Troubleshooting S7-1214C TCON Status 7002 With RST-ACK From PC
1. Problem Statement and Symptom Capture
An S7-1200 CPU 1214C (order number 6ES7 214-1HG31-0XB0, firmware V3.0) fails to complete an outbound TCP connection to a Windows PC. The PLC project uses the TCON instruction block from the Siemens "TCP\u00a0conn. example" application set, compiled in TIA Portal. After the call to TCON with REQ := TRUE, the following conditions are observed on the watch table:
-
BUSY=TRUEcontinuously (never returns toFALSE). -
DONE=FALSE(connection is never confirmed as established). -
ERROR=FALSE(no protocol error is reported). -
STATUS=W#16#7002for the entire duration of the call.
Layer-3 connectivity is fine: the PC and the CPU ping each other. Both are on the same subnet. Windows Firewall and the installed antivirus (AV) have been disabled. A Wireshark capture on the PC Ethernet interface shows the following three-way-handshake pattern:
- CPU \u2192 PC:
SYNto TCP port 2000 (correct source IP, correct destination IP). - PC \u2192 CPU:
RST, ACK(instead of the expectedSYN, ACK). - CPU retries the
SYNafter the standard retransmission interval, the PC again answers withRST, ACK.
The TCP stack of a Windows host emits RST, ACK only when it has decided to refuse the connection \u2014 not when it is busy. A RST, ACK during the initial handshake is the kernel's way of saying: "there is no socket here for you to talk to, or you are not allowed to talk to it." The PLC therefore reports 7002 indefinitely because no SYN, ACK ever arrives.
W#16#7002 on TCON is not a transient condition. The connection state machine of the CPU is waiting for the partner to accept the TCP session. The bug is almost always on the partner (PC) side, not on the S7-1200.2. Decoding TCON Status 7002
The STATUS word of TCON (and its companion TDISCON/TSEND/TRCV) is a standardized Siemens W#16# value. The relevant codes for the connection-establishment phase are:
| STATUS (hex) | STATUS (dec) | Meaning | Action |
|---|---|---|---|
7000 |
28672 | Connection not yet established; idle state. | Normal before the first call. |
7001 |
28673 | Connection setup in progress (first call with REQ=TRUE). |
Wait for completion. |
7002 |
28674 | Connection setup in progress (intermediate / repeat call). | Wait, but investigate if > 30 s. |
7003 |
28675 | Connection currently being terminated by TDISCON. |
Wait for teardown. |
80C0 |
32960 | Connection terminated by partner. | Check partner application. |
80C1 |
32961 | Connection terminated locally (e.g. TDISCON). |
Normal after teardown. |
80C3 |
32963 | Connection terminated by partner or network error. | Check link / partner. |
8180 |
33152 | Parameter error in TCON block / connection DB. |
Inspect the TCON_IP_RFC data block. |
8183 |
33155 | Max. number of connections reached. | Free an active connection. |
8186 |
33158 | Connection ID already in use. | Use a unique ID per connection. |
A value of 7002 persisting beyond 20-30 seconds, combined with BUSY=TRUE and ERROR=FALSE, means the S7-1200's CP (the integrated PROFINET interface) is still transmitting SYN segments and has not yet received the SYN, ACK that the partner should produce. The PLC is doing its job; the partner is not.
3. Wireshark RST-ACK Forensics: What the PC is Telling You
The Wireshark trace is the definitive diagnostic when the handshake breaks. The PC's response of RST, ACK instead of SYN, ACK on the first SYN has one and only one cause from the Windows TCP/IP stack perspective: no application is in LISTEN state on the destination port. This can be confirmed independently:
- On the PC, open an elevated command prompt and run
netstat -ano -p TCP | findstr :2000. - Look for an entry in state
LISTENINGwithLocal Address 0.0.0.0:2000(or[::]:2000for IPv6). - If the command returns nothing, the application you expect to accept the connection is not bound to port 2000 \u2014 or is not running at all.
Secondary confirmation: launch a temporary listener in PowerShell and re-trigger the TCON. A one-line TCP listener can be used as a sanity check:
powershell -NoProfile -Command "$l = New-Object System.Net.Sockets.TcpListener([System.Net.IPAddress]::Any, 2000); $l.Start(); while($true){Start-Sleep 1}"
If the connection succeeds while this listener runs, the problem is guaranteed to be "no real application listening on 2000". Stop the listener with Ctrl+C after the test.
SYN arriving with no reply at all \u2014 not an RST, ACK.4. Root-Cause Matrix for TCON \u2192 7002 With RST-ACK
| # | Likely Root Cause | Indicator | Fastest Verification |
|---|---|---|---|
| 1 | No PC application listening on TCP port 2000. | Wireshark shows RST, ACK with the CPU source IP as the destination. |
netstat -ano -p TCP | findstr :2000 returns nothing in LISTENING. |
| 2 | PC application is listening, but on a different port (e.g. 2001 or 5000). |
RST, ACK still appears, but the netstat result shows another port listening. |
Change PLC TCON "Remote Port" to match the listening port. |
| 3 | Windows Firewall is "off" in the GUI but a third-party firewall (Kaspersky, ESET, Bitdefender, Norton, McAfee) is still filtering. |
netstat shows the listener, but Wireshark still shows RST, ACK. |
Temporarily fully uninstall / disable the security suite and retest. |
| 4 | Antivirus HIPS / Web Shield / Exploit Prevention feature inspects raw TCP and drops the session. | Same as #3, plus the AV log may show "blocked inbound connection". | Disable each AV module individually; re-enable Windows Firewall during the test. |
| 5 | PLC and PC are on different VLANs that allow ping (ICMP) but drop TCP/2000. | Ping works; SYN leaves the CPU but no reply, or RST, ACK from a different MAC than expected. |
Trace the route, or temporarily put the devices on the same unmanaged switch. |
| 6 | Duplicate connection ID ID in the TCON block (already used by another open instruction). |
STATUS 8186 usually appears \u2014 but with corrupted projects 7002 is possible. |
Set the ID to a unique value (1, 2, 3\u2026) per open connection. |
| 7 | CPU has not been reloaded after the project change; the running firmware is the old binary. | Watch table shows new IP but PLC still sends SYN from old IP, or 7002 is intermittent. |
Full Stop \u2192 Warm restart, or download "Hardware and software (complete)". |
| 8 | TCON InterfaceId is wrong (PROFINET interface GUID mismatch after project migration). |
STATUS 8180 or 80C4; sometimes 7002 if the parameter is silently rejected. |
Delete the connection DB and re-create the TCON call from scratch. |
5. TCON Configuration Verification (PLC Side)
The CPU 1214C FW 3.0 supports the legacy TCON, TSEND, TRCV, and TDISCON blocks as well as the newer TCON_v2 family. For a passive partner (PC acts as server) the PLC is the active connection opener. The connection DB is normally generated automatically by TIA Portal when you drop a TCON block and assign a new instance DB \u2014 the values can be inspected in the data block view. Verify the following fields:
| Parameter | Required Value for the Reported Symptom | Wrong Value to Watch For |
|---|---|---|
InterfaceId |
64 (decimal) = 16#40, the CPU's PROFINET interface, slot 0, sub-slot 1. |
Any value other than 16#40 \u2014 the instruction cannot bind. |
ID |
Unique integer 1 \u2013 4095 across all open TCON instances. | 0, or reused ID. |
ConnectionType |
16#0B (TCP/IP) or 16#11 (TCP/IP with ISO-on-TCP). Use 0B for a Windows socket partner. |
16#01 (ISO transport) \u2014 not valid for WinSock. |
ActiveEstablished |
TRUE if the S7-1200 initiates; FALSE if it waits for a partner. |
FALSE when the partner is a Windows server \u2014 the S7 will listen, but the PC does not know to call in. |
LocalPort |
0 (any) or a specific unused port such as 2001. |
Same value as RemotePort if the PC is also binding to that port. |
RemoteAddress |
PC IP, e.g. 192.168.0.10, in ADDR as a REMOTE_IP_v4 structure (4 bytes). |
Loopback (127.0.0.1) \u2014 will not be routed to the Ethernet port. |
RemotePort |
2000 (decimal) matching the PC listener. |
Different port \u2014 triggers RST, ACK. |
A common copy/paste error: copying the example project that targets another CPU (e.g. 1515) and leaving InterfaceId = 16#FE in the connection DB. The 1214C ignores the TCON silently in that case \u2014 you get exactly the symptom described. Re-create the TCON block fresh in the 1214C project so TIA Portal writes the correct interface ID.
6. Port 2000 Socket Listener Inspection (PC Side)
TCP port 2000 is in the IANA "registered" range. It is used by several applications (default for some SCCP / UniVerse integrations and some legacy Siemens COM tools) and is also a popular choice for example projects. Windows does not block port 2000 by default, but a service listening on it is not part of the operating system. The PC must therefore run an explicit server.
When a port has no listener, the TCP behavior in Windows is defined by SynAttackProtect, EnableConnectionRateLimiting, and (most relevant here) the socket itself. The kernel responds with RST, ACK for every SYN that targets a port without a LISTEN-state socket. The PLC sees the RST, internally resets the attempt counter, and resends the SYN after the retransmission timeout (typically 1 s, 2 s, 4 s \u2026 64 s capped). The Wireshark trace from the source post shows exactly this pattern.
To prove the issue, do one of the following three validations:
-
netstat:
netstat -ano -p TCP | findstr LISTENING | findstr :2000\u2014 must show at least one entry with PID. -
Test client from the same PC:
Test-NetConnection -ComputerName 127.0.0.1 -Port 2000in PowerShell \u2014 if it returnsTcpTestSucceeded : False, no local listener exists. -
Test client from the PLC subnet:
Test-NetConnection -ComputerName <PC_IP> -Port 2000from another machine on the same LAN \u2014 if this succeeds but TCON still fails, suspect routing/firewall asymmetries.
Fix: start the actual application that is supposed to act as the server. The Siemens TCP example typically expects a small PC tool (e.g. the "TCP\u00a0conn. example" from the TIA Portal example set) to be running and bound to port 2000. Without it, the handshake cannot complete.
7. Firewall and Antivirus Deep Audit
Disabling Windows Firewall via the control panel does not always remove every filtering rule. The following are the standard steps that resolve the "TCP\u00a02000 is open in my head but the packet is still RST" puzzle:
-
Check active profile state:
Get-NetFirewallProfile | Select Name, Enabledin PowerShell. All three profiles (Domain, Private, Public) must showEnabled : Falsefor the test. - Third-party firewall: Kaspersky, ESET, Bitdefender, Norton, McAfee, Sophos, Avast, AVG and Trend Micro all install a Windows Filtering Platform (WFP) provider that survives the "Disable" toggle. Uninstall (not just disable) for the duration of the test.
-
WFP active providers:
netsh wfp show providers\u2014 if any provider other thanMicrosoft Windows Filtering Platformis listed and active, it is inspecting your traffic. -
Hyper-V / WSL / VPN virtual NICs: the PC may have a virtual adapter (e.g.
vEthernet (WSL),Hyper-V Virtual Switch) that captures the SYN before it reaches the user-mode listener. Disable unused virtual adapters during the test. -
Add an explicit inbound allow rule (preferred over blanket disable) for port 2000 with
New-NetFirewallRule -DisplayName "S7-1200 TCP" -Direction Inbound -Protocol TCP -LocalPort 2000 -Action Allow -Profile Any.
8. CPU and Firmware Compatibility Check
The reported order number 6ES7 214-1HG31-0XB0 is the SIMATIC S7-1200 CPU 1214C DC/DC/DC, 14 DI / 10 DO / 2 AI onboard, with PROFINET interface. FW V3.0 is the original firmware for the "-1HG31-" MLFB. TIA Portal V13 SP1 is the minimum version that supports this CPU; for the TCON block with the parameters shown, TIA Portal V14 SP1 or V15.x is recommended for stability.
Known compatibility points to verify before chasing network issues:
- The PROFINET interface of the 1214C FW V3.0 supports up to 8 S7 connections for Open User Communication (OUC) plus the PG/OP and HMI reserved connections. The
8183status appears only when the limit is hit;7002is independent of this counter. - Online accessible devices must match the project. After loading the project, the watch table IP and the partner IP in the connection DB must match the physical addressing of the devices.
- Do not run a project compiled for a 1200 V4 CPU (different MLFB) on a V3 CPU. The instruction set differs slightly, and the download will fail outright \u2014 but a partially-compiled project can leave residual configuration that produces
7002rather than a hard error.
Full technical specifications, including the maximum number of OUC connections, the integrated PROFINET interface pinout, and the supported Web/OPC UA services for this MLFB, are documented in the SIMATIC S7-1200 Programmable Controller \u2014 CPU 1214C technical specifications.
9. Step-by-Step Resolution Workflow
-
Confirm physical connectivity. From the PC,
ping <CPU_IP>. From the PLC web server or online diagnostics, confirm the partner IP is reachable. -
Confirm the PC listener exists.
netstat -ano -p TCP | findstr :2000. If empty, the partner application is not running \u2014 start it, or run the PowerShell test listener from section 3. -
Capture a fresh Wireshark trace on the same NIC the PLC pings. Apply a display filter
tcp.port == 2000. Expect to see the SYN / RST-ACK pattern until root cause is fixed. - Audit firewalls and AV per section 7. The cleanest test: install the PC listener on a workstation with no AV and Windows Firewall fully disabled on all profiles.
-
Re-verify the TCON connection DB per section 5 \u2014 especially
InterfaceId = 16#40,ConnectionType = 16#0B,ActiveEstablished = TRUE, and a uniqueID. - Re-download to the CPU: from TIA Portal, use "Download to device \u2192 Hardware and software (complete)" to avoid partial downloads. Cycle power if the CPU behaves erratically.
-
Trigger TCON with
REQ=TRUEin the watch table. Expected new status sequence:7001\u21927002(briefly) \u21920000withDONE=TRUEandERROR=FALSEwithin 1\u20132 seconds. -
Validate the Wireshark capture: the trace must now show
SYN \u2192 SYN, ACK \u2192 ACK(3-way handshake) followed by application data.
10. Verification and Long-Term Stability
A successful TCON is not the end of the diagnostic. The following checks keep the link stable:
-
TSEND / TRCV round-trip: send 100 bytes from PLC, echo them back from the PC application, and verify length and content in the watch table. The
DATApointer andLENmust be consistent; a length mismatch yields80B1/80B2on TRCV. -
Watch table periodic poll: monitor
TCON.DONE,TCON.ERROR,TCON.STATUS, and the connection'sESTABLISHEDstatus. A drift to80C0/80C3indicates the PC application is closing the socket \u2014 the partner must keep the listener open continuously. - Network resilience: an unmanaged switch is acceptable for the first validation, but in production use a managed switch with port security and ARP inspection. The PROFINET interface of the 1214C supports ring redundancy only via the CPU 1215\u201315/1515 family \u2014 a single 1214C node has no native redundancy.
-
Diagnostic buffer: after the fix, view the CPU diagnostic buffer under "Online & Diagnostics \u2192 Diagnostic buffer". It must show no TCON-related warnings. Any residual
Connection interruptedentries indicate intermittent loss \u2014 typically from Wi-Fi hops or VPN tunnels between the PC and the PLC.
11. Frequently Asked Questions
What does TCON STATUS 7002 mean on an S7-1200?
STATUS 7002 (W#16#7002) is the intermediate "connection setup in progress" code emitted while the S7-1200 is waiting for the TCP three-way handshake to complete. A value of 7002 is normal for 1\u20132 seconds; if it persists indefinitely, the partner is not sending the expected SYN, ACK \u2014 in a Windows environment that almost always means no application is listening on the target port.
Why does the PC send RST, ACK instead of SYN, ACK?
Windows replies with RST, ACK when a SYN arrives at a port with no socket in the LISTEN state. The RST, ACK is generated by the kernel, not by the user application, and tells the sender to stop retransmitting. Confirm with netstat -ano -p TCP | findstr :2000 that an entry in LISTENING is present for that port.
Can a disabled Windows Firewall still drop the packet?
Yes. Disabling Windows Firewall from the GUI does not remove third-party firewall drivers that hook into the Windows Filtering Platform (WFP). On managed laptops, group policy can also re-enable Windows Firewall. For a clean test, use Get-NetFirewallProfile to verify all three profiles are off, and temporarily uninstall any third-party security suite.
Which TCON parameters are required for a 1214C talking to a Windows PC?
Use InterfaceId = 16#40, ConnectionType = 16#0B (TCP), ActiveEstablished = TRUE (PLC opens the connection), RemoteAddress = PC IPv4, and RemotePort matching the port the PC application is listening on. Each open connection needs a unique ID in the range 1\u20134095.
Does the CPU 1214C FW 3.0 support the modern TCON_v2 blocks?
CPU 1214C FW V3.0 supports the legacy TCON / TSEND / TRCV / TDISCON block family. TCON_v2 is supported on S7-1200 from FW V4.2 onward, paired with TIA Portal V15.1 or higher. If you are on FW 3.0, stick with the legacy block and the manual connection DB structure described in section 5.