Problem Description
After installing or upgrading SIMATIC WinCC (Classic V7.x or TIA Portal WinCC Professional V16/V17/V18) on a Windows 10 engineering station, the following fault chain is observed:
- The SCADA Runtime is launched (WinCC Explorer → Activate or WinCC Runtime start).
- The Windows Set PG/PC Interface applet shows
Noneas the access point assignment for the previously configured protocol (e.g.,S7ONLINE,CP_L2_1:,CP_TCPIP:). - WinCC Runtime hangs during initialization with "SCADA Runtime not loaded" or stalls indefinitely with the splash dialog.
- External tags bound to S7 / S7-1200 / S7-1500 PLCs remain in
Bad Qualityand the connection diagnostics report0x00000001(channel initialization failure).
The fault is reproducible immediately after the engineering station is restarted. The PLC program is in RUN, online communication with the HMI works through TIA Portal (Project Tree → Online → Go online), but the WinCC Runtime project cannot reach the controller.
Affected Software Matrix
| WinCC Version | Minimum Required Update | Supported Windows 10 Builds | Notes |
|---|---|---|---|
| WinCC V7.4 | Update 6 (V7.4 SP1 + Upd6) | 1607 LTSB / 1703 / 1709 | Earlier updates fail on 1809+. |
| WinCC V7.4 SP1 | Update 13 or later | 1809 LTSC / 1909 | Required for LTSC installations. |
| WinCC V7.5 | Update 1 or later | 1809 / 1903 / 1909 / 2004 / 20H2 | Highest tested with V7.5 Upd5. |
| WinCC V7.5 SP1 | Update 2 or later | 1809 / 1909 / 2004 / 20H2 / 21H1 | Recommended baseline for new builds. |
| WinCC V8.0 | Update 1 or later | 1909 / 2004 / 20H2 / 21H1 / 21H2 | First WinCC release with full 21H2 support. |
| WinCC Professional V16 (TIA) | Update 3 or later | 1809 / 1909 / 2004 | Requires SIMATIC NET V16. |
| WinCC Professional V17 (TIA) | Update 1 or later | 1909 / 2004 / 20H2 / 21H1 / 21H2 | Requires SIMATIC NET V17. |
| WinCC Professional V18 (TIA) | None | 20H2 / 21H1 / 21H2 / 22H2 | Validated against Windows 10 22H2. |
Verify your installed WinCC version against the official Siemens compatibility matrix at the Siemens Industry Online Support portal (search term: "WinCC Windows 10 compatibility").
Root Cause Analysis
WinCC Runtime uses SIMATIC communication channels (S7 Protocol Suite, MPI, PROFIBUS DP, Industrial Ethernet ISO-on-TCP / TCP / UDP) that depend on a Windows-layer service called SIMATIC NET PC Station. The transport between WinCC and the underlying protocol stack is bound through the S7ONLINE access point, which is configured in the Windows Control Panel applet "Set PG/PC Interface".
When this access point is unassigned or the underlying SIMATIC NET driver is deregistered, WinCC Runtime cannot open any S7 channel and halts in the startup phase. The five most common root causes on Windows 10 are listed below in descending frequency.
RC1 — S7ONLINE Access Point Reset by Windows Update
Windows 10 1809+ resets custom S7ONLINE bindings to None after major feature updates, in-place upgrades, or cumulative updates that touch the network stack. Symptoms: Set PG/PC Interface shows (None) for S7ONLINE; previously saved .cfg files are ignored.
RC2 — SIMATIC NET PC Station Not Running
The Windows service S7Dos_Service (display name: S7 DOS Service) and CP_PC_Station must be in state Running. Windows 10 Defender or group policies can prevent the service from auto-starting, especially after a non-administrator user logs on. The WinCC channel diagnostic shows S7DOS-Error: 0xFFFE / 0x8000.
RC3 — Multiple SIMATIC NET Versions Side-by-Side
STEP 7 V5.6, TIA Portal V16, TIA Portal V17, and WinCC Flexible share a single PC Station configuration. Mixing them on one engineering PC corrupts the PCStation.xml and the SIMATIC NET Configuration Console shows "Station manager not active".
RC4 — Incompatible Windows 10 Build for the Installed WinCC Patch
An Update 5 of WinCC V7.5 has been validated against 2004, but not against 22H2. Starting WinCC Runtime on an unsupported build silently disables drivers because the s7otbxdx.dll cannot register against the new Winsock LSP catalog.
RC5 — User Account Control (UAC) Blocking Driver Registration
The first launch of Set PG/PC Interface requires elevation. If the user dismisses the UAC prompt or has EnableLUA = 1 with a deny ACE, the access point is created in the per-user hive but not in HKLM\SOFTWARE\Siemens\S7Dos.
Diagnostic Procedure
-
Capture the WinCC startup log. Open
<WinCC_Install>\diagnose\WinCC_Sys_Log.txtandWinCC_StartLog.txt. Look for lines containingS7DOS,S7OTB,S7CHN, orchannel init failed. -
Verify Windows services. Run
services.msc→ confirm SIMATIC NET PC Station, SIMATIC S7 DOS Service, and CP_HARDWARE services are Running and startup type is Automatic. -
Open Set PG/PC Interface. Start → Siemens Automation → STEP 7 → Set PG/PC Interface (or
Start → Control Panel → Set PG/PC Interface). Select Access Point of the Application: S7ONLINE (STEP 7) – TCP/IP. If the dropdown showsNone, the S7ONLINE access point is broken. -
Inspect Configuration Console. Launch
SIMATIC NET Configuration Console→ Modules tab. TheIE Generalmodule must be assigned to the correct Windows network adapter with the same MAC/IP as the WinCC project. -
Review Event Viewer.
eventvwr.msc→ Windows Logs → System. Filter for SourceS7DOSandService Control Manager. ErrorsEvent ID 7023,7034, and7000onS7Dos_Serviceindicate crash loops. -
Test ISO-on-TCP reachability. From an elevated command prompt run
cmd /c "ping -n 2 <PLC_IP>". If ping succeeds, layer 3 is fine. Then runTestS7.exefrom the SIMATIC NET install directory; a successful PDU exchange printsConnect to PLC...OK.
Solution A — Repair the S7ONLINE Access Point
- Close WinCC Runtime and WinCC Explorer.
- Right-click Set PG/PC Interface → Run as administrator.
- In Interface Parameter Assignment Used:, select the TCP/IP network adapter that is physically connected to the PLC subnet.
- Click OK. Windows creates the
S7ONLINEsubkey underHKLM\SOFTWARE\Siemens\S7Dospointing to the chosen NDIS adapter. - Re-launch WinCC Runtime. Verify in the S7 channel diagnostic that the connection state moves from
0(No Connection) to4(Connected).
HKCU only, and the WinCC Runtime started as a service cannot read it.Solution B — Reinstall or Repair SIMATIC NET
- Open Control Panel → Programs and Features. Note the exact SIMATIC NET version (e.g., SIMATIC NET PC Software V17 SP1).
- Right-click → Repair. The installer re-registers
s7otbxdx.dll,s7oiehsx.exe, and the OPC UA server binaries. - If Repair fails, uninstall SIMATIC NET and reinstall from the matching TIA Portal DVD or Siemens Support download. The supported install order on Windows 10 is:
- Windows 10 cumulative updates
- .NET Framework 4.8 (KB4486152 or later)
- SIMATIC NET V17
- TIA Portal V17
- WinCC V8.0 (if used)
- After reinstall, run
Start → Siemens → SIMATIC NET → Commissioning → Station Configuration Editor. Verify that Index 1 is the IE General module bound to the correct Windows NIC.
Solution C — Disable Windows 10 Driver Store Reset
- Open gpedit.msc (Pro/Enterprise only). Navigate to Computer Configuration → Administrative Templates → Windows Components → Windows Update → Manage updates offered from Windows Update.
- Set Do not include drivers with Windows Updates to Enabled.
- Restart Windows.
- Verify the S7ONLINE binding survives a reboot.
On Windows 10 Home editions, run wushowhide.diagcab from Microsoft and hide the offending Siemens S7DOS Driver update. Alternatively, set the registry value HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ExcludeWUDriversInQualityUpdate = 1.
Solution D — TIA Portal Specific Steps for WinCC Professional V16/V17/V18
- In TIA Portal, open the WinCC project → Devices & Networks → Network view.
- Right-click the HMI station → Properties → Communication → Connection resources. Confirm the S7 connection has Establishment = Active and Access point = S7ONLINE.
- Compile the project (Hardware and Software, full rebuild).
- Download the WinCC RT to the engineering PC. The download re-creates the PC Station XML and pushes it to the Station Configuration Editor.
- From the WinCC Runtime taskbar icon → Diagnostics → S7 Channel Diagnostics. Verify partner state is Connected with reachable partner =
<PLC IP>:102(ISO-on-TCP port 102 by default).
Solution E — Classic WinCC V7.x Specific Steps
- In WinCC Explorer, right-click Tag Management → SIMATIC S7 PROTOCOL SUITE → TCP/IP → System Parameters → Unit → Logical Device Name. Ensure it equals
CP_TCPIP. - Verify the
CP_TCPIPentry exists in Set PG/PC Interface and points to the same Windows NIC. - If using PROFIBUS, the unit must equal
CP_L2_1:and the CP5611 / CP5621 driver must be installed. Check Device Manager → Multi-function adapters; an unknown device with yellow exclamation indicates the CP driver was overwritten by a Windows update. - Right-click the WinCC project → Properties → Graphics Runtime → Window Attributes. Disable Close on screen keyboard if it conflicts with the focus policy of the runtime window.
Firewall and Network Configuration
Windows 10 Firewall with Advanced Security can silently drop SIMATIC frames even with no apparent driver issue. Required rules:
| Port | Protocol | Use | Direction |
|---|---|---|---|
| 102 | TCP (ISO-on-TCP / RFC 1006) | S7 communication to S7-300/400/1200/1500 | Inbound + Outbound |
| 5001–5005 | TCP | S7DOS internal channel | Loopback |
| 161/162 | UDP | SNMP for diagnostics (optional) | Inbound + Outbound |
| 34964 | TCP | PROFINET DCP discovery | Inbound + Outbound |
| 48898 | TCP | WinCC OPC UA server (if used) | Inbound + Outbound |
Create an inbound rule named SIMATIC NET allowing TCP ports 102, 5001–5005 for the program path %ProgramFiles%\Siemens\Automation\S7DOS\s7otbxdx.exe. Alternatively, use the Siemens-provided PowerShell script Siemens_S7_Firewall_Rules.ps1 from the SIMATIC NET install media.
Verification Procedure
- Open Set PG/PC Interface and confirm
S7ONLINEshows the assigned NIC, notNone. - Run
Start → Siemens → SIMATIC Manager → Accessible Nodes. The PLC IP must appear with online statusOnline (RUN). - Start WinCC Runtime. In the WinCC channel diagnostic, confirm:
Tag: Status_Online Value: 1 Quality: 0xC0 (Good)
Connection: TCP/IP to 192.168.0.10 State: Established - Force a tag value from the WinCC tag simulator and verify the change is reflected on the PLC via TIA Portal watch table.
- Run
WinCC_RT_PerfMon.exe(Runtime → Tools → Performance Monitor). Cycle time should remain under 500 ms for a 500-tag project. Values above 2 s indicate channel rescan loops caused by a flaky access point. - Reboot the engineering PC and repeat steps 1–4 to confirm the binding persists.
Fault Code Reference
| WinCC Channel Error Code | Meaning | Most Likely Cause |
|---|---|---|
| 0x00000001 | Channel initialization failed | S7ONLINE access point = None |
| 0x0002 / 0x8002 | Partner not reachable | Wrong IP, firewall, or subnet |
| 0xFFFE | SIMATIC NET service not started | S7Dos_Service stopped |
| 0x0F01 | PC Station not configured | Station Configuration Editor empty |
| 0x0F04 | Wrong IE module index | Module index 1 not bound to physical NIC |
| 0x9001 | Connection aborted by partner | PLC CPU in STOP or Put/Get disabled |
| 0x8010 | Access point not assigned | Set PG/PC Interface set to None |
| 0xD202 | OPC UA server certificate error | Trust list missing on WinCC RT side |
Preventive Measures
- Deploy WinCC on Windows 10 LTSB or LTSC (1607, 1809) builds for long-term stability. Avoid SAC builds unless explicitly supported.
- Create a Windows image that excludes driver updates via
wushowhideor group policy before commissioning. - Document the S7ONLINE binding in the engineering station handover packet and check it after every Windows update cycle.
- Use a dedicated engineering PC without third-party antivirus or backup software that injects Winsock LSPs.
- Subscribe to Siemens Product Notification RSS for your installed WinCC version to receive update alerts.
Related Platform Notes
Third-Party SCADA (WinCC Open Architecture / Ignition) on Windows 10
For non-Siemens SCADA packages running on the same engineering station, the same S7ONLINE access point collision occurs. Allocate one logical device per SCADA driver (e.g., CP_TCPIP_2:) using the Configuration Console. Ignition by Inductive Automation uses a separate S7 driver (Ignition S7 Ethernet) and does not require S7ONLINE, but coexistence with WinCC requires the SIMATIC NET drivers to remain installed.
Schneider SCADAPack Migration
If the same engineering station also hosts Schneider Electric SCADAPack configuration tools, disconnect any serial RS-485 programming cable from the SCADAPack before launching WinCC Runtime. Serial enumeration on Windows 10 can shift COM port numbers and block SIMATIC NET driver initialization. Cold-boot the SCADAPack 32/57 controller after reconnecting.
FAQ
Why does Set PG/PC Interface show "None" after every Windows 10 reboot?
Windows 10 feature updates reset the S7ONLINE access point to None. Run Set PG/PC Interface as Administrator, select the TCP/IP NIC bound to your PLC subnet, click OK, and disable driver delivery via Windows Update using ExcludeWUDriversInQualityUpdate = 1 to prevent recurrence.
Which Siemens documentation covers the S7ONLINE access point configuration?
Refer to Siemens Entry ID 90832706 for the canonical STEP 7 procedure, and the SIMATIC NET PC Software Installation Manual on the Siemens Industry Online Support portal for driver-level details.
Can I run WinCC V7.5 on Windows 10 22H2 without upgrading to V8.0?
WinCC V7.5 SP1 with Update 2 is validated only up to Windows 10 21H2. For 22H2 you must upgrade to WinCC V8.0 Update 1 or later, and reinstall SIMATIC NET to a matching V18 release.
What is the difference between S7ONLINE and CP_TCPIP access points?
S7ONLINE is the access point used by STEP 7 / TIA Portal online functions and by the WinCC S7 Protocol Suite on Classic V7. CP_TCPIP is a WinCC-specific logical device used internally by the SIMATIC S7 Protocol Suite channel. Both must point to the same Windows network adapter for redundant routing to work.
How do I confirm ISO-on-TCP port 102 is open end-to-end?
From an elevated command prompt run TestS7.exe <PLC_IP> -port 102 from the SIMATIC NET install directory. A successful handshake prints Connect OK and exits 0. If it fails, check Windows Firewall rule SIMATIC NET for TCP 102 inbound and outbound, then verify the PLC CPU has Permit access with PUT/GET communication from remote partner enabled in Properties → Security.