Logging an S7‑1500 over OPC UA

Switching on the CPU's OPC UA server, getting certificates and users right, the limits by CPU and firmware, and what the common error codes mean.

The Siemens S7-1500 has an OPC UA server built into the CPU, which makes it one of the easiest controllers to log from without extra hardware. Most of the time spent getting it working goes on four things: the runtime licence, which variables are visible, user sign-in, and certificates. This guide covers each, then the limits that matter for a historian and the error codes you are likely to see.

Menu names are from TIA Portal V18 to V20 with CPU firmware V2.9 to V3.1. Siemens moves things between versions, so if a menu is not where we say, look nearby.

Use a bench PLC or a test project first. Switching on the OPC UA server and trusting a new client are configuration changes downloaded to the CPU, and a download can put the CPU into STOP. A new client also adds communication load.

1. Switch on the server

In the CPU's properties, go to General → OPC UA → Server → General and tick Activate OPC UA server. Note the server addresses shown there, one opc.tcp://<address>:4840 per interface. The logging PC must reach one of them on TCP port 4840.

Leave Enable standard SIMATIC server interface ticked. That is the interface that exposes data blocks and tags to clients, and it is what a historian browses.

2. Check the runtime licence

The OPC UA server needs a runtime licence sized to the CPU:

CPU Licence
CPU 1511, 1512, 1513 and ET 200SP CPUs SIMATIC OPC UA S7-1500 Small
CPU 1515, 1516 Medium
CPU 1517, 1518 Large

Set the purchased type under Runtime licenses → OPC UA in the CPU's properties. When a server looks correctly configured but will not behave, a missing or undersized licence is the first thing to rule out.

3. Make the variables visible

Only variables marked for HMI and OPC UA appear in the server. In each data block, and in the PLC tag table if you want I/O or memory, tick Accessible from HMI/OPC UA for every variable you want to log. A historian only reads, so leave Writable from HMI/OPC UA unticked.

The variables appear to clients under Objects → the CPU's name, with data blocks in DataBlocksGlobal. Node IDs look like this:

nsu=http://www.siemens.com/simatic-s7-opcua;s="DB_Process"."Tank1_Level"

A client that stores the namespace URI (nsu=) rather than the namespace number (ns=3) keeps working if the server renumbers its namespaces after a change.

4. Choose the security

Under OPC UA → Server → Security → Secure channel, make sure the CPU has a server certificate (TIA Portal creates one when you activate the server) and tick Basic256Sha256 – Sign & Encrypt in the available security policies. Newer firmware also offers Aes128Sha256RsaOaep and Aes256Sha256RsaPss.

Untick No security unless you are deliberately testing an unencrypted connection on an isolated bench.

5. Create a user

How you add a user depends on firmware.

  • V3.1 and later (TIA Portal V19 onwards): OPC UA users live in the project's user management. Under Security settings → Users and roles, create a role with the OPC UA server access runtime right for this CPU, then a user with a password and that role. Anonymous access is off by default; leave it off.
  • Before V3.1: in the CPU's properties under OPC UA → Server → Security → User authentication, untick guest access, enable user name and password authentication, and add the user there.

6. Trust the client's certificate

With Sign & Encrypt, the CPU must trust the historian's certificate.

  1. Export the client certificate from your historian (a .der file; rename it .cer if the TIA Portal file dialog does not show it).
  2. Import it in the project's certificate manager under Trusted certificates and root certification authorities.
  3. In the CPU's properties under Secure channel → Trusted clients, add the imported certificate.

There is also an option to accept client certificates automatically at runtime. It is convenient during commissioning; switch it off and download again once the historian is connected, or any client can connect.

Trust works in the other direction too: the historian must trust the CPU's certificate. Check the thumbprint matches what TIA Portal shows before accepting it.

7. Download, then connect

Compile and download the hardware and software changes. Then point the historian at opc.tcp://<plc-ip>:4840, choose Sign & Encrypt with the strongest policy offered, enter the user and test the connection.

Make sure the CPU's clock is right before you start. Certificates carry a validity period, and a CPU whose clock is behind will reject a brand-new client certificate as not yet valid.

The limits that matter for logging

Siemens publishes OPC UA limits per CPU class and firmware in entry 109755846 (V1.0, 02/2024). The recommended maximum number of monitored items is the one that most often surprises people:

Firmware CPU Sessions Subscriptions per session Fastest sampling Monitored items (recommended max)
V3.0, V3.1 1511, 1512, 1513 32 50 100 ms 4,000
V3.0, V3.1 1515, 1516 48 50 100 ms 4,000
V3.0, V3.1 1517, 1518 64 50 10 ms 24,000
V2.8, V2.9 1511, 1512, 1513 32 20 100 ms 1,000
V2.8, V2.9 1515, 1516 48 20 100 ms 2,000
V2.8, V2.9 1517, 1518 64 20 10 ms 10,000

These are recommendations under load rather than hard stops, but a site controller logging 3,000 signals on a CPU 1513 at firmware V2.9 is outside them. A historian should report how many items the CPU actually accepted rather than failing silently.

Error codes you will meet

BadSecurityChecksFailed. The CPU refused the secure channel. Almost always the client's certificate is not in Trusted clients yet, or was imported but not downloaded. Also check both clocks.

BadCertificateUntrusted. One side does not trust the other. At the first connection it is usually the client not yet trusting the CPU; after that, the CPU not trusting the client.

BadCertificateHostNameInvalid. The CPU's certificate does not name the address you typed. Use an address the certificate lists, or regenerate the server certificate after changing the CPU's IP address, and download.

BadUserAccessDenied or BadIdentityTokenRejected. Check the user and password, that the role has OPC UA server access on this CPU, and that you downloaded after adding the user.

BadTooManySessions. Other clients are holding sessions. A client that was killed rather than closed keeps its session until it times out.

BadTooManyMonitoredItems. Log fewer signals, check the licence size, and compare with the limits above.

Doing this with Vault

Vault's connection wizard follows these steps: it discovers what the CPU offers, picks the strongest Sign & Encrypt policy, trusts the CPU's certificate in one click, gives you its own certificate to import, stores the password encrypted by Windows and translates each error code into the step to check. It ships with a full S7-1500 guide. See Vault's OPC UA support.

Sources

  • Siemens, TIA Portal OPC UA system limits for the S7-1500/S7-1200 CPUs, entry 109755846, V1.0, 02/2024.
  • Siemens, SIMATIC S7-1500 Communication function manual, "License for OPC UA".
  • Siemens TIA Portal information system, License for OPC UA (S7-1500, S7-1500T).
  • Siemens, User Management & Access Control with TIA Portal V19, entry 109973173.