Upload S7-1200 Program to TIA Portal: Online Monitoring Setup

David Krause16 min read
SiemensTIA PortalTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Upload S7-1200 Program to TIA Portal: Online Monitoring Setup

This technical reference describes the end-to-end procedure for retrieving a program from a SIMATIC S7-1200 CPU to a TIA Portal engineering station when the original project is not available, and for establishing a stable online connection for live monitoring. The procedure covers project recovery via Upload device as new station, online block visibility, OB/FB/FC/DB inspection, watch table use, and the IP/PG interface prerequisites that commonly block first-time engineers. The workflow is aligned with STEP 7 in TIA Portal V17, V18, V19, and V20.

Field note: The most common failure mode for new TIA Portal users is attempting to download a project to the PLC rather than uploading from the PLC. If the engineering station has no project and the target PLC is the only project source, the workflow is Upload device as new station, not Download to device.

1. Problem Definition and Scope

When an S7-1200 has been programmed on a different engineering station and the original TIA Portal project file (.ap17/.ap18/.ap19/.ap20) is not available, the program must be recovered directly from the PLC's load memory. The S7-1200 stores:

  • System blocks (SDB) — hardware configuration, system data
  • Organization Blocks (OBs) — OB1, OB100, OB82, OB121, etc.
  • Function Blocks (FBs) and Functions (FCs) — user logic
  • Data Blocks (DBs) — both instance and global data
  • Technology objects (TOs) — PID, motion, high-speed counters (Firmware V4.0+)

Uploading retrieves all of these into a new offline project that matches the PLC's runtime configuration. After upload, the engineering station can establish an online connection for live value monitoring, forcing, and diagnostics.

2. Prerequisites

Before executing the upload procedure, verify the following items:

Prerequisites for S7-1200 Upload Workflow
Item Requirement Verification
STEP 7 in TIA Portal V17, V18, V19, or V20 (matching or higher than PLC project) Help → About TIA Portal → Show Details
S7-1200 CPU Firmware V4.0 or higher recommended; V4.2/V4.3/V4.4/V4.5/V4.6 supported Online → Accessible Nodes → CPU Properties
Ethernet cable RJ45, Cat 5e or higher, direct or via switch Link LED on CPU port solid green
PLC IP address Known (default 192.168.0.1, mask 255.255.255.0) or discoverable Online → Accessible Nodes scan
PG/PC interface Intel I211/I219 or compatible NIC selected in TIA Portal Options → Set PG/PC Interface
User permission Read/write access to PLC (default: no password unless set) Online → Accessible Nodes → right-click → Online & Diagnostics
Firewall Port 102 (ISO-TSAP) inbound/outbound allowed Windows Defender Firewall with Advanced Security
Compatibility note: TIA Portal enforces a one-way upward compatibility rule. A V20 engineering station can upload from a V17 project PLC, but a V17 station cannot upload from a V20 project PLC. Always confirm the engineering TIA Portal version is equal to or higher than the version that originally programmed the device.

3. Configuring the PG/PC Interface

Open TIA Portal and access the interface selection. This is the most common source of "PLC not found" or "connection refused" errors during the first scan of accessible nodes.

  1. Launch TIA Portal (no project open is acceptable at this stage).
  2. Navigate to Options → Set PG/PC Interface.
  3. Select the access point S7ONLINE (STEP 7).
  4. From the interface list, choose the physical NIC bound to the subnet of the S7-1200. For a direct connection, this is typically the Intel(R) Ethernet Connection or Realtek PCIe GbE Family Controller.
  5. If the IP of the NIC does not match the PLC's subnet, click Properties and assign a static IPv4 address (e.g., 192.168.0.10 / 255.255.255.0).
  6. Click OK and close the dialog. The setting persists per user profile.

3.1 Static IP Assignment for the Engineering NIC

If the S7-1200 is set to its default IP (192.168.0.1) and the laptop's NIC is on a different subnet (e.g., DHCP-assigned 192.168.1.x), the Accessible Nodes scan will return an empty list even though the link LED is green. Configure the NIC manually:

Static IPv4 for Engineering NIC
Parameter Value
IP address 192.168.0.10
Subnet mask 255.255.255.0
Default gateway (empty for direct link)
Preferred DNS (empty)

4. Performing the Upload from the PLC

There are two distinct entry points for the upload action. Choose the method that matches the project state on the engineering station.

4.1 Method A — Upload from Accessible Nodes (no project open)

This is the correct method when the engineering station has no existing project that references the target CPU.

  1. Open TIA Portal. Do not open a project; remain at the Portal view or Project view with no project loaded.
  2. From the menu bar select Online → Accessible Nodes.
  3. In the Accessible Nodes pane (typically docked on the right), TIA Portal will perform a broadcast ARP/PROFINET DCP scan and list every S7-1200 on the local subnet.
  4. Confirm the target CPU is shown with its IP address, MAC address, device name, and firmware version.
  5. Right-click the target CPU and select Upload device as new station (hardware and software).
  6. TIA Portal opens a wizard. Confirm the target device and click Upload.
  7. TIA Portal creates a new project named Upload_[DeviceName]_[Date] in the default project repository.
  8. After completion, TIA Portal prompts: Do you want to go online with the uploaded device? Click Yes to immediately enter the online view, or No to inspect offline first.
Critical: If the menu item is greyed out, the project is locked or another TIA Portal instance holds a session. Close all other TIA Portal windows, including offline project tabs, and retry. Re-selecting the CPU in Accessible Nodes with a single click typically re-enables the menu.

4.2 Method B — Upload from Project View (existing project open)

Use this method if a TIA Portal project is already open but does not match the CPU's actual configuration.

  1. In Project View, select the PLC device in the project tree.
  2. From the menu select Online → Upload from device (software).
  3. In the dialog, select the accessible node matching the CPU's IP address.
  4. Check Replace the project data with the online data to overwrite the local project with the CPU's runtime data.
  5. Click Upload and confirm the overwrite prompt.

4.3 Verification of Uploaded Content

After upload, expand the project tree and confirm the following appear:

  • Device configuration — shows the CPU order number (e.g., 6ES7 214-1AG40-0XB0) and signal modules
  • Program blocks — OBs, FBs, FCs, and DBs visible
  • PLC tags — name table recovered from CPU
  • Watch and force tables — empty by default; create new ones for monitoring
  • Technology objects — for S7-1200 V4.0+ with PID or motion configured

5. Going Online and Enabling Live Monitoring

The online connection is the second half of the workflow. A successful upload is required before online monitoring becomes useful, since the project must match the CPU to bind symbolic names to memory addresses.

5.1 Establishing the Online Connection

  1. Select the PLC device in the project tree.
  2. Click the Go online icon (the symbol resembling two monitors) in the toolbar, or press Ctrl+K.
  3. If prompted, choose the PG/PC interface and the subnet.
  4. The status bar at the bottom right transitions to Online and displays the connection state in green. A red status indicates failure — see Section 9 for the diagnostic matrix.
  5. When the CPU is in RUN, online monitoring of code blocks is disabled by default. Switch the view via Online → Online & Diagnostics → Operating mode or click the Monitor on/off icon (glasses symbol) in the editor toolbar.

5.2 Block Visibility — Why the Online View May Appear Empty

A common confusion after upload is that the project tree shows blocks but the editor panes are blank. The cause is that the project is in the offline view. To force the editor to render the online values:

  1. Click on any program block (e.g., OB1) in the project tree.
  2. Open the block. If the block contains code, but the LAD/FBD/ST view appears grey/empty, ensure you are looking at the online version, not the offline one.
  3. Click the Monitor on button (the glasses icon). TIA Portal recompiles the block against online data and displays current operand values inline next to the logic elements.
Online vs Offline Block Behavior
Condition Offline View Online View (Monitor on)
Block exists only in project Visible, editable Not visible
Block exists only in CPU Not visible Visible, read-only
Block in both and identical Visible Visible, current values shown
Block in both but differing Visible (compile required) Visible with online values

6. Live Monitoring with Watch Tables and Force Tables

Watch tables are the primary live-monitoring tool for engineers who need to inspect and (with caution) modify process values while the PLC is in RUN.

6.1 Creating a Watch Table

  1. In the project tree, right-click Watch and force tables.
  2. Select Add new watch table. Name it (e.g., WT_IO_Status).
  3. Click on the Name column and type the symbolic name (e.g., Motor_Start) or absolute address (e.g., I0.0). TIA Portal auto-completes from the PLC tag table.
  4. Click the Monitor all button (the binoculars) or press Ctrl+F5 to start live polling. The default poll interval is 1000 ms; right-click the table header to adjust to 200/500/1000/2000 ms.

6.2 Force Tables — Engineering Use and Safety

Force tables override the PLC's logic for specified inputs/outputs, masking both the program logic and physical I/O. The PLC stores force values in non-volatile memory.

SAFETY WARNING: Forcing physical outputs in a running process can cause machine motion, valve actuation, or hazardous energization. Always:
• Place the controlled equipment in a safe state before forcing.
• Use a second engineer as a witness for live machine forcing.
• Document the forced points and clear them at the end of the session via Force → Stop forcing.
• Never force outputs on a process where unexpected motion would result in injury.

6.3 Reading and Writing Tag Values from Watch Tables

Watch Table Column Conventions
Column Meaning Edit Allowed
Name Symbolic tag name Yes (enter new symbol)
Address Absolute address (e.g., %MW10) Yes
Display format BOOL, INT, REAL, HEX, etc. Yes
Monitor value Current value from CPU Read-only during monitor
Modify value One-shot write Yes (CTRL+F9 to apply)
Force value Persistent override Yes (with safety check)
Status (LED icons) Quality flags Read-only

7. Data Block Upload and Data Transfer Operations

Uploading the project recovers global DBs as know-how protected only when protection was active on the CPU. If know-how protection is enabled, the block body is not recovered — only the interface declaration. To inspect protected blocks, the engineer must request the unprotect action from the CPU using the password defined during the original download.

For applications requiring periodic data transfer between data blocks — for example, logging recipe data from a runtime DB to a permanent storage DB — Siemens provides the following reference procedure in their support knowledge base:

This entry demonstrates standard techniques such as MOVE_BLK_VARIANT (SFC13-style) for S7-1500, and the POKE_BLK / PEEK_BLK pattern using the AT declaration overlay for S7-1200. For structured DB-to-DB transfer, the standard pattern is:

// SCL example: copy 100 bytes from source DB to destination DB
// S7-1200/S7-1500 compatible

FOR i := 0 TO 99 DO
    "dest_DB".data[i] := "src_DB".data[i];
END_FOR;

For larger transfers, use the FieldRead/FieldWrite instructions or the optimized SCL MOVE_BLK function with the source and target declared as ARRAY[*] OF BYTE with appropriate AT view declarations.

8. PROFINET I-Device Transfer Areas (Advanced Context)

When the S7-1200 acts as a PROFINET I-Device (intelligent IO device), the upload will also recover the transfer area configuration. Transfer areas define which inputs and outputs are exchanged with the higher-level IO controller. The configuration rules are described in the TIA Portal V20 documentation:

Key rules to verify after upload:

I-Device Transfer Area Rules
Rule Description
Slot constraints Transfer areas occupy subslots 1, 2, 3, ... in the I-Device GSD file
Length limits Maximum 1440 bytes per transfer area direction in S7-1200 V4.x
Consistency Each transfer area is consistent only within itself; ensure the controller accesses full area
Direction An area is either input (I-device → controller) or output (controller → I-device); not both
Empty areas A transfer area must contain at least one element; empty areas are not permitted in the GSD export

9. Troubleshooting Matrix

Use the following matrix to diagnose common failure modes during the upload or online connection procedure.

S7-1200 Upload and Online Connection Troubleshooting Matrix
Symptom Likely Cause Diagnostic Step Corrective Action
Accessible Nodes returns empty NIC on wrong subnet Run cmd → arp -a Set static IP matching PLC subnet (e.g., 192.168.0.10/24)
Accessible Nodes returns empty Wrong PG/PC interface selected Options → Set PG/PC Interface Select S7ONLINE → correct NIC
Accessible Nodes returns empty Firewall blocks UDP 34964 / TCP 102 Windows Defender → Inbound Rules Allow TIA Portal on port 102 and 34964
Accessible Nodes finds PLC, but upload fails with "0xE0A0" Version mismatch Check PLC FW vs TIA version Upgrade TIA Portal to a version equal to or higher than the project version
Upload fails with "0x0118" Know-how protection on a block Online & Diagnostics → Properties → Protection Enter know-how password and re-upload
Upload fails with "0x0706" Password-protected PLC Online & Diagnostics → Access level Enter the access password
Go online shows "Online: not possible — different hardware" Local project has wrong order number Compare device order number Re-upload as new station
Monitor on yields empty values in RUN Online view not active Click glasses icon again Verify green online status in status bar
Block opens blank after upload Compiled without online data Right-click block → Compare → Online Open block with monitor enabled
Force on output has no effect Force not committed in RUN Watch table force icon shows yellow Click force icon to commit, then start forcing
Connection drops after 60 seconds Laptop power management disables NIC Device Manager → NIC → Power Management Uncheck "Allow the computer to turn off this device to save power"

9.1 Common Siemens Error Codes

Hexadecimal Error Codes for Upload and Online Operations
Code Meaning Resolution
0x000F User cancellation No action required
0x0118 Block protection active Deactivate know-how protection on the CPU
0x0155 Access level too low Set PG to "Full access (no protection)" or use password
0x0706 Wrong password or access denied Verify password; check PLC access level settings
0x0A2A Communication error / connection lost Check physical link; rescan accessible nodes
0x0E0A0 Project version higher than TIA Portal version Upgrade TIA Portal or use the original version
0x0F021 Firmware downgrade not supported Update PLC firmware or project to compatible version

10. Verification and Commissioning Checklist

Use the following checklist to confirm a complete and reliable upload and online session:

  1. Open the project that resulted from the upload and confirm the project name is Upload_[DeviceName]_[Date].
  2. Expand the project tree and confirm CPU order number and firmware match the physical label on the device (e.g., 6ES7 214-1AG40-0XB0 / FW V4.4).
  3. Confirm all program blocks (OBs, FBs, FCs, DBs) are present. A project with no FBs and only OB1 is normal for a small S7-1200 program.
  4. Open OB1, click Monitor on, and confirm inputs update with physical I/O state.
  5. Create a new watch table, add tags I0.0, I0.1, Q0.0, M0.0, and verify polling.
  6. Use Online → Online & Diagnostics → Diagnostic buffer and confirm the diagnostic buffer is readable.
  7. Save the project to the engineering repository. File → Save As → choose a meaningful project name (e.g., PlantA_Line3_S71200).
  8. Before disconnecting, click Go offline. Confirm the status indicator transitions to Offline.
  9. Export the project archive: Project → Archive → TIA Portal Project Archive (.zap20) and store in a versioned folder structure.

11. Field-Proven Caveats and Best Practices

  • Save the recovered project immediately. Uploaded projects sit in TIA Portal's memory and are vulnerable to crash; save and archive before any further work.
  • Keep the engineering version consistent. If the S7-1200 was programmed in V17 SP1, stay on V17 SP1 or upgrade both the project and the engineering station to V20 in a controlled change.
  • Document the CPU firmware and hardware version. A replacement CPU from the same order number may have a higher firmware version, which can change system block behavior on the next download.
  • Use the PRONETA tool for subnet discovery if the S7-1200's IP is unknown. Siemens PRONETA is a free utility that scans PROFINET networks and reports device IPs, names, and MAC addresses.
  • Disable Windows hibernation on the engineering station to prevent abrupt NIC suspension mid-session.
  • Use a dedicated engineering switch with port-mirroring for diagnostic capture in complex networks. Avoid connecting the S7-1200 directly to a corporate network where firewalls may block PROFINET discovery.
  • Verify protective devices — surge protectors, EMI filters, and the PLC's PE ground — before any debugging session on a newly installed cabinet.

12. Summary Procedure

The end-to-end workflow for recovering an S7-1200 program and going online with TIA Portal is:

  1. Set PG/PC interface to the NIC bound to the S7-1200's subnet.
  2. Set a static IP on the engineering NIC matching the subnet.
  3. Open TIA Portal with no project loaded.
  4. Click Online → Accessible Nodes and verify the CPU appears.
  5. Right-click the CPU and select Upload device as new station (hardware and software).
  6. When prompted, click Yes to go online immediately with the uploaded device.
  7. In the project tree, open OB1 and click the Monitor on (glasses) icon.
  8. Create a watch table and add tags for live monitoring.
  9. Save the project and archive as a .zap20 file.

Why is "Upload device as new station" greyed out in TIA Portal?

The menu item is disabled when no project is open or when the wrong PG/PC interface is selected. Close all open TIA Portal projects, then re-select the CPU in the Accessible Nodes pane. Confirm the PG/PC interface is bound to the correct NIC via Options → Set PG/PC Interface.

Can I upload from an S7-1200 if I do not know the original TIA Portal version?

Yes. The upload creates a project matching the current CPU content. However, if the CPU was programmed in a higher TIA Portal version than the engineering station, the upload will fail with error 0x0E0A0. Upgrade the engineering station to a TIA Portal version equal to or higher than the project version to resolve this.

What is the difference between "Download to device" and "Upload from device"?

Download to device writes the project from the engineering station to the PLC. Upload from device reads the project from the PLC back to the engineering station. Use Upload when recovering a project from a PLC that has no matching offline project, and Download when transferring a known project to a freshly commissioned PLC.

Why does the project tree show blocks, but the block editor opens empty?

The project is in the offline view, or the online data is not being applied. Click the Monitor on (glasses) icon in the editor toolbar to bind the block to the CPU's current online content. If the block is still empty, right-click the block in the project tree, select Compare against the online version, and choose Online as the reference.

How do I find the IP address of an S7-1200 with an unknown configuration?

Use the Siemens PRONETA tool for PROFINET network analysis, or the TIA Portal Accessible Nodes scan (Online → Accessible Nodes) which performs a PROFINET DCP discovery broadcast. If the device is in a different subnet, assign a static IP to the engineering NIC and use the PROFINET LLDP/DCP discovery over a direct cable connection.

Back to blog