Troubleshooting PC Station OPC UA Connection to S7-1200 in TIA Portal
Connecting a SIMATIC PC Station to an S7-1200 CPU using OPC UA is a standard integration pattern, but commissioning engineers frequently hit a wall at the "Compile and Download PC Station Configuration" step. The browser shows only the S7-1200 PLC, the PC Station entry remains invisible, the IE General module refuses to accept a custom MAC/IP, and the download ultimately fails. This reference covers every verified root cause for that failure mode, the exact Station Configuration Editor (SCE) slot layout required for the S7-1200 V4 firmware family, and the load procedure using both DCP discovery and the offline XDB approach.
1. Problem Description
During the commissioning of an S7-1200 to PC Station OPC UA link, the following symptoms are reported:
- The TIA Portal "Compile and Download PC Station Configuration" dialog opens the "Select target device" browser.
- The browser enumerates only the S7-1200 CPU, never the locally configured PC Station.
- Adding an IE General module into Slot 1 of the PC Station via the Station Configuration Editor produces a default entry that cannot be edited (the MAC address and IP address fields stay grayed or revert to the default CP 1623/PC interface MAC).
- No OPC server slot is visible in the Station Configuration Editor, so the compile fails with diagnostic buffer entries referring to a missing OPC entry, or the download rejects the configuration because the hardware catalog is incomplete.
- When the IE General can be added, ping from the engineering station to the PC Station IP succeeds, but TIA Portal still cannot find the PC Station target.
The expected behavior is that the Station Configuration Editor exposes both the IE General (operating as the OPC UA gateway's Ethernet interface) and the OPC server on a defined slot, and that the TIA Portal browser resolves the PC Station as a downloadable target by IP or XDB file.
2. Affected Versions and Topology
| Component | Version / Model | Relevance |
|---|---|---|
| CPU firmware | S7-1200 V4.x and higher | Required for the integrated OPC UA server; V3.x only supports S7 communication |
| Engineering software | TIA Portal V15.1 and higher (V16/V17 commonly deployed) | Provides PC Station type "SIMATIC PC Station" and OPC UA client blocks |
| PC Station runtime | SIMATIC NET PC software V15.1+ (for OPC UA), V16/V17 recommended | Hosts the IE General, OPC server, and S7 connection |
| PC network interface | Standard Ethernet NIC, Intel/Broadcom recommended | Bound to IE General in Station Configuration Editor |
| OPC UA server port on S7-1200 | TCP 4840 (default; certs on 4840, discovery on 4840) | Distinct from S7 port 102 |
| OPC UA client (engineering side) | TIA Portal OPC UA client, or third-party (Ignition, Kepware, etc.) | Targets opc.tcp://<PLC_IP>:4840 |
3. Root Cause Analysis
Five distinct causes produce the same observable failure. Treat them as a diagnostic matrix; verify each in order before escalating.
3.1 Empty Station Configuration Editor
If the Station Configuration Editor is opened and no module is placed in any slot, the PC Station is functionally empty. The OPC server software is not loaded, no S7 connection endpoint exists, and the TIA Portal browser will not find a target. Many engineers add only the OPC server in Slot 1 and forget the IE General, which causes the OPC server to fail its internal endpoint initialization because it has no lower-layer network interface.
3.2 Wrong Module Indices in SCE
SIMATIC NET requires the IE General in Index 1 (or the lowest available index) and the OPC server in the next free index. If the OPC server is dragged into Index 1 and the IE General into Index 2, the order is rejected at compile time with a "Configuration inconsistent" error and the download cannot proceed.
3.3 NIC Not Bound to the IE General
When the IE General is added but the dropdown for the PC network adapter is left at "(none)", the IE General has no physical binding. The MAC/IP edit fields appear locked because the binding determines the MAC. The PC Station cannot be reached by the TIA Portal browser because the IP you typed is not actually attached to a configured interface from the runtime's perspective.
3.4 DCP Discovery Blocked
By default, "Browse" in the "Compile and Download PC Station Configuration" dialog uses the DCP (Discovery and Configuration Protocol) protocol - the same protocol that PROFINET devices use to advertise themselves. DCP discovery works by sending a multicast/broadcast Ethernet frame. If a managed switch filters multicast, if VLAN tagging is misconfigured, or if the NIC's firewall profile blocks inbound DCP, the PC Station never answers. The result: the PLC is visible (PROFINET-capable, replies to DCP), the PC is not.
3.5 Windows Firewall, Antivirus, and Third-Party Security Software
Windows Defender Firewall with the "Public network" profile blocks the SIMATIC NET broadcast listener ports by default. Third-party endpoint protection suites (Symantec, McAfee, Trend Micro, Sophos, CrowdStrike) can block the DCP receiver socket even when the firewall rule is open. This is the single most common field failure and should be eliminated first.
4. Prerequisites
Before starting the corrective procedure, validate the following:
- CPU firmware is V4.0 or higher. Verify in TIA Portal under Online → Diagnostics → Online & Diagnostics. The OPC UA server only exists from V4.0. See the S7-1200 manual collection OPC UA configuration overview.
- OPC UA server is enabled on the S7-1200. In the CPU device configuration, navigate to OPC UA → OPC UA server and tick "Activate OPC UA Server". A server certificate is generated automatically; set the security policy to "None" for commissioning, then switch to "Basic128Rsa15" or "Basic256Sha256" for production.
-
OPC UA port matches. Default 4840 on the S7-1200 side. The TIA Portal OPC UA client block
OPC_UA_Connectuses the same port. Verify with a test client (UaExpert, Prosys) usingopc.tcp://<PLC_IP>:4840. - Engineering PC and S7-1200 are on the same subnet (e.g. 172.26.15.0/24). The PC Station IP and the engineering PC IP must be in the same broadcast domain.
- SIMATIC NET PC software is installed on the PC Station. The installer must match the TIA Portal version (e.g. TIA V16 → SIMATIC NET V16).
- User has local administrator rights on the PC Station for the Station Configuration Editor and the SIMATIC NET configuration console.
5. Step-by-Step Resolution
5.1 Build the PC Station Configuration in the Project Tree
- In the TIA Portal project tree, right-click Devices → Add new device.
- Choose PC systems → SIMATIC PC Station. Assign a name that matches the hostname of the runtime machine (recommended for clarity, not required).
- Open Device view on the PC Station. The slot chassis opens with Index 1, Index 2, etc. empty.
- From the hardware catalog, drag IE General into Index 1 of the PC Station.
- From the hardware catalog, drag OPC server into Index 2 of the PC Station.
5.2 Configure the IE General
- Select Index 1 (IE General) in the device view.
- In the inspector pane under Properties → General → Interface, verify the network adapter assignment. If the dropdown is empty, the SIMATIC NET installation is incomplete or the NIC driver does not support the SIMATIC NET binding.
- Set the IP address of the IE General to the planned PC Station IP, e.g.
172.26.15.233, subnet mask255.255.255.0. - Leave the MAC address at "Automatically generate" unless the project requires a specific MAC. The PC Station uses the host NIC's MAC when the runtime starts.
- Compile the PC Station (Project tree → PC Station → right-click → Compile → Hardware (rebuild all)).
5.3 Mirror the Configuration in the Station Configuration Editor
The Station Configuration Editor (SCE) on the PC Station must match the TIA Portal project exactly. Open SCE from Start → SIMATIC → Station Configuration Editor.
- In SCE, click Add... and select the IE General from the module list. Place it in Index 1.
- Click Add... and select the OPC server. Place it in Index 2.
- Double-click the IE General entry. Under Network connection, bind it to the physical NIC. Under IP address, enter the same IP you used in TIA Portal (
172.26.15.233) with the same subnet mask. - Save the SCE configuration. SCE writes the XDB file used by the runtime.
5.4 Compile and Download the PC Station
Two download paths exist. Try the online path first; fall back to the XDB path if discovery fails.
5.4.1 Online Path with TCP/IP Browse
- In TIA Portal, right-click the PC Station and choose Compile → Compile and download PC station configuration.
- In the "Select target device" dialog, change the dropdown filter from "Show all compatible devices" to "Show devices with the same IP address". This bypasses the DCP broadcast and resolves the target directly by TCP/IP.
- Click the Access address column and type the PC Station IP
172.26.15.233. Click outside the field to commit the entry. - TIA Portal attempts a direct TCP connection. The PC Station entry should appear. Click Load.
5.4.2 Offline Path with the XDB File
If the online path still fails, use the offline load:
- Compile the PC Station in TIA Portal. Note the output XDB file path (typically
%ProgramData%\Siemens\Automation\<project>\PCStation\<name>.xdb). - Copy the XDB file to the PC Station at
C:\ProgramData\Siemens\Automation\<project>\<name>.xdb. - Open SCE on the PC Station. Station → Import Station. Select the XDB file.
- Restart the SIMATIC NET runtime service:
sc stop "S7RTM"andsc start "S7RTM"from an elevated command prompt, or restart the "SIMATIC NET" service via services.msc. - Once the runtime is up, return to TIA Portal and use the online path; the PC Station is now reachable.
5.5 Eliminate the Windows Firewall and AV Interference
- Open Windows Defender Firewall with Advanced Security.
- Add an inbound rule allowing
%ProgramFiles%\Siemens\Automation\SIMATIC.NET\S7RTMSRVX.exeon UDP port 34964 (DCP) and TCP ports 102, 4840, and the SIMATIC NET range 49152-65535. - For initial commissioning, set the network profile to "Private" rather than "Public". Public blocks inbound DCP by default.
- Disable third-party AV/endpoint protection suites temporarily. Many ship with application-control rules that block raw Ethernet broadcast sockets used by DCP.
- From the engineering PC, run
ping 172.26.15.233. A successful ping proves IP-level connectivity but does not prove DCP is unblocked.
5.6 Activate the OPC UA Server on the S7-1200
- In TIA Portal, open the S7-1200 device configuration.
- Navigate to OPC UA → OPC UA Server.
- Tick Activate OPC UA server.
- Set Port to 4840 (default).
- Choose the security policy. For lab use, "None" is acceptable. For production, use Basic256Sha256 with a server certificate signed by the project CA.
- Compile and download the CPU configuration.
- Verify with a third-party OPC UA client:
opc.tcp://172.26.15.10:4840should return a list of namespaces including the S7-1200 tag namespace.
6. Verification
After the corrective steps, run the following checks in order. Each must pass before the next is attempted.
| # | Check | Method | Expected Result |
|---|---|---|---|
| 1 | PC Station reachable at IP |
ping 172.26.15.233 from engineering PC |
< 1 ms response, 0% loss |
| 2 | PC Station visible in TIA browser | "Compile and download PC station configuration" | PC Station listed with correct IP |
| 3 | PC Station load completes | Click "Load" in browser | "Download completed successfully" |
| 4 | SIMATIC NET runtime active | SCE diagnostics view | IE General "RUN", OPC server "RUN" |
| 5 | S7 connection established | SCE → OPC server → S7 connections | Connection state = "established" |
| 6 | OPC UA server reachable on S7-1200 | UaExpert or equivalent | Endpoint opc.tcp://172.26.15.10:4840 returns servers |
| 7 | Tag browse from OPC UA client | Drag a tag from S7-1200 program to UA client | Value updates with PLC scan cycle |
If step 2 fails but step 1 passes, the issue is at the SIMATIC NET runtime layer. Restart the S7RTM service and re-attempt.
7. Configuration Parameter Reference
| Parameter | Default | Recommended for S7-1200 | Notes |
|---|---|---|---|
| PC Station IP | 0.0.0.0 | Static address in PLC subnet | Must match SCE binding |
| PC Station subnet | 0.0.0.0 | 255.255.255.0 | Match the S7-1200 subnet |
| IE General MAC | Auto | Auto (host NIC) | Override only for redundancy |
| OPC server slot (Index) | None | Index 2 | Index 1 reserved for IE General |
| S7 connection type | None | S7 connection (single) | Configured in OPC server properties |
| S7 connection partner IP | None | S7-1200 IP (e.g. 172.26.15.10) | Used by OPC server to reach PLC |
| S7 connection TSAP local | None | 01.01 | OPC server side |
| S7 connection TSAP remote | None | 01.01 | PLC side; must match the S7-1200 protection list |
| OPC UA server port (PLC) | 4840 | 4840 | Distinct from S7 port 102 |
| OPC UA security policy (PLC) | None | Basic256Sha256 (prod) | Drives certificate handling |
| DCP UDP port | 34964 | 34964 (open) | Must be allowed in Windows firewall |
| S7 TCP port | 102 | 102 (open) | Used by OPC server → PLC |
8. Diagnostic Matrix by Symptom
| Observed Symptom | Most Likely Cause | Corrective Action |
|---|---|---|
| Only PLC visible in browser | DCP discovery blocked, or empty PC Station | Use "Show devices with same IP" filter; verify SCE has IE General + OPC server |
| IE General MAC/IP fields grayed | No NIC bound to IE General in SCE | Re-open SCE, bind IE General to physical adapter, then re-enter IP |
| Download fails immediately | Slot order wrong or runtime service down | Place IE General in Index 1, OPC in Index 2; restart S7RTM service |
| Ping works, TIA still cannot find PC | Firewall / AV blocking SIMATIC NET ports | Disable third-party AV temporarily; open UDP 34964 in Windows firewall |
| OPC UA client cannot browse tags | Wrong port (102 vs 4840) or OPC UA disabled on PLC | Confirm opc.tcp://<PLC_IP>:4840 and "Activate OPC UA server" ticked |
| Tags visible but values stay "Bad" | S7 connection not established on OPC server | Check SCE → OPC server → connections; verify TSAP pair |
| Browser sees PC Station intermittently | Network profile flips to Public | Set Windows network profile to Private persistently |
9. Common Field Errors and Lessons Learned
- TIA Portal and SIMATIC NET version mismatch. TIA V16 projects require SIMATIC NET V16 on the runtime. A V15 SCE configuration will not load against a V16 TIA Portal project. Always install the matching SIMATIC NET version.
- S7-1200 protection list. Even when the OPC server establishes an S7 connection, the PLC's local connection list must allow the partner IP. By default, S7-1200 V4 has an unrestricted access level when no project password is set; once a password is added, the access level must be set to "Full access (no protection)" or the partner must be added to the connection list.
- CPU in STOP. The OPC UA server on the S7-1200 only publishes values when the CPU is in RUN. If the CPU is in STOP, the OPC UA browse succeeds but all tag values return "Bad".
- Duplicate IP addresses. If another device on the subnet uses the planned PC Station IP, DCP replies with the wrong target. Always ping the intended IP first to confirm it is free.
- Multicast suppression on managed switches. IGMP snooping enabled without an IGMP querier can silently drop DCP multicast. Disable IGMP snooping on the switch port used for commissioning, or configure an IGMP querier.
- Virtual machines. Running the PC Station in a VM requires the hypervisor virtual switch to allow promiscuous mode. VMware Workstation, Hyper-V, and VirtualBox all default to non-promiscuous, which breaks DCP. The "Show devices with the same IP address" filter rescues this scenario.
10. Quick-Reference Procedure
For engineers who want a single ordered checklist, this is the canonical sequence:
- Confirm S7-1200 firmware ≥ V4.0 and "Activate OPC UA server" is ticked.
- Install matching SIMATIC NET version on the PC Station.
- In TIA Portal, add a SIMATIC PC Station; place IE General in Index 1 and OPC server in Index 2; assign the planned IP.
- Open the Station Configuration Editor on the PC Station; mirror the same modules and bind IE General to the physical NIC; assign the same IP.
- Open the matching Windows network profile as "Private".
- Disable third-party AV / endpoint protection.
- Compile the PC Station in TIA Portal.
- Use Compile and download PC station configuration with the filter set to "Show devices with the same IP address"; type the PC Station IP into the Access address column.
- If the online path still fails, perform an offline load via the XDB file and restart the SIMATIC NET runtime service.
- Verify the S7 connection state, then verify OPC UA with a third-party UA client against
opc.tcp://<PLC_IP>:4840.
11. Related Topics and Cross-References
- Siemens Application Example 39960679 – Connecting a PC Station to an S7-1200 using OPC UA (PDF available under the entry's attachments).
- S7-1200 Manual Collection – Overview of OPC UA Server Configuration – TIA Portal cloud documentation covering the OPC UA server enablement, port, security policy, and certificate handling on the CPU.
FAQ
Why does the TIA Portal browser only find the S7-1200 and not the PC Station?
The default browse uses DCP (UDP 34964) over Ethernet broadcast. If the SIMATIC NET runtime has not yet loaded a configuration, no service is listening for DCP, so the PC Station is invisible. Switch the filter to "Show devices with the same IP address" and type the PC Station IP (for example 172.26.15.233) into the Access address column. TIA Portal then resolves the target via TCP/IP directly, bypassing DCP.
The IE General module in the Station Configuration Editor does not let me change the IP or MAC. What is wrong?
The IP and MAC fields are locked when no physical NIC is bound to the IE General. Open the Station Configuration Editor, select the IE General, go to Properties → Network connection, and pick the actual Ethernet adapter of the PC. Once bound, the IP field becomes editable and the MAC defaults to the host NIC's MAC.
Which slot must the IE General and the OPC server occupy in the PC Station?
The IE General must be in Index 1 (the lowest available index). The OPC server must be in the next free index, typically Index 2. Reversing the order causes the runtime to refuse the configuration and the download fails with "Configuration inconsistent".
What port does the S7-1200 OPC UA server use and how is it different from S7 communication?
The S7-1200 OPC UA server uses TCP port 4840 by default. S7 communication (used by the SIMATIC NET OPC server to talk to the CPU) uses TCP port 102. A common error is to point an OPC UA client at port 102, which returns a connection error because S7 is not an OPC UA protocol.
After enabling OPC UA on the S7-1200, tags are visible in the UA client but values stay "Bad". What should I check?
Verify that the CPU is in RUN, that the S7 connection between the PC Station OPC server and the S7-1200 is established in the Station Configuration Editor, that the TSAP pair matches, and that the PLC's access level allows the partner. Also confirm that the OPC UA security policy in the client matches the policy configured on the CPU (None, Basic128Rsa15, or Basic256Sha256).
Can the PC Station be virtualized? What breaks DCP in a VM?
Yes, but the virtual switch must allow promiscuous mode and multicast/broadcast. VMware Workstation, Hyper-V, and VirtualBox default to non-promiscuous mode, which prevents DCP from receiving replies. Use the "Show devices with the same IP address" filter in TIA Portal as a workaround, or configure the virtual switch for promiscuous mode.