WinCC IDB V7.3 OPC UA Limitation Configuring TP1500 Comfort OPC

David Krause16 min read
SCADA ConfigurationSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

WinCC IDB V7.3 OPC UA Limitation: Configuring TP1500 Comfort as OPC Server

Engineers integrating a SIMATIC TP1500 Comfort panel as an OPC UA server with WinCC IndustrialDataBridge (IDB) V7.3 will find that the bridge cannot enumerate, subscribe to, or read OPC UA endpoints — even when the HMI OPC UA server is fully reachable from third-party clients such as OPC Scout V10. The limitation is rooted in the provider stack shipped with WinCC IDB V7.3 and is resolved only by upgrading to WinCC IDB V7.5 (or later), which added native OPC UA provider support. This reference explains the architectural reason for the limitation, verifies the failure mode with diagnostic steps, and provides the migration, workaround, and commissioning paths needed for a complete field deployment.

Affected software: SIMATIC WinCC IndustrialDataBridge V7.3 (and earlier V7.x releases). Resolved in: WinCC IndustrialDataBridge V7.5 / V7.5 SP1 / V8.0. Tested HMI: SIMATIC TP1500 Comfort, firmware/runtime image version V14.0.1, configured in TIA Portal V14 SP1.

1. Problem Statement

The integration scenario is a common shop-floor topology:

  1. A SIMATIC TP1500 Comfort HMI acts as the data source. It exposes internal tags (process values, alarms, recipes) as OPC UA nodes through its built-in OPC UA server.
  2. WinCC IndustrialDataBridge runs on a Windows-based station and acts as a data concentrator, forwarding subscribed tag values to downstream consumers (SQL databases, CSV files, MQTT brokers, ERP systems, cloud endpoints).
  3. The end IT customer expects to receive the data through whatever sink WinCC IDB writes to (database, file, or third-party interface).

The TP1500 OPC UA server was verified working end-to-end with OPC Scout V10: the client browsed the namespace, read tag values, and subscribed to data changes. The server URL used was opc.tcp://192.168.0.2:4870, the default OPC UA TCP port for a SIMATIC HMI Comfort OPC UA server.

When the engineer configured WinCC IDB V7.3 as a consumer and tried to add the TP1500 as a provider, only Local COM/DCOM servers were enumerated. Browsing the OPC Server field produced no OPC UA entries, and entering the URL opc.tcp://192.168.0.2:4870 manually produced either a connection error or was silently rejected because the V7.3 OPC DA provider cannot parse UA-style endpoints.

2. Root Cause: Provider Stack in WinCC IDB V7.3

WinCC IndustrialDataBridge uses a Provider / Consumer architectural model. A connection definition pairs exactly one provider (the data source) with one consumer (the data sink). Each connection runs as a scheduled job that reads from the provider and writes to the consumer at configurable intervals.

The V7.3 provider catalog shipped with the product included the following bridge providers:

Provider Type Notes
OPC Data Access (DA) COM/DCOM Supports OPC DA 2.05a and 3.0; reads from local and remote DA servers via Windows DCOM.
SQL / ODBC Database Reads rows from ODBC-compliant databases (MS SQL, MySQL, Oracle).
CSV / TXT File Reads delimited text files from a local or network path.
TCP / UDP socket Stream Generic raw socket provider for custom protocols.
WinCC OLE DB Database Reads alarm and tag archives from WinCC V7 RT databases.

Notably absent from this list is any OPC Unified Architecture (OPC UA) provider. The release notice for SIMATIC WinCC/IndustrialDataBridge V7.3 confirms the scope of the product: it is built on OPC DA 3.0 and DCOM, with no UA binary or web service stack.

OPC UA is a fundamentally different transport from OPC DA:

Property OPC DA OPC UA
Transport COM / DCOM (RPC over TCP) TCP binary (port 4840 default) or HTTPS/SOAP
Discovery Windows registry / DCOM enumerator LDS (Local Discovery Server) or manual URL
Security DCOM ACLs Built-in encryption, signing, certificates, user-token policies
Endpoint format OPCServer.ProgID opc.tcp://host:port or opc.https://host:port

Because the V7.3 provider framework is built around COM/DCOM and ProgID enumeration, it cannot connect to a UA endpoint even when the URL is typed manually. The URL parser rejects the opc.tcp:// scheme because no UA transport stack is linked into the V7.3 binary.

Conclusion: WinCC IDB V7.3 cannot bridge from an OPC UA server to any consumer. This is a product feature limitation, not a configuration error. No registry edit, DCOM permission change, or service restart will enable UA support in V7.3.

3. Affected Versions and Released Fix

WinCC IDB Version OPC DA Provider OPC UA Provider Status
V7.0 Yes No Legacy
V7.2 Yes No Legacy
V7.3 / V7.3 SP1 Yes No Limited — UA not supported
V7.4 Yes No Limited
V7.5 Yes Yes First version with native UA provider
V7.5 SP1 Yes Yes Maintenance release
V8.0 Yes Yes Current line

The OPC UA provider was added in V7.5, which is also when the product was aligned with the TIA Portal V14 SP1 HMI runtime images. The V7.5 release article is documented under SIMATIC WinCC IndustrialDataBridge V7.5 — Delivery Release and Order Numbers.

4. Diagnostic: Verifying the Limitation on Your Installation

Before assuming the limitation, confirm three independent facts on your bridge station and on the HMI.

4.1 Confirm WinCC IDB Version

  1. Open the WinCC IndustrialDataBridge Configuration tool on the bridge station.
  2. From the menu, select Help > About.
  3. Read the exact version string. For the limitation to apply, it must read WinCC IndustrialDataBridge V7.3 or any V7.x build below V7.5.
  4. Alternatively, inspect the installed MSI product code in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall for a key containing WinCC IndustrialDataBridge; the DisplayVersion value matches the Help > About output.

4.2 Confirm TP1500 OPC UA Server Is Reachable

  1. From the bridge station, open a command prompt and execute ping 192.168.0.2 (substitute the actual HMI IP). Confirm sub-millisecond response on the same subnet.
  2. Confirm TCP reachability to port 4870: Test-NetConnection 192.168.0.2 -Port 4870 (PowerShell) or telnet 192.168.0.2 4870.
  3. Launch OPC Scout V10 (a Siemens tool that ships with SIMATIC NET). Add a server by URL: opc.tcp://192.168.0.2:4870. Browse and read at least one tag to validate the UA stack.

4.3 Confirm the V7.3 Provider Catalog

  1. In WinCC IDB Configuration, create a new connection and reach the Provider step.
  2. Click the dropdown next to OPC Server. Only entries of the form OPCServer.<Vendor>.<ProgID> appear — no opc.tcp:// URIs.
  3. Attempt to type the URL manually. The field either rejects it or accepts it without producing a successful connection at runtime.

If 4.1 shows V7.3, 4.2 confirms the HMI is reachable, and 4.3 confirms only COM/DCOM servers appear, the limitation is reproduced. The resolution is to upgrade the bridge to V7.5+.

5. Workaround Options for V7.3 Deployments

Engineers constrained to V7.3 (license agreements, validation windows, plant-wide V7.3 standardization) have three workarounds. Each has different engineering trade-offs.

5.1 Option A — Add an OPC UA-to-DA Gateway

Insert a translation gateway between the TP1500 and the V7.3 bridge. The gateway subscribes to the TP1500 OPC UA server, republishes the data as a classical OPC DA 3.0 server, and is then consumed by V7.3 over COM/DCOM. Common gateways include:

  • Siemens SIMATIC NET OPC UA Gateway component
  • Third-party products such as TOP Server with the OPC UA driver option, which can act as a UA client and a DA server simultaneously (see Communicating with a Simatic HMI Comfort Panel via OPC UA).
  • Cogent DataHub or similar industrial middleware.

The gateway approach adds a Windows host to the topology, additional licensing, and another DCOM configuration surface. DCOM must be configured on every machine in the chain (HMI, gateway, bridge station) with matching Windows accounts and ACLs.

5.2 Option B — Use the HMI's Own OPC DA Server (If Available)

The TP1500 Comfort, in addition to its OPC UA server, exposes an OPC DA server under the SIMATIC HMI station. The HMI acts as a DA server through the OPC server on the HMI device functionality described in the TIA Portal Help under Using OPC in WinCC (Panels, Comfort Panels, RT Advanced). With this enabled, the V7.3 bridge can connect directly without any UA stack. Verify in the HMI's OPC settings in TIA Portal that both the OPC DA server and OPC UA server are activated. The DA ProgID will be of the form OPC.SIMATIC.HMI.TP1500.

5.3 Option C — Replace WinCC IDB with a Native UA Consumer

If a different concentrator is acceptable, modern alternatives such as Siemens Industrial Edge, Node-RED with the OPC UA nodes, or a custom .NET application using the OPC Foundation .NET Standard stack can subscribe directly to the TP1500 OPC UA server. The data is then forwarded to any sink (SQL, MQTT, file) without a UA-to-DA bridge. This option requires rewriting the V7.3 connection definitions but eliminates the V7.3 limitation entirely.

6. Upgrade Path to WinCC IDB V7.5 / V7.5 SP1

The recommended resolution for production deployments is to upgrade WinCC IDB to V7.5 or later. The order numbers and licensing details are listed in the official Siemens support article SIMATIC WinCC IndustrialDataBridge V7.5 — Delivery Release and Order Numbers. Key facts:

  • V7.5 is delivered as a single installer for both 32-bit and 64-bit Windows stations.
  • The license model uses a base license plus optional client tags or connections as needed.
  • A migration tool reads V7.3 connection definitions (.xml project files) and ports them to V7.5 with no data loss for OPC DA, SQL, CSV, and socket connections.
  • OPC UA provider configuration is added to the wizard under the same Provider dropdown that previously only listed DA servers.
  • No trial version is published for V7.5. The product must be ordered through Siemens sales channels or a regional distributor.

6.1 Compatibility Check Before Upgrading

Component Required Notes
Windows Windows 10 IoT Enterprise LTSC 2019 or Windows Server 2016 / 2019 32-bit and 64-bit supported
WinCC RT V7.4 SP1 or V7.5 for co-installed WinCC RT Not required if IDB runs standalone
OPC Core Components V7.5 ships its own; remove older 3.00 if present Mixing core components versions is unsupported
.NET .NET Framework 4.7.2 or higher Preinstalled on supported Windows builds
Existing V7.3 projects Export via Configuration > Export > XML Re-import on V7.5 station

7. Configuring the TP1500 Comfort OPC UA Server

Before any UA bridge — whether V7.5 or a custom consumer — can connect, the TP1500 Comfort must have its OPC UA server enabled and configured correctly. The setup is done in TIA Portal under HMI > Properties > OPC UA Server.

7.1 Enable the OPC UA Server

  1. Open the TIA Portal project that contains the TP1500 Comfort device.
  2. Select the TP1500 in the project tree and open Properties > OPC UA Server.
  3. Check Activate OPC UA server.
  4. Set the Port. The default is 4870; keep it on a known value for firewall rules and bridge configuration.
  5. Choose the security policy. For lab/test deployments, None is acceptable; production deployments should select at least Basic128Rsa15 or Basic256Sha256 with Sign or SignAndEncrypt.
  6. Confirm the Server certificate is generated automatically on first start; export the certificate's thumbprint for the bridge's trust list.

7.2 Configure the Router and Reachability

The TP1500 Comfort's OPC UA server listens only on the PROFINET interface of the panel. To allow the bridge station to reach it, the Use router option in the HMI's OPC UA settings must be considered. This setting determines whether the panel routes OPC UA traffic through the configured default gateway or only listens on the local subnet. With Use router enabled, the HMI accepts OPC UA discovery (LDS) and connection requests from any reachable IP. With it disabled, only same-subnet clients can connect.

7.3 Define UA Tags and Permissions

  1. Under HMI Tags, mark each tag that should be exposed via UA with the Accessible via OPC UA checkbox.
  2. Configure read/write permissions. By default, every exposed tag is readable; writes require explicit enablement.
  3. Group related tags into logical folders (e.g., ProcessData, Alarms, Recipes) to make the namespace easier to browse from the bridge.
  4. Compile the HMI project and download to the TP1500. Restart the runtime to apply OPC UA settings.

7.4 Verify with OPC Scout V10

  1. On the bridge station, launch OPC Scout V10.
  2. Insert a new server by URL: opc.tcp://192.168.0.2:4870.
  3. Browse the namespace. Confirm all exposed HMI tags appear under the configured folder structure.
  4. Add a tag to a monitored items group, then verify its value updates in real time.

If the verification succeeds in OPC Scout V10, the UA server side of the integration is correct. Any failure to bridge from this point onward lies in the bridge software, not the HMI.

8. Commissioning the OPC UA Connection in WinCC IDB V7.5+

  1. Open WinCC IndustrialDataBridge Configuration on the V7.5+ station.
  2. Create a new connection. Under Provider, select OPC UA from the type dropdown.
  3. Enter the Endpoint URL: opc.tcp://192.168.0.2:4870.
  4. Select the Security policy and Message security mode to match the TP1500 configuration. If the TP1500 uses None, the bridge can run unencrypted; for production, choose matching Sign or SignAndEncrypt.
  5. Choose the user-token policy. The TP1500 supports anonymous and username/password. For a controlled deployment, configure a dedicated bridge user in the HMI's User administration and select Username/Password here.
  6. Browse the server's namespace or enter a Start node ID to scope the browse.
  7. Select the tags to subscribe to and map each to a target field in the chosen Consumer (SQL database, CSV file, MQTT broker, etc.).
  8. Set the polling interval. UA subscriptions in V7.5 use the OPC UA subscription model with publishing intervals; 200 ms to 1 s is typical for HMI-sourced process values.
  9. Save, validate, and start the connection. Monitor the connection log for Bad_CommunicationError or Bad_SessionIDInvalid errors and remediate per Section 9 — Troubleshooting Matrix.

9. Troubleshooting Matrix

Symptom Likely Cause Diagnostic Resolution
V7.3 bridge does not list opc.tcp:// servers V7.3 provider stack has no UA support Check Help > About; confirm version Upgrade to V7.5+ or use a UA-to-DA gateway
V7.5+ bridge returns Bad_CommunicationError on connect TCP port 4870 blocked, HMI not in same subnet, firewall Test-NetConnection from bridge station Open firewall, enable Use router on HMI
V7.5+ bridge returns Bad_SecurityChecksFailed Security policy mismatch between HMI and bridge Compare HMI security policy with bridge configuration Align both to the same policy; regenerate certificates if needed
Bridge connects but tag values remain Bad_WaitingForInitialData HMI tag not marked Accessible via OPC UA, or the node ID is wrong Browse with OPC Scout V10; verify node exists Enable Accessible via OPC UA in TIA Portal; re-compile and re-download HMI
Bridge can read tags but writes return Bad_UserAccessDenied HMI tag is configured read-only Inspect tag's OPC UA read/write settings in TIA Portal Enable write access for tags that need to be set from the bridge
Connection drops after a few minutes with Bad_SessionTimeout Bridge session keep-alive interval too long Check V7.5 connection diagnostics for session timeout value Reduce session timeout; verify network stability; check for switch port suspension
OPC Scout V10 works but bridge does not Bridge is a different Windows user than the one that trusts the HMI certificate Check the bridge service account's certificate store Import HMI certificate into the bridge's Trusted People store

10. Field-Proven Best Practices

  1. Pin the HMI firmware version. A TP1500 Comfort configured with runtime image V14.0.1 should be re-deployed with that exact image; downgrading or upgrading mid-project changes UA namespace IDs in some cases.
  2. Use a dedicated user for the bridge. Create a bridge-specific user on the TP1500's user administration rather than using the default administrator. Restrict the user to read-only on process tags and read/write only on the recipe tags that legitimately need to be set from IT.
  3. Document the namespace. Export the TP1500 UA namespace from OPC Scout V10 to XML on every project handoff. Hand this to the IT customer alongside the bridge connection definitions.
  4. Version the bridge configuration. Save the V7.5 connection definitions under source control. Bridge logic that maps HMI tags to SQL columns should be reviewable like any other application code.
  5. Plan the upgrade window. The migration from V7.3 to V7.5 requires a re-install and a project re-import. Schedule the cutover with the IT customer to avoid data gaps.
  6. Validate end-to-end before go-live. Use a temporary SQL consumer that logs every polled value to a side table. Compare against the HMI's own tag log over a 24-hour soak test to confirm sample-by-sample parity.
  7. Lock down the OPC UA endpoint. In production, disable None security policy on the TP1500 and require at minimum Basic128Rsa15. The bridge station must trust the HMI's self-signed certificate (or a CA-signed one if your facility uses a PKI).
  8. Monitor the connection. V7.5+ writes connection state to a local log and to the Windows Event Log under source WinCC IndustrialDataBridge. Forward these events to a central syslog or SCADA alarm viewer.

11. Frequently Asked Questions

Can WinCC IDB V7.3 connect to an OPC UA server at all?

No. WinCC IndustrialDataBridge V7.3 supports only OPC Data Access (DA) over COM/DCOM as an external provider. There is no OPC UA provider in the V7.3 build, and the URL scheme opc.tcp:// is not recognized by the V7.3 provider framework. The first version with native OPC UA support is V7.5.

How do I confirm which WinCC IDB version is installed?

Open the IndustrialDataBridge Configuration tool and choose Help > About. The version string must show V7.5 or higher for OPC UA support. You can also inspect HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall in the registry for a product key containing WinCC IndustrialDataBridge and read its DisplayVersion value.

Is there a trial version of WinCC IDB V7.5 available for download?

No. Siemens does not publish a trial or evaluation installer for WinCC IndustrialDataBridge V7.5. The product must be ordered through Siemens sales or a regional distributor. The order numbers and licensing options are documented under SIMATIC WinCC IndustrialDataBridge V7.5 — Delivery Release and Order Numbers.

What is the default OPC UA port on a SIMATIC TP1500 Comfort?

The default TCP port for the OPC UA server on TP1500 Comfort (and the broader Comfort Panel family) is 4870. The full default endpoint URL is opc.tcp://<HMI_IP>:4870. The port can be changed in TIA Portal under the HMI's OPC UA server properties; any change must be reflected in every client configuration, including the bridge, OPC Scout, and any third-party consumer.

Can I keep WinCC IDB V7.3 and use a UA-to-DA gateway instead?

Yes. A UA-to-DA gateway (such as SIMATIC NET OPC UA Gateway, TOP Server with the OPC UA driver option, or a similar industrial middleware) can subscribe to the TP1500 OPC UA server and republish the data as a classical OPC DA 3.0 server on a Windows host. V7.3 then bridges from this DA server to your SQL, CSV, or socket consumer as normal. The trade-off is an additional Windows host, an extra license, and DCOM configuration on every machine in the chain.

Does the TP1500 Comfort also expose an OPC DA server alongside OPC UA?

Yes. SIMATIC Comfort Panels support both OPC DA and OPC UA server roles. The DA server can be enabled in TIA Portal under HMI > Properties > OPC Settings. When enabled, the HMI registers a ProgID of the form OPC.SIMATIC.HMI.<Device>, which WinCC IDB V7.3 can consume directly. This avoids the OPC UA limitation entirely when an OPC DA path is acceptable for the project's data flow.

Which OPC UA security policies should I use in production?

For production deployments, configure the TP1500 with at least Basic128Rsa15 — Sign or stronger, and align the bridge configuration to the same policy and message security mode. Disable the None policy on the HMI once commissioning is complete. The HMI's self-signed certificate must be imported into the bridge station's Trusted People certificate store, or replaced with a certificate issued by your facility's PKI.

Back to blog