Upload S7-1200 Program to TIA Portal: Online Monitoring Setup
This technical reference describes the end-to-end procedure for retrieving a program from a SIMATIC S7-1200 CPU to a TIA Portal engineering station when the original project is not available, and for establishing a stable online connection for live monitoring. The procedure covers project recovery via Upload device as new station, online block visibility, OB/FB/FC/DB inspection, watch table use, and the IP/PG interface prerequisites that commonly block first-time engineers. The workflow is aligned with STEP 7 in TIA Portal V17, V18, V19, and V20.
1. Problem Definition and Scope
When an S7-1200 has been programmed on a different engineering station and the original TIA Portal project file (.ap17/.ap18/.ap19/.ap20) is not available, the program must be recovered directly from the PLC's load memory. The S7-1200 stores:
- System blocks (SDB) — hardware configuration, system data
- Organization Blocks (OBs) — OB1, OB100, OB82, OB121, etc.
- Function Blocks (FBs) and Functions (FCs) — user logic
- Data Blocks (DBs) — both instance and global data
- Technology objects (TOs) — PID, motion, high-speed counters (Firmware V4.0+)
Uploading retrieves all of these into a new offline project that matches the PLC's runtime configuration. After upload, the engineering station can establish an online connection for live value monitoring, forcing, and diagnostics.
2. Prerequisites
Before executing the upload procedure, verify the following items:
| Item | Requirement | Verification |
|---|---|---|
| STEP 7 in TIA Portal | V17, V18, V19, or V20 (matching or higher than PLC project) | Help → About TIA Portal → Show Details |
| S7-1200 CPU | Firmware V4.0 or higher recommended; V4.2/V4.3/V4.4/V4.5/V4.6 supported | Online → Accessible Nodes → CPU Properties |
| Ethernet cable | RJ45, Cat 5e or higher, direct or via switch | Link LED on CPU port solid green |
| PLC IP address | Known (default 192.168.0.1, mask 255.255.255.0) or discoverable | Online → Accessible Nodes scan |
| PG/PC interface | Intel I211/I219 or compatible NIC selected in TIA Portal | Options → Set PG/PC Interface |
| User permission | Read/write access to PLC (default: no password unless set) | Online → Accessible Nodes → right-click → Online & Diagnostics |
| Firewall | Port 102 (ISO-TSAP) inbound/outbound allowed | Windows Defender Firewall with Advanced Security |
3. Configuring the PG/PC Interface
Open TIA Portal and access the interface selection. This is the most common source of "PLC not found" or "connection refused" errors during the first scan of accessible nodes.
- Launch TIA Portal (no project open is acceptable at this stage).
- Navigate to
Options → Set PG/PC Interface. - Select the access point
S7ONLINE (STEP 7). - From the interface list, choose the physical NIC bound to the subnet of the S7-1200. For a direct connection, this is typically the Intel(R) Ethernet Connection or Realtek PCIe GbE Family Controller.
- If the IP of the NIC does not match the PLC's subnet, click Properties and assign a static IPv4 address (e.g., 192.168.0.10 / 255.255.255.0).
- Click OK and close the dialog. The setting persists per user profile.
3.1 Static IP Assignment for the Engineering NIC
If the S7-1200 is set to its default IP (192.168.0.1) and the laptop's NIC is on a different subnet (e.g., DHCP-assigned 192.168.1.x), the Accessible Nodes scan will return an empty list even though the link LED is green. Configure the NIC manually:
| Parameter | Value |
|---|---|
| IP address | 192.168.0.10 |
| Subnet mask | 255.255.255.0 |
| Default gateway | (empty for direct link) |
| Preferred DNS | (empty) |
4. Performing the Upload from the PLC
There are two distinct entry points for the upload action. Choose the method that matches the project state on the engineering station.
4.1 Method A — Upload from Accessible Nodes (no project open)
This is the correct method when the engineering station has no existing project that references the target CPU.
- Open TIA Portal. Do not open a project; remain at the Portal view or Project view with no project loaded.
- From the menu bar select
Online → Accessible Nodes. - In the Accessible Nodes pane (typically docked on the right), TIA Portal will perform a broadcast ARP/PROFINET DCP scan and list every S7-1200 on the local subnet.
- Confirm the target CPU is shown with its IP address, MAC address, device name, and firmware version.
- Right-click the target CPU and select
Upload device as new station (hardware and software). - TIA Portal opens a wizard. Confirm the target device and click Upload.
- TIA Portal creates a new project named Upload_[DeviceName]_[Date] in the default project repository.
- After completion, TIA Portal prompts: Do you want to go online with the uploaded device? Click Yes to immediately enter the online view, or No to inspect offline first.
4.2 Method B — Upload from Project View (existing project open)
Use this method if a TIA Portal project is already open but does not match the CPU's actual configuration.
- In Project View, select the PLC device in the project tree.
- From the menu select
Online → Upload from device (software). - In the dialog, select the accessible node matching the CPU's IP address.
- Check Replace the project data with the online data to overwrite the local project with the CPU's runtime data.
- Click Upload and confirm the overwrite prompt.
4.3 Verification of Uploaded Content
After upload, expand the project tree and confirm the following appear:
-
Device configuration— shows the CPU order number (e.g., 6ES7 214-1AG40-0XB0) and signal modules -
Program blocks— OBs, FBs, FCs, and DBs visible -
PLC tags— name table recovered from CPU -
Watch and force tables— empty by default; create new ones for monitoring -
Technology objects— for S7-1200 V4.0+ with PID or motion configured
5. Going Online and Enabling Live Monitoring
The online connection is the second half of the workflow. A successful upload is required before online monitoring becomes useful, since the project must match the CPU to bind symbolic names to memory addresses.
5.1 Establishing the Online Connection
- Select the PLC device in the project tree.
- Click the Go online icon (the symbol resembling two monitors) in the toolbar, or press
Ctrl+K. - If prompted, choose the PG/PC interface and the subnet.
- The status bar at the bottom right transitions to Online and displays the connection state in green. A red status indicates failure — see Section 9 for the diagnostic matrix.
- When the CPU is in RUN, online monitoring of code blocks is disabled by default. Switch the view via
Online → Online & Diagnostics → Operating modeor click the Monitor on/off icon (glasses symbol) in the editor toolbar.
5.2 Block Visibility — Why the Online View May Appear Empty
A common confusion after upload is that the project tree shows blocks but the editor panes are blank. The cause is that the project is in the offline view. To force the editor to render the online values:
- Click on any program block (e.g., OB1) in the project tree.
- Open the block. If the block contains code, but the LAD/FBD/ST view appears grey/empty, ensure you are looking at the online version, not the offline one.
- Click the Monitor on button (the glasses icon). TIA Portal recompiles the block against online data and displays current operand values inline next to the logic elements.
| Condition | Offline View | Online View (Monitor on) |
|---|---|---|
| Block exists only in project | Visible, editable | Not visible |
| Block exists only in CPU | Not visible | Visible, read-only |
| Block in both and identical | Visible | Visible, current values shown |
| Block in both but differing | Visible (compile required) | Visible with online values |
6. Live Monitoring with Watch Tables and Force Tables
Watch tables are the primary live-monitoring tool for engineers who need to inspect and (with caution) modify process values while the PLC is in RUN.
6.1 Creating a Watch Table
- In the project tree, right-click
Watch and force tables. - Select
Add new watch table. Name it (e.g., WT_IO_Status). - Click on the Name column and type the symbolic name (e.g.,
Motor_Start) or absolute address (e.g.,I0.0). TIA Portal auto-completes from the PLC tag table. - Click the Monitor all button (the binoculars) or press
Ctrl+F5to start live polling. The default poll interval is 1000 ms; right-click the table header to adjust to 200/500/1000/2000 ms.
6.2 Force Tables — Engineering Use and Safety
Force tables override the PLC's logic for specified inputs/outputs, masking both the program logic and physical I/O. The PLC stores force values in non-volatile memory.
• Place the controlled equipment in a safe state before forcing.
• Use a second engineer as a witness for live machine forcing.
• Document the forced points and clear them at the end of the session via
Force → Stop forcing.• Never force outputs on a process where unexpected motion would result in injury.
6.3 Reading and Writing Tag Values from Watch Tables
| Column | Meaning | Edit Allowed |
|---|---|---|
| Name | Symbolic tag name | Yes (enter new symbol) |
| Address | Absolute address (e.g., %MW10) | Yes |
| Display format | BOOL, INT, REAL, HEX, etc. | Yes |
| Monitor value | Current value from CPU | Read-only during monitor |
| Modify value | One-shot write | Yes (CTRL+F9 to apply) |
| Force value | Persistent override | Yes (with safety check) |
| Status (LED icons) | Quality flags | Read-only |
7. Data Block Upload and Data Transfer Operations
Uploading the project recovers global DBs as know-how protected only when protection was active on the CPU. If know-how protection is enabled, the block body is not recovered — only the interface declaration. To inspect protected blocks, the engineer must request the unprotect action from the CPU using the password defined during the original download.
For applications requiring periodic data transfer between data blocks — for example, logging recipe data from a runtime DB to a permanent storage DB — Siemens provides the following reference procedure in their support knowledge base:
This entry demonstrates standard techniques such as MOVE_BLK_VARIANT (SFC13-style) for S7-1500, and the POKE_BLK / PEEK_BLK pattern using the AT declaration overlay for S7-1200. For structured DB-to-DB transfer, the standard pattern is:
// SCL example: copy 100 bytes from source DB to destination DB
// S7-1200/S7-1500 compatible
FOR i := 0 TO 99 DO
"dest_DB".data[i] := "src_DB".data[i];
END_FOR;
For larger transfers, use the FieldRead/FieldWrite instructions or the optimized SCL MOVE_BLK function with the source and target declared as ARRAY[*] OF BYTE with appropriate AT view declarations.
8. PROFINET I-Device Transfer Areas (Advanced Context)
When the S7-1200 acts as a PROFINET I-Device (intelligent IO device), the upload will also recover the transfer area configuration. Transfer areas define which inputs and outputs are exchanged with the higher-level IO controller. The configuration rules are described in the TIA Portal V20 documentation:
Key rules to verify after upload:
| Rule | Description |
|---|---|
| Slot constraints | Transfer areas occupy subslots 1, 2, 3, ... in the I-Device GSD file |
| Length limits | Maximum 1440 bytes per transfer area direction in S7-1200 V4.x |
| Consistency | Each transfer area is consistent only within itself; ensure the controller accesses full area |
| Direction | An area is either input (I-device → controller) or output (controller → I-device); not both |
| Empty areas | A transfer area must contain at least one element; empty areas are not permitted in the GSD export |
9. Troubleshooting Matrix
Use the following matrix to diagnose common failure modes during the upload or online connection procedure.
| Symptom | Likely Cause | Diagnostic Step | Corrective Action |
|---|---|---|---|
| Accessible Nodes returns empty | NIC on wrong subnet | Run cmd → arp -a
|
Set static IP matching PLC subnet (e.g., 192.168.0.10/24) |
| Accessible Nodes returns empty | Wrong PG/PC interface selected | Options → Set PG/PC Interface | Select S7ONLINE → correct NIC |
| Accessible Nodes returns empty | Firewall blocks UDP 34964 / TCP 102 | Windows Defender → Inbound Rules | Allow TIA Portal on port 102 and 34964 |
| Accessible Nodes finds PLC, but upload fails with "0xE0A0" | Version mismatch | Check PLC FW vs TIA version | Upgrade TIA Portal to a version equal to or higher than the project version |
| Upload fails with "0x0118" | Know-how protection on a block | Online & Diagnostics → Properties → Protection | Enter know-how password and re-upload |
| Upload fails with "0x0706" | Password-protected PLC | Online & Diagnostics → Access level | Enter the access password |
| Go online shows "Online: not possible — different hardware" | Local project has wrong order number | Compare device order number | Re-upload as new station |
| Monitor on yields empty values in RUN | Online view not active | Click glasses icon again | Verify green online status in status bar |
| Block opens blank after upload | Compiled without online data | Right-click block → Compare → Online | Open block with monitor enabled |
| Force on output has no effect | Force not committed in RUN | Watch table force icon shows yellow | Click force icon to commit, then start forcing |
| Connection drops after 60 seconds | Laptop power management disables NIC | Device Manager → NIC → Power Management | Uncheck "Allow the computer to turn off this device to save power" |
9.1 Common Siemens Error Codes
| Code | Meaning | Resolution |
|---|---|---|
| 0x000F | User cancellation | No action required |
| 0x0118 | Block protection active | Deactivate know-how protection on the CPU |
| 0x0155 | Access level too low | Set PG to "Full access (no protection)" or use password |
| 0x0706 | Wrong password or access denied | Verify password; check PLC access level settings |
| 0x0A2A | Communication error / connection lost | Check physical link; rescan accessible nodes |
| 0x0E0A0 | Project version higher than TIA Portal version | Upgrade TIA Portal or use the original version |
| 0x0F021 | Firmware downgrade not supported | Update PLC firmware or project to compatible version |
10. Verification and Commissioning Checklist
Use the following checklist to confirm a complete and reliable upload and online session:
- Open the project that resulted from the upload and confirm the project name is Upload_[DeviceName]_[Date].
- Expand the project tree and confirm CPU order number and firmware match the physical label on the device (e.g., 6ES7 214-1AG40-0XB0 / FW V4.4).
- Confirm all program blocks (OBs, FBs, FCs, DBs) are present. A project with no FBs and only OB1 is normal for a small S7-1200 program.
- Open OB1, click Monitor on, and confirm inputs update with physical I/O state.
- Create a new watch table, add tags
I0.0,I0.1,Q0.0,M0.0, and verify polling. - Use
Online → Online & Diagnostics → Diagnostic bufferand confirm the diagnostic buffer is readable. - Save the project to the engineering repository.
File → Save As→ choose a meaningful project name (e.g., PlantA_Line3_S71200). - Before disconnecting, click Go offline. Confirm the status indicator transitions to Offline.
- Export the project archive:
Project → Archive → TIA Portal Project Archive (.zap20)and store in a versioned folder structure.
11. Field-Proven Caveats and Best Practices
- Save the recovered project immediately. Uploaded projects sit in TIA Portal's memory and are vulnerable to crash; save and archive before any further work.
- Keep the engineering version consistent. If the S7-1200 was programmed in V17 SP1, stay on V17 SP1 or upgrade both the project and the engineering station to V20 in a controlled change.
- Document the CPU firmware and hardware version. A replacement CPU from the same order number may have a higher firmware version, which can change system block behavior on the next download.
- Use the PRONETA tool for subnet discovery if the S7-1200's IP is unknown. Siemens PRONETA is a free utility that scans PROFINET networks and reports device IPs, names, and MAC addresses.
- Disable Windows hibernation on the engineering station to prevent abrupt NIC suspension mid-session.
- Use a dedicated engineering switch with port-mirroring for diagnostic capture in complex networks. Avoid connecting the S7-1200 directly to a corporate network where firewalls may block PROFINET discovery.
- Verify protective devices — surge protectors, EMI filters, and the PLC's PE ground — before any debugging session on a newly installed cabinet.
12. Summary Procedure
The end-to-end workflow for recovering an S7-1200 program and going online with TIA Portal is:
- Set PG/PC interface to the NIC bound to the S7-1200's subnet.
- Set a static IP on the engineering NIC matching the subnet.
- Open TIA Portal with no project loaded.
- Click
Online → Accessible Nodesand verify the CPU appears. - Right-click the CPU and select
Upload device as new station (hardware and software). - When prompted, click Yes to go online immediately with the uploaded device.
- In the project tree, open OB1 and click the Monitor on (glasses) icon.
- Create a watch table and add tags for live monitoring.
- Save the project and archive as a .zap20 file.
Why is "Upload device as new station" greyed out in TIA Portal?
The menu item is disabled when no project is open or when the wrong PG/PC interface is selected. Close all open TIA Portal projects, then re-select the CPU in the Accessible Nodes pane. Confirm the PG/PC interface is bound to the correct NIC via Options → Set PG/PC Interface.
Can I upload from an S7-1200 if I do not know the original TIA Portal version?
Yes. The upload creates a project matching the current CPU content. However, if the CPU was programmed in a higher TIA Portal version than the engineering station, the upload will fail with error 0x0E0A0. Upgrade the engineering station to a TIA Portal version equal to or higher than the project version to resolve this.
What is the difference between "Download to device" and "Upload from device"?
Download to device writes the project from the engineering station to the PLC. Upload from device reads the project from the PLC back to the engineering station. Use Upload when recovering a project from a PLC that has no matching offline project, and Download when transferring a known project to a freshly commissioned PLC.
Why does the project tree show blocks, but the block editor opens empty?
The project is in the offline view, or the online data is not being applied. Click the Monitor on (glasses) icon in the editor toolbar to bind the block to the CPU's current online content. If the block is still empty, right-click the block in the project tree, select Compare against the online version, and choose Online as the reference.
How do I find the IP address of an S7-1200 with an unknown configuration?
Use the Siemens PRONETA tool for PROFINET network analysis, or the TIA Portal Accessible Nodes scan (Online → Accessible Nodes) which performs a PROFINET DCP discovery broadcast. If the device is in a different subnet, assign a static IP to the engineering NIC and use the PROFINET LLDP/DCP discovery over a direct cable connection.