Troubleshooting WinCC V8 OMS+ Connection Drops to S7-1200 PLCs

David Krause11 min read
SiemensTroubleshootingWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Description: Intermittent OMS+ Connection Loss in WinCC V8

WinCC V8 Update 5 runtime stations configured with mixed S7 channel loads — 10 native TCP/IP connections to S7-300/S7-400 controllers and 8 OMS+ (S7-Optimized Communication) connections to a heterogeneous fleet of S7-1200 CPUs — periodically report channel down events followed by automatic re-establishment. The legacy S7-1200 stations were commissioned in TIA Portal V11 and V12, while newer units were re-engineered in TIA V17 with active certificates for protected communication. Affected channels show status transitions between Connected, Disconnected, and Establishing in WinCC Channel Diagnosis, typically every 30 to 300 seconds.

The host is a Windows Server 2022 machine with a certified industrial NIC, SIMATIC NET V19, and a Softnet IE S7 license that nominally permits 64 S7 connections. Despite the apparent over-provisioning, the drops persist, indicating that the bottleneck is not at the host licensing tier but at the S7-1200 side or the OMS+ channel configuration itself.

Field symptom signature: S7-300/S7-400 TCP/IP channels stay green while OMS+ channels to S7-1200 blink. This asymmetry is the diagnostic anchor for the entire troubleshooting flow described below.

Root Cause Analysis Overview

Four interacting factors typically cause the observed pattern. Each must be eliminated in turn before declaring the fault resolved.

# Root Cause Layer Diagnostic Artifact Resolution Path
1 S7-1200 connection-resource exhaustion CPU diagnostic buffer entry "No resources for new connection" Reduce parallel OP/PG/HMI connections, upgrade to CPU with more resources
2 SIMATIC NET license tier (Lean vs. Softnet IE) SIMATIC NET License Tool, channel error "Maximum number of S7 connections reached" Upgrade Lean → Softnet IE S7 with sufficient connection count
3 Windows Server OS compatibility SIMATIC NET installation log, S7DOS service status Use supported Server SKU, configure S7DOS as automatic delayed start
4 OMS+ certificate / TIA version mismatch TIA V17 protection settings, WinCC connection log TLS handshake failures Align certificate strategy, disable "Permit access with PUT/GET" conflict

Root Cause 1 — S7-1200 Communication Resource Exhaustion

S7-1200 CPUs (firmware V1.x through V4.x) allocate a fixed pool of S7 communication resources per CPU model. These resources are shared between PG, OP/HMI, S7 PUT/GET, and user-programmed TSEND/TRCV connections. The legacy S7-1200 firmware from TIA V11/V12 was not engineered for the simultaneous connection load that a WinCC V8 station with 8 OMS+ channels plus other HMI clients places on it.

S7-1200 Maximum Connection Counts by CPU Class

CPU Model (typical) Max PG Connections Max OP/HMI Connections Max S7 Connections (PUT/GET) Total Resource Pool
CPU 1211C / 1212C 1 3 8 ~6 dynamic resources
CPU 1214C / 1215C 1 3 8 ~14 dynamic resources
CPU 1217C 1 3 16 ~22 dynamic resources
CPU 1212C DC/DC/DC (FW 4.x) 1 3 8 ~14 dynamic resources
CPU 1215C DC/DC/DC (FW 4.4+) 1 3 16 ~22 dynamic resources
S7-1200 G2 (FW 4.6+, 2024+) 1 3 16+ Expanded pool

Verify exact resource values in TIA Portal under Device properties → Communication resources for the specific CPU and firmware version in use. The values above reflect Siemens documentation; check the precise CPU article for production deployments.

Why OMS+ amplifies the load: OMS+ channels in WinCC V8 use S7-Optimized communication, which opens separate connection slots per acquisition cycle and per redundant partner. Eight OMS+ channels on a single legacy S7-1200 can saturate the dynamic resource pool within minutes of WinCC startup, causing the CPU to reject new connection establishment requests, which WinCC then retries — creating the on/off cycle observed in Channel Diagnosis.

Reference: Siemens Support entry 109479986 — S7-1200/S7-1500 communication resources and number of possible connections.

Diagnostic Procedure

  1. Connect TIA Portal to the affected S7-1200 online.
  2. Open Online & Diagnostics → Diagnostics buffer and filter for entries containing connection or resource.
  3. Look for diagnostic event ID 0x01C8 / W#16#0190 range messages indicating connection rejection due to resource limits.
  4. Check Online → Accessible nodes to confirm how many partners the CPU currently reports.
  5. In WinCC Explorer, open Tools → Channel Diagnosis, select the OMS+ channel, and capture the error code (e.g., 0xFFDF3840 for "connection establishment failed").

Resolution

  • Disconnect any redundant Comfort Panels or secondary HMI clients from the affected S7-1200 CPUs.
  • If the application requires the full OMS+ count on a single CPU, migrate the legacy TIA V11/V12 projects to TIA V17 with a CPU 1215C or 1217C (FW 4.4+) that supports the expanded resource pool.
  • Consolidate WinCC tags so that the OMS+ connection count is reduced. One WinCC V8 channel can multiplex multiple tag groups; verify tag tree in the WinCC Tag Management editor.

Root Cause 2 — SIMATIC NET License Tier

SIMATIC NET ships with a graduated licensing model. Each tier imposes a hard ceiling on the number of S7 connections that can be simultaneously active on the host.

License Tier S7 Connection Limit Typical Use Case
SIMATIC NET Lean (included with WinCC) 8 Small WinCC stations, single PLC
Softnet IE S7 (up to 64) 64 Mid-size HMI/SCADA servers
Softnet IE S7 (up to 128) 128 Large SCADA hosts
Softnet IE S7 (up to 512) 512 Plant-wide servers
Hardnet IE S7 (per CP) Per CP license (commonly 64–256) Hard real-time, deterministic networking

With 10 S7-300/400 TCP/IP channels plus 8 OMS+ channels the host needs at least 18 concurrent S7 connections. The Lean tier (8) is insufficient. If the customer believes Softnet IE 64 is installed but the drops still occur, validate the actual installed license through the SIMATIC NET License Tool rather than the apparent installation.

Verifying the Active License

  1. Open Start → Siemens Automation → SIMATIC NET → License Manager (or SN_LicMgr.exe).
  2. Confirm the active license key — not the presence of the license file on disk.
  3. Check the S7DOS service: sc query S7DOS must show RUNNING and the description must reference Softnet IE rather than Lean.
  4. In Windows Event Viewer → Applications and Services → Siemens Automation, look for the event S7 connection count exceeded.
License activation caveat: Softnet IE licenses must be transferred via the Automation License Manager (ALM) and bound to the host's MAC address or a USB dongle. A license installed on a different machine, or activated against a virtual NIC, will not satisfy the host check. Confirm with ALM > Manage > Active.

Reference: Siemens Support — Which licenses can be used for SIMATIC NET PC software.

Root Cause 3 — Windows Server OS and SIMATIC NET Architecture

SIMATIC NET V19 is the first release with full certification on Windows Server 2022. Earlier SIMATIC NET versions reject Server SKUs during install or run in a degraded mode where the S7DOS service cannot bind to the network stack correctly, producing drop-and-recover behavior. Confirm the following:

Check Command / Location Expected State
SIMATIC NET release reg query "HKLM\SOFTWARE\Siemens\AUTSW\S7WNM\SETUP" /v Version 19.0 or higher
S7DOS service sc qc S7DOS START_TYPE: AUTO_DELAYED, STATE: RUNNING
SIMATIC NET Configuration Console Start → Siemens → Configuration Console Network adapter bound to S7DOS mode
Windows firewall rule for S7DOS wf.msc inbound rules for %SIMATIC_NET%\s7dos\sld.exe Enabled for port 102 (TCP) on industrial NIC profile only
Power management Device Manager → NIC → Power Management Allow the computer to turn off this device = UNCHECKED
Common Server-side mistake: Binding S7DOS to a virtual NIC (Hyper-V switch, VPN tunnel, or team interface) instead of the physical industrial adapter. S7DOS does not tolerate MAC changes or VMQ offload; drops occur when Windows rebalances RSS queues.

Root Cause 4 — OMS+ Certificate and TIA V17 Protection

OMS+ is a Siemens-defined S7-Optimized channel that uses TLS 1.2/1.3 and X.509 certificates when the S7-1200 firmware is V4.4+ and the TIA project enables Connection mechanisms → Permit access with PUT/GET communication is disabled. Mixed fleets that include older CPUs without certificates force WinCC V8 to negotiate security parameters that the legacy firmware cannot match. The result is a TLS handshake failure that the WinCC OMS+ channel logs as a normal disconnect, retries, succeeds, fails again — the exact cyclic pattern observed.

Alignment Procedure

  1. Open the TIA V17 project for the modern S7-1200 stations.
  2. Navigate to Device properties → Protection & Security → Connection mechanisms.
  3. Select Permit access with PUT/GET communication from a remote partner if WinCC V8 must interoperate without certificate exchange.
  4. If certificates are required, export the WinCC station certificate from WinCC Explorer → Computer → Properties → OMS+ and import it into the S7-1200 project under Global security settings → Certificate manager.
  5. Repetitively download the project to the S7-1200 to ensure the certificate store is updated.

Reference: Siemens Support — Using S7-1200/S7-1500 certificates in WinCC V8 (OMS+).

Step-by-Step Diagnostic Workflow

  1. Capture baseline: In WinCC Channel Diagnosis, record the drop intervals and the specific S7-1200 partners that are blinking. Export the WinCC diagnostic file WinCC_S7_ChannelDiag.log from <WinCC Project>\Diagnosis.
  2. Validate S7-1200 resources: Online each affected S7-1200 and read the diagnostic buffer. Apply Root Cause 1 fix if resource exhaustion is logged.
  3. Validate SIMATIC NET license: Confirm Softnet IE 64 is the active license, not Lean. If a license upgrade is required, obtain the correct license from the Siemens license portal and activate via ALM.
  4. Validate Server OS configuration: Confirm S7DOS service is bound to the physical NIC, firewall is open on TCP/102, and power management is disabled on the adapter.
  5. Validate OMS+ certificates: Open the TIA V17 project, export/import certificates, and either enable PUT/GET or deploy the certificates correctly.
  6. Restart sequence: Stop WinCC Runtime, restart S7DOS service, start WinCC Runtime. Verify all 18 channels show Connected with no drop events over a 10-minute window.

Verification Procedure

Once the suspected root cause has been remediated, validate stability through the following steps:

Verification Method Pass Criterion
Channel uptime WinCC Channel Diagnosis continuous view, 24 h Zero disconnect events for 24 h
S7-1200 diagnostic buffer TIA Portal online → Diagnostics buffer No new "no resources" entries
S7DOS log %SIMATIC_NET%\s7dos\log No E=0x0230 error lines
WinCC tag error count Tag Management → Statistics Error count delta = 0 over 1 h
Connection counts Configuration Console → S7DOS → Connections ≤ Softnet IE licensed limit, no spillover

Preventive Measures and Best Practices

  • Inventory the S7-1200 fleet by firmware and CPU model. Map each WinCC OMS+ connection to a CPU with sufficient resources.
  • Standardize TIA Portal version. Mixing TIA V11/V12 with V17 is the primary driver of certificate/handshake drift. Plan a TIA V17+ migration for the legacy stations.
  • Reserve a single Softnet IE license tier for the host that exceeds the worst-case connection load by at least 20%.
  • Document the certificate strategy: PUT/GET enabled, or full X.509 chain. Mix-and-match is the most common cause of intermittent OMS+ drops.
  • Configure a single physical NIC for S7DOS. Disable VMQ, RSS, and any virtual switch on that adapter.
  • Add WinCC redundancy only after channel stability is achieved; redundant WinCC pairs double the connection load on the S7-1200 and will trigger Root Cause 1 if the CPU pool is already near saturation.

Extended Troubleshooting Matrix

Observed Symptom Most Likely Cause Action
All OMS+ channels drop simultaneously S7DOS service or host license failure Restart S7DOS, verify Softnet IE license
Only legacy (TIA V11/V12) S7-1200 channels drop CPU resource exhaustion or firmware TLS gap Reduce parallel connections, upgrade firmware or migrate to TIA V17 CPU
Only modern (TIA V17) S7-1200 channels drop Certificate mismatch or "Permit PUT/GET" disabled Enable PUT/GET or import WinCC certificate into TIA project
Channels drop at fixed interval (e.g., 30 s) Keep-alive or OPC retry timer collision Increase WinCC connection establishment timeout to 60 s
Channels drop at variable interval during high tag traffic TCP buffer overrun, NIC offload Disable TCP chimney offload, lower WinCC acquisition cycle
Drops correlate with Windows update or antivirus scan Firewall or service interference Create firewall inbound allow rule for S7DOS, exclude WinCC directory from AV
Drops stop after WinCC restart, return within 1 h Resource leak, likely S7-1200 side Reboot the affected S7-1200, re-download TIA project

Configuration Snippets

OMS+ Channel Timeout Parameter (WinCC V8)

In the WinCC Tag Management, the OMS+ channel exposes the connection establishment timeout in the channel unit properties. For mixed-fleet deployments increase the timeout from the default 5 s to 30 s:

Connection establishment timeout: 30000 ms
Connection break tolerance: 3 retries
Keep-alive interval: 15000 ms
Tag polling cycle (acquisition): 1000 ms

Windows Firewall Rule for S7DOS (PowerShell)

New-NetFirewallRule -DisplayName "SIMATIC NET S7DOS TCP 102" `
  -Direction Inbound -Action Allow -Protocol TCP `
  -LocalPort 102 -Profile Any `
  -Program "%ProgramFiles%\Siemens\Automation\SimaticNet\s7dos\sld.exe" `
  -InterfaceAlias "Intel I210 Ethernet" -Enabled True

Disabling NIC Power Management (PowerShell)

Disable-NetAdapterPowerManagement -Name "Ethernet*" -IncludeHidden
Set-NetAdapterAdvancedProperty -Name "Ethernet*" `
  -DisplayName "Energy Efficient Ethernet" -DisplayValue "Disabled"
Set-NetAdapterAdvancedProperty -Name "Ethernet*" `
  -DisplayName "TCP/UDP Checksum Offload (IPv4)" -DisplayValue "Disabled"

FAQ

Why are OMS+ connections to S7-1200 dropping in WinCC V8 Update 5?

The most frequent cause is exhaustion of the S7-1200 dynamic connection resource pool when 8 OMS+ channels are opened in parallel to legacy firmware (TIA V11/V12) CPUs. Confirm the S7-1200 diagnostic buffer for resource-rejection events and either reduce parallel connections, migrate to a higher-resource CPU (1215C/1217C FW 4.4+), or upgrade the firmware.

What is the SIMATIC NET S7 connection limit per license tier?

SIMATIC NET Lean caps at 8 S7 connections. Softnet IE S7 ships in 64, 128, and 512 connection variants. For 18 concurrent channels (10 TCP/IP + 8 OMS+) the minimum is Softnet IE S7-64. Verify the active license in the SIMATIC NET License Manager rather than relying on the install footprint.

How many HMI/OP connections can a legacy S7-1200 CPU support?

CPU 1211C/1212C support 3 OP/HMI connections plus 1 PG and 8 S7 PUT/GET connections, sharing a small dynamic resource pool. CPU 1214C/1215C extend the pool to approximately 14 dynamic connections. CPU 1217C and S7-1200 G2 (FW 4.6+) double that figure. Always check the specific CPU article in the TIA Portal device properties for the exact number.

Is Windows Server 2022 supported with SIMATIC NET V19?

Yes. SIMATIC NET V19 is the first release with full Windows Server 2022 certification. Earlier SIMATIC NET versions install on Server 2022 only in a degraded mode where the S7DOS service cannot bind correctly, producing drop-and-recover behavior. Confirm the installed version is 19.0+ via the registry key HKLM\SOFTWARE\Siemens\AUTSW\S7WNM\SETUP\Version.

How do I enable WinCC Channel Diagnosis for OMS+?

In WinCC Explorer open Tools → Channel Diagnosis, select the OMS+ channel unit, and enable continuous logging. The log file is written to <WinCC Project>\Diagnosis\<timestamp>_OMS.log. Use the S7DOS log under %SIMATIC_NET%\s7dos\log for lower-layer events. Look for hex error code 0xFFDF3840 (connection establishment failed) and 0x0230 (resource exhaustion).

Back to blog