WinCC Flexible AS511 Communication Loss: Configuring HMI Alarms

David Krause12 min read
SiemensTroubleshootingWinCC
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

When a WinCC Flexible 2008 SP2 runtime station communicates with a SIMATIC S5 PLC over the legacy AS511 protocol on a serial COM port, a cable disconnect, PLC stop, or interface failure during operation produces no visible warning on the operator panel. Process values freeze at the last scanned value, substitutes are applied silently, and the operator can continue to issue commands based on stale data. In any application where a Start, Stop, Jog, or Setpoint command can damage equipment, this silent failure mode is a Class A operational hazard.

The behavior is a documented characteristic of the connection diagnostic subsystem in WinCC Flexible when the active screen's alarm control is not configured to display the System alarm class. The connection state transition is recorded in the internal alarm buffer at the moment it occurs, but unless an alarm view subscribed to that class is visible, the operator never sees the diagnostic event.

Safety relevance: Loss of visibility into PLC state must drive at least one of: a visible alarm, an audible annunciator, a forced logout, or an automatic navigation to a dedicated "No Connection" screen. A comm-loss that is generated but never displayed is functionally identical to no alarm at all.

AS511 Protocol Background

AS511 is the original Siemens serial protocol used by the SIMATIC S5 family. It is a proprietary point-to-point master-slave protocol operating over RS-232 (V.24) between the HMI (master) and the S5 CPU (slave). Each transaction is initiated by the HMI, which polls the S5 for input/output process image and data block content.

AS511 default COM port parameters
Parameter Value
Baud rate 9600 or 19200 (CPU dependent)
Data bits 8
Parity Even
Stop bits 1
Handshake RTS/CTS or none (cable dependent)
Connector (S5 side) 15-pin Sub-D, PG/MODEM port
Maximum cable length 15 m (RS-232 limit)
Topology Point-to-point, single master

Because AS511 is a polled, single-master protocol, the HMI can detect a break in the physical layer (cable removed, PLC powered down, PLC in STOP with serial interface disabled) by timeout on a poll cycle. WinCC Flexible raises an internal Connection state bit per configured connection and emits a system alarm of class System into the alarm buffer. The alarm text is language-dependent; in English it typically reads "Connection to interface COM1/IF1 is broken."

WinCC Flexible Communication Architecture

WinCC Flexible 2008 SP2 organizes runtime communication into two layers:

  1. Connection layer — one or more logical connections, each bound to a protocol driver (AS511, MPI/PROFIBUS, Ethernet, OPC). Each connection has a lifecycle state of Established, Disconnected, or Error.
  2. Tag layer — HMI tags polled cyclically or on change. Each tag is bound to a connection; on connection failure, tag updates stop and the configured substitute value is used.

When the connection state transitions to Disconnected, the runtime generates a system alarm of class System. This alarm is queued in the alarm buffer regardless of which screen is currently displayed. However, a Message View control must be on a visible screen AND must have the System alarm class enabled in its filter for the operator to ever see the entry.

Connection Driver Alarm Buffer Message View Operator state filter If System class not enabled — operator sees NOTHING

Root Cause: Why No Warning Appears

There are three common configuration states that suppress connection-loss warnings:

  1. Message View filter excludes the System class. The default Message View template in many WinCC Flexible sample projects shows only the Errors and Warnings classes. The System class is unchecked, so the connection-loss alarm is generated but never rendered.
  2. No Message View on the active screen. Even if the System class is enabled, if the operator is on a screen with no Message View control, the alarm has no surface to render on. The alarm still exists in the buffer and is logged, but the operator sees nothing.
  3. Substitute value identical to last good value. A numeric tag with substitute value 0 and a process value of 0 at the moment of disconnect will appear unchanged. An operator looking at a level reading of "0 mm" cannot distinguish "0 is real" from "0 is substitute".

The reported symptom — "I receive the message at startup if not connected, but not when the cable is removed during operation" — is consistent with cause #1. At startup, the system alarm is shown because the Startup screen typically contains a Message View that includes the System class. After navigation to a process screen that lacks a properly configured Message View, the same alarm class is filtered out.

Solution 1: Enable the System Alarm Class in Message View

The minimum fix is to enable the System class on every Message View control that the operator may see.

Step-by-step

  1. In the WinCC Flexible ES project tree, expand Screens and open each screen that contains a Message View (Alarm View in some builds).
  2. Click the Message View control to select it.
  3. In the Properties window, open Appearance → Alarm classes (or in older builds: Settings → Alarm classes).
  4. Check the box next to System in addition to Errors and Warnings.
  5. Optionally, set Display alarms without acknowledgment to "Yes" and configure a flash color so the entry is visually conspicuous.
  6. Compile and download to the runtime panel.
Build note: In WinCC Flexible 2008 SP2 the alarm class names are Errors, Warnings, System, Diagnosis Events, and Recipe. Make sure at least System is checked on every Message View that may be visible during a comm-loss event.

After this change, a cable removal during operation produces a system alarm rendered in the Message View within one polling cycle plus the connection timeout (default AS511 timeout is 3 s, configurable in the connection parameters).

Solution 2: PLC-Side Watchdog Tag with User-Defined Alarm

For safety-critical applications, a system alarm alone may not be sufficient because it is bound to the same connection that has just failed. A watchdog tag provides an independent health bit driven by the PLC's own OB1 / OB100 cycle. The HMI monitors this tag and raises a user-defined alarm if it is not toggled within a defined window.

PLC program (STEP 5, OB1 excerpt)

; Watchdog flip-flop
; DB100.DBX0.0 toggled every PLC cycle in OB1
;
OB1
  AN  F 100.0
  S   F 100.0
  AN  F 100.0
  SET
  S   DB100.DBX0.0   ; toggle DB bit each cycle
  ...

For S7-300 / S7-400 used in front of an S5 line (gateway configuration), the equivalent is a clock bit such as M0.5 from OB35, or a dedicated toggle in OB1 written to a data word in DB100. The bit must be visible at a fixed address on the AS511 side of the gateway.

HMI configuration

  1. Define an HMI tag PLC_Health of type Bool with acquisition Cyclic continuous, polling cycle 1 s, bound to the S5 connection, address DB100.DBX0.0.
  2. Create a tag-based alarm with trigger condition PLC_Health = 0 for more than 5 s.
  3. Assign the alarm to class Errors (already enabled in the default Message View) and configure a high-priority color (for example, red flashing).

The 5-second window absorbs normal AS511 retransmits and short comms hiccups without false alarms, while still being short enough to prevent operator error.

Solution 3: Scheduler Script for Automatic Screen Change

For plants where the operator must be physically removed from the process view on comm loss, a VBScript scheduled task can navigate to a dedicated "No Connection" screen and require password re-authentication to return to process control.

VBScript (WinCC Flexible, scheduled task — every 1 s)

' Watch for comm loss to AS511 connection COM1
If SmartTags("ConnectionState_COM1") = 0 Then
    ' Disable operator inputs
    SmartTags("HMI_InputsEnabled") = False
    ' Navigate to warning screen
    ShowScreen "Screen_Comm_Lost", 0
    ' Log event to trace file
    HMIRuntime.Trace "Comm loss to S5 detected at " & Now
End If

The internal tag ConnectionState_COM1 is created automatically by the connection wizard and reflects the live state of the AS511 driver. Pair this with a password-protected "Acknowledge" button on the Screen_Comm_Lost screen that performs ShowScreen "Main_Process", 1 only after successful authentication.

Configuring the AS511 Connection

Connection timeout and retry behavior must be tuned so that the operator sees the alarm quickly, but transient noise does not generate false events.

Recommended AS511 connection parameters
Parameter Recommended Comment
Baud rate 19200 Maximum supported by AS511; faster failure detection.
Polling cycle (acquisition) 250 ms – 1 s Shorter = faster failure detection, higher CPU load on the S5.
Connection timeout 3 s After this, connection state goes to Disconnected.
Retry attempts 2 Recover from single dropped frames without alarm.
Substitute value (per tag) Distinct from real range where possible Use NaN or "----" for analog tags so operator sees "value lost".
Area pointer — coordination Enabled Required for screen change via VBScript on comm loss.

Substitute Value Strategy

The substitute value is what the HMI displays when the tag has not been updated successfully. A common error is to use 0 as a substitute, which collides with legitimate process values. Recommended practice:

  • Analog tags: use a sentinel such as 32767 or the string ---- to make the lost state obvious.
  • Boolean tags: use 0 only if 0 is not a valid process state; otherwise leave undefined and let the default substitute apply.
  • Critical control tags: bind a colored border or background to a quality-code tag, not to the value itself.

Verification Procedure

  1. Compile and download the project to the panel.
  2. Start Runtime. Confirm the message "Connection to interface COM1/IF1 is established" appears.
  3. Navigate to a process screen. If your design omits a Message View on process screens, add a temporary one for the test.
  4. Disconnect the AS511 cable.
  5. Within timeout + 1 polling cycle (typically 4 s), the system alarm "Connection to interface COM1/IF1 is broken" should appear in the active Message View, OR the operator should be navigated to Screen_Comm_Lost by the scheduler script.
  6. Reconnect the cable. Confirm the alarm clears and (if the script is in use) the operator can re-authenticate and return to the process screen.
  7. Repeat the test while the PLC is in STOP. The HMI should still detect the loss because the AS511 driver returns no response on a STOP CPU with disabled PG interface.

Migration Considerations to TIA Portal / WinCC Unified

WinCC Flexible 2008 SP2 reached end of life; the S5 / AS511 path is now maintained only through WinCC (TIA Portal) V15 and later with a TP/OP panel and a SIMATIC S7-1200/1500 in front of the S5 (acting as a protocol gateway), or via the WinCC Unified runtime on a PC.

For new deployments the recommended path is the Troubleshooting — Procedure if there is no connection (RT Unified) documentation, where the connection is established at the start of Runtime and a system alarm is generated on failure. The same System-class visibility rule applies: the alarm control on the screen must have the System class enabled.

For S5 legacy replacement, the standard migration path is to install an S7-1500 with an AS511-to-PROFINET gateway (for example, a Helmholz RPI 32 or Insevis S5-LAN) and replace the HMI with a Comfort Panel or Unified PC. The HMI-side warning logic is identical: enable the System class in the alarm control, add a watchdog tag, and wire the substitute values to distinguishable sentinels.

Troubleshooting Matrix

Comm-loss warning not visible — diagnosis and fix
Symptom Likely cause Fix
Alarm at startup, none during operation Startup screen has Message View with System class; process screens do not Enable System class on all Message Views
No alarm at startup, none during operation No Message View on any visible screen, or all have System unchecked Add a Message View or enable System class globally
Alarm fires but is immediately overwritten Alarm class flash disabled, or color matches background Configure high-priority flash color and audible horn
Alarm fires but process values still update Substitute value cycle continues; connection state bit not polled Bind alarms to ConnectionState internal tag, not tag values
Alarm fires but operator dismisses it Class is "Information" or "Warning" not "Error" Promote connection-loss alarm to Errors class with acknowledgment
Alarm fires too often on noisy cable Timeout too short, no retry configured Increase timeout to 3 s, set retry attempts to 2
Alarm fires but no substitute value visible Substitute value collides with real process value Use NaN / "----" sentinel for analog tags
Alarm fires, screen change script does not run Area pointer coordination not enabled on the connection Enable coordination area pointer in connection properties

Field Commissioning Checklist

  • Message View on every operator-visible screen has the System class enabled.
  • Connection timeout set to a minimum of 3 s, retry attempts 2.
  • At least one redundant health path implemented (PLC watchdog or scheduler script).
  • Substitute values distinguishable from real values (NaN / "----" / distinct sentinel).
  • Audible horn or stack light bound to Error-class alarms.
  • Logged alarm persistence verified (alarm buffer survives screen change and panel restart if the alarm log is on a backed-up store).
  • Recovery path tested: reconnection + operator re-authentication.
  • PLC STOP behavior tested and documented in the operator instructions.
  • Coordinator area pointer enabled if using VBScript for navigation.
  • Language of alarm text verified for each installed runtime language.
Documentation: Record the alarm text in the operator's language, the recovery procedure, and the responsible engineer. A comm-loss alarm that is acknowledged but never understood is a latent hazard and will recur at the worst possible moment.

Diagnostic State Machine

Disconnected Connecting (poll) Established Timeout / Error start ack timeout reconnect fail

FAQ

Why does WinCC Flexible show the comm-loss alarm at startup but not during operation?

The system alarm of class "System" is raised on every connection state change, including cable removal during operation. It is not visible because the active process screen's Message View control is filtering the System class out. Enable "System" in the Message View's alarm class filter on every operator-visible screen.

How fast does WinCC Flexible detect an AS511 cable break?

Detection time equals the connection timeout (default 3 s) plus one polling cycle. With a 1 s polling cycle the operator sees the alarm within 4 s of the physical disconnect. Reduce timeout to 2 s for safety-critical applications and accept a higher false-alarm rate on marginal cables.

Can I detect S5 PLC STOP separately from cable removal?

No, not over a pure AS511 link — the protocol returns no response in both cases, so the HMI sees only a generic connection loss. If the application must distinguish STOP from cable break, add an S5 status bit (for example, an OB1 clock-marker) to a DB and read it as a watchdog; if the bit stops toggling while the connection is up, the CPU has stopped.

Do I need a watchdog tag if I enable the System alarm class?

For most non-safety applications, no. The System alarm is bound to the connection driver and is the most reliable indicator. A watchdog tag is recommended for SIL-classified applications, for processes where the operator can issue destructive commands, or when the connection driver itself may be in a wedged state that does not raise a system alarm.

How do I migrate this to TIA Portal / WinCC Unified?

Replace the S5 with an S7-1500 plus an AS511-to-PROFINET gateway, and use a Comfort Panel or Unified PC. The HMI-side warning logic is identical: enable the System class in the alarm control. See the official Troubleshooting — Procedure if there is no connection (RT Unified) documentation for the modern equivalent.

Back to blog