels (KTP700F, KTP900F, KTP1200F) integrate PROFIsafe over PROFINET for handheld operator control up to SIL 3 / PL e / Category 4. When the panel runtime cannot resolve the physical connection-box identifier (the BOX ID set on the connection-box rotary switches), it terminates runtime with the dialog:

"Error While reading the BOX ID. Please reconnect the connecting cable or check the safety operation parameter."

This article consolidates the verified field procedure for the KTP700F Mobile (catalog number 6AV2125-2GB23-0AX0) when paired with an S7-1500F CPU such as the CPU 1516F, projects engineered in TIA Portal V14 SP1 through V15.1. The recommended corrective sequence is: (1) hardware isolation, (2) ordered factory reset, (3) PROFINET assignment, (4) PROFIsafe/Box-ID configuration, (5) full project reload, (6) acceptance test.

Functional-safety warning: The Mobile Panel and its connection box participate in a safety chain. Any swap of connection boxes, firmware, or PROFIsafe addresses must be followed by a documented acceptance test before re-introducing the operator station to production. Failure to do so can leave the system in an unverified state.

1. Problem Statement and Observable Symptoms

The fault surfaces immediately on cable insertion between the panel and any connection box belonging to the engineered project. The runtime terminates and the panel becomes inoperable. Symptoms and supporting observations:

  • The error text appears in the KTP700F boot/runtime dialog before HMI tags load.
  • Twelve connection boxes were exercised against the same panel — all twelve produced the identical fault.
  • A spare, freshly unboxed KTP700F (without downloaded configuration) reproduced the error on the existing cable when plugged into a known-good connection box.
  • The PLC application implementing the BOX ID Evaluation program (readback of the panel-reported BOX ID into a data block) reported that no BOX ID was being delivered from the HMI.
  • Changing safety-operation parameters (for example: "Stop button evaluated by safety relay") did not clear the error and produced the same fault dialog.

The fault is not the classic PROFIsafe passivation message (SF-LED steady red, BF-LED red). It is a pre-runtime HMI-level rejection issued by the panel firmware because the BOX ID protocol response from the connection box is either absent, garbled, or fails authentication against the configured value.

2. Affected Hardware and Software Versions

Component Catalog / Version Notes
KTP700F Mobile (button variant) 6AV2125-2GB23-0AX0 7", key+touch, PROFIsafe
KTP700F Mobile (wide-screen, touch) 6AV2145-8GB23-0AX0 Same PROFIsafe behavior
KTP900F Mobile 6AV2145-8JB23-0AX0 9" wide-screen
KTP1200F Mobile 6AV2145-8KB23-0AX0 12" wide-screen
Connection box, standard 6AV2125-2AE23-0AX0 Includes emergency-stop / enable wiring interface
Connection box, compact 6AV2125-2AE13-0AX0 Reduced footprint
S7-1500F CPU (test CPU) 6ES7516-3FN02-0AB0 (CPU 1516F) F-runtime license required
TIA Portal (original project) V14 SP1 Panel had run for ~12 months under this version
TIA Portal (cross-grade) V15 → V15.1 Reproduced same fault after upgrade
Connecting cable 6AV2181-5AF02 / 5AF75 / 5AG60 (length variants) Hybrid (PROFINET + PROFIsafe + 24 V + box-ID signaling)

The full Mobile Panel safety integration — including the BOX ID protocol, connection-box identification, and PROFIsafe channel — is documented in the Siemens application note "Using the 2nd-Generation Mobile Panel in a Safety Application".

3. Root Cause Analysis

The fault has multiple contributing causes that must be ruled out in order. Field experience shows the most common root cause is state divergence between panel non-volatile memory and the configured project, typically after:

  1. TIA Portal upgrade (V15 → V15.1) — the panel firmware boot sequence was extended and the BOX ID handshake lost tolerance for a partial save. Downgrading or re-flashing the panel restores tolerance.
  2. Long-term disconnection (battery / capacitor backup depleted) — the connection-box's identification response can fall out of synchronization with the panel's cached credential. Brief reconnects pass; reconnects after long idle periods fail.
  3. Re-flashed panel without ordered PROFINET re-assignment — the panel accepts the project but reports "no BOX ID" because it never completed the PROFINET/PROFIsafe/Box-ID tri-config required to authenticate the box.
  4. Modified safety parameters without project reload — toggling "Stop button evaluated by safety relay" in isolation re-validates against the previously stored BOX ID handshake, which is no longer consistent.

Hardware root causes (cable pin continuity, defective connection-box ID EEPROM, failed 24 V supply rail on box) must always be eliminated first because they produce indistinguishable runtime messages.

4. Preliminary Diagnostics

Complete the following checks before any software reset. Each is non-destructive and isolates the failure to the software or hardware layer.

4.1 Connection-Cable Pin and Continuity Check

The connecting cable is a hybrid assembly carrying PROFINET (RJ45 pairs), PROFIsafe signaling, 24 V power, and BOX ID lines. Disconnect both ends and verify:

  • 24 V supply pair: < 0.5 Ω end-to-end, > 1 MΩ to ground.
  • PROFINET pairs: continuity on all eight RJ45 lines per TIA-568B; shield bonded at one end only.
  • BOX ID signal lines: continuity and absence of short to power / shield.
  • Connector housings: inspect for bent pins, contamination, or recessed latches (a partially seated connector is the single most common source of intermittent BOX ID failure).

4.2 Connection-Box Rotary Switch Verification

Each connection box has two rotary switches (units and tens digits) for the box identifier. The BOX ID must be unique plant-wide. Verify against the TIA Portal hardware configuration:

  1. Open Devices & Networks → Mobile Panel → PropertiesSafety Operation.
  2. Confirm the configured BOX ID matches the physical rotary switch setting on the box under test.
  3. Re-seat the cable at the box, then at the panel, and observe the box LEDs.

4.3 LED Status Interpretation

LED Color / State Interpretation
PWR Green, steady 24 V supply OK
PN (LINK) Green, steady PROFINET link up
SF Off No system fault (still required to clear runtime error)
BF Off PROFINET communication OK
SF / BF Red flashing PROFIsafe or PROFINET configuration mismatch — proceed to §5
BOX (where present) Yellow BOX ID handshake in progress

5. Factory Reset Sequence (Authoritative Procedure)

Field experience on multiple identical installations has shown that the order of operations is critical. A factory reset that omits any step, or that performs the steps out of order, leaves the panel in a state where the BOX ID readback either never completes or fails immediately after a long disconnect.

  1. Trigger Factory Reset from TIA Portal. Use Online > Maintenance > Reset to factory settings on the panel device. Wait for the panel to reboot into transfer mode.
  2. Cancel the automatic transfer prompt that appears after the reset. Do not start a compile-download at this stage.
  3. Open the Control Panel on the panel. Use the panel's local touch / button interface.
  4. Navigate to PROFINET. Enable the PROFINET interface. At this stage you may set the device name on the panel itself, or defer this to step 6 and assign from TIA.
  5. Assign IP address and subnet mask consistent with the project. Match the device name case-sensitively to the value configured in TIA Portal (including any suffix such as .port-1).
  6. Set the PROFIsafe address on the Mobile Panel via the Control Panel > PROFIsafe (or Safety Operation) dialog. The default value of 0 is invalid; use a unique F-Destination address in the range permitted by the device (typically 1–1022).
  7. Open the "Safety Operation" menu and select the operation mode that matches your application (for example: Stop button evaluated by safety relay, or Stop button evaluated by F-CPU).
  8. Set the BoxID to the value matching the connection box's rotary switch, and save.
  9. Load the complete Mobile Panel project from TIA Portal. Use a full project compile-download (not an individual HMI-tag delta). Allow the runtime to start.
  10. Verify the BoxID is retained. Navigate to Settings > Safety Operation. On current panel firmware, the BoxID may not be displayed in this menu; verify operationally instead by unplugging and re-plugging the cable and confirming runtime continues without the BOX ID error.
Why the order matters: The panel firmware initializes its non-volatile caches in a specific sequence. PROFINET assignment must precede PROFIsafe address assignment, which must precede BoxID binding. Skipping or reordering these steps — for example, by writing the PROFIsafe address via TIA's "Accessible nodes" before the panel has accepted the PROFINET name — produces the exact fault reported here.

5.1 Quick-Recovery Sequence (Long-Disconnect Workaround)

For installations where the panel can be disconnected for longer than the backup-hold duration (typically several hours to a few days depending on internal capacitor state), adopt the following tactical sequence at every power-up. It is not a permanent fix but has been verified on four production lines as a repeatable recovery:

  1. Power up the panel with the cable disconnected.
  2. Wait for full boot and login.
  3. Connect the cable to the connection box.
  4. If the BOX ID error appears, disconnect the cable, power-cycle the panel, and reconnect.

Track each occurrence; if the panel requires more than two reconnects per shift, escalate to a full factory reset (§5) and consider a firmware re-flash (§9).

6. PROFINET Configuration on the Panel

After the factory reset, the PROFINET interface must be re-bound to the device name that TIA Portal expects:

  1. Open TIA Portal, navigate to Online > Accessible nodes.
  2. Identify the panel's MAC address (printed on the rear label).
  3. Right-click the device → Assign PROFINET device name. Match the project-configured name exactly (case-sensitive).
  4. Confirm the assignment from the panel's Control Panel under PROFINET > Device name.
Parameter Typical Value Notes
PROFINET device name kp700f-station-1 Must match TIA project exactly
IP address 192.168.0.50 Per project subnet plan
Subnet mask 255.255.255.0 Per project
PROFINET mode PN IO Device Fixed for Mobile Panel
Port 1 / Port 2 Enabled, autonegotiation Disable unused ports

7. PROFIsafe Address and Box ID Configuration

The PROFIsafe address and the BOX ID are distinct identifiers and must not be confused:

  • PROFIsafe address (F-Destination address) — identifies the Mobile Panel as the PROFIsafe slave on PROFINET. Configured in the TIA Portal project and downloaded to the panel.
  • Box ID — identifies the physical connection box. Configured via rotary switches on the box and matched in the TIA Portal hardware configuration under Safety Operation > BoxID.

7.1 PROFIsafe Parameter Set (F-Parameters)

F-Parameter Typical Value Source of Truth
F-Destination address 1–1022 (unique per panel) Set in panel Control Panel or TIA
F-Source address Assigned by F-CPU CPU-side configuration
F-Watchdog time (F-Monitoring time) 100–500 ms typical CPU-side
F-Behavior on communication error Passivation Per F-CPU standard
iParameter signature (iParCRC) Computed at compile Auto-generated

7.2 BoxID Readback Logic in the PLC

Implement a diagnostic data block in the F-CPU that mirrors the runtime-reported BOX ID and compares it to the configured value. Example in SCL:

// SCL: BoxID readback and consistency check (non-safety diagnostic)
// Place in a standard OB (not in F-runtime OB1)
"DB_BoxID_Diag".BoxID_Runtime    := "HMI_BoxID_Tag";      // provided by panel
"DB_BoxID_Diag".BoxID_Configured := "Configured_BoxID_DB"; // from project

IF "DB_BoxID_Diag".BoxID_Runtime = "DB_BoxID_Diag".BoxID_Configured
   AND "DB_BoxID_Diag".BoxID_Runtime <> 0 THEN
    "DB_BoxID_Diag".BoxID_OK := TRUE;
    "DB_BoxID_Diag".BoxID_Error := FALSE;
ELSE
    "DB_BoxID_Diag".BoxID_OK := FALSE;
    "DB_BoxID_Diag".BoxID_Error := TRUE;
END_IF;

This block is for diagnostics only; the safety decision is taken by the F-runtime. If BoxID_Error is persistently TRUE after a fresh factory reset, re-check the rotary switches and the TIA configuration against §4.2.

8. Cable and Connection-Box Hardware Verification

If the ordered factory reset does not resolve the fault, perform hardware substitution in the following order:

  1. Substitute the connecting cable with a known-good unit. Keep the cable length < 25 m unless the application demands longer (longer cables are supported but introduce higher signal-integrity risk for the BOX ID handshake).
  2. Substitute the connection box. The connection-box's ID EEPROM can fail intermittently without LED indication; substitution is the only fast test.
  3. Substitute the Mobile Panel. A second confirmed-good panel isolates the failure to the original panel's non-volatile configuration.
  4. Verify the 24 V supply at the connection box terminals under load. Voltage must remain above 20.4 V (lower limit of Siemens 24 V tolerance) with all safety circuits active.
  5. Inspect the emergency-stop loop. An open emergency-stop can mask the BOX ID handshake on some firmware revisions.

Field experience has shown that all three substitutions may be necessary before the fault clears in worst-case scenarios.

9. Firmware Update Procedure

Where the fault first appeared after a TIA Portal upgrade (V15 → V15.1) or after a long service interval, re-flash the panel firmware to a known-stable version:

  1. Download the correct firmware package from the Siemens Industry Online Support portal. Confirm the firmware matches the panel's article number (for example: 6AV2125-2GB23-0AX0).
  2. Connect the panel directly to the engineering PC via PROFINET (do not use the connection box).
  3. In TIA Portal, Online > HMI Device Maintenance > Firmware Update. Select the .fwf file and proceed.
  4. Wait for completion; do not interrupt power.
  5. After reboot, re-execute §5 in full.
Pinning recommendation: Once a working combination of TIA Portal version and panel firmware is identified, document it in the project header (TIA Portal Project > Properties) and the customer's maintenance binder. Cross-version upgrades have historically been the primary trigger for this fault class.

10. Verification and Commissioning Tests

After the corrective procedure, perform and document the following acceptance tests before returning the station to production:

Test Expected Result Pass Criterion
Cold power-up with cable connected Runtime starts within 30 s No BOX ID error dialog
Hot swap (cable disconnect / reconnect < 5 s) Runtime continues No restart required
Long-disconnect test (60 min) Runtime restarts without BOX ID error Apply quick-recovery from §5.1 if needed; re-test after full reset
Emergency-stop press Safety function trips F-CPU enters safe state per project
Enable-button release Safety function trips Same as above
BoxID readback (PLC diagnostic block) BoxID_OK = TRUE BoxID_Runtime = BoxID_Configured
Connection-box substitution Runtime restarts with new box ID Re-assign BoxID per project

11. Known Field Issues and Workarounds

11.1 BoxID Not Visible in Settings Menu

On recent panel firmware revisions the BoxID is intentionally not displayed in the Settings menu, even when correctly saved. This is by design — the runtime value is held in the safety layer, not in the HMI settings database. Verification must be operational (§10) or via the PLC readback (§7.2).

11.2 BoxID Persists Only Briefly After Disconnect

Where the BOX ID error reappears after a long disconnect but clears on a brief disconnect-reconnect, the panel's capacitor-backed parameter memory is degrading. Apply the quick-recovery sequence (§5.1) at every operator shift handover and budget for panel replacement within one maintenance window.

11.3 Fault Reproduced Across Multiple Panels

If the fault appears across multiple panels and connection boxes simultaneously, the most likely root cause is a project-side parameter corruption (e.g., a re-compile with a different iParameter CRC). Re-compile the entire project from source and download to all panels.

12. Frequently Asked Questions

What does the KTP700F error "Error While reading the BOX ID" actually mean?

It means the panel cannot complete the BOX ID handshake with the connection box — the panel is either not receiving a valid ID response, or the ID it receives does not match the value configured in TIA Portal under Safety Operation > BoxID. The runtime is rejected pre-start.

Is this a hardware or a software fault?

It can be either. Verify the cable, connector seating, and connection-box 24 V supply first. If hardware substitution does not resolve it, the panel's non-volatile configuration is the next suspect and an ordered factory reset (§5) is required.

Why did the panel work under TIA Portal V15 but fail after upgrading to V15.1?

The V15.1 panel firmware tightened the BOX ID handshake validation and changed how non-volatile parameters are cached. Panels that retained a partial BoxID save from V15 will fail the new handshake. A full factory reset and ordered re-configuration (§5) restores operation.

Can I bypass the BOX ID check to bring the line back up?

No. The BOX ID is part of the PROFIsafe safety contract. Disabling it would leave the safety chain unverifiable and is not supported by Siemens. Use the quick-recovery sequence (§5.1) to keep the line running while a full reset is scheduled.

How do I confirm the BoxID is correctly read at runtime?

Implement the readback block shown in §7.2 in the F-CPU. Monitor DB_BoxID_Diag.BoxID_OK in TIA Portal's online view. If the bit is FALSE and BoxID_Runtime = 0, the panel is not receiving a BOX ID at all — proceed to hardware substitution (§8). If BoxID_Runtime is non-zero but mismatched, correct the rotary switches or the TIA configuration.

Back to blog