Adding CP 343-1 to S7-300: Safe Installation & Configuration
The CP 343-1 communications processor extends a SIMATIC S7-300 system with industrial Ethernet capability and is the standard interface for HMI, SCADA, OPC, and peer-to-peer S7 communication. Adding the module to a running machine is a common maintenance scenario: an existing PLC must be networked for tag polling, and the engineer wants to confirm whether the rack can stay in production while the module is wired in. The answer for the S7-300 family is unambiguous: the central rack does not support hot-swap, and the CPU enforces its hardware configuration deterministically. Inserting a CP 343-1 in a slot that is empty in HW Config will, by default, take the CPU to STOP with a diagnostic buffer entry. This article documents the safe procedure for adding the module, the configuration steps in TIA Portal and STEP 7 V5.x, the network parameters, the protocol choices, and the field verification that proves a clean commissioning.
Overview of the S7-300 Ethernet Architecture
The CP 343-1 sits in the central rack as a slave on the S7-300 backplane bus. The CPU owns the bus and assigns parameter data to every populated slot using the system data blocks (SDB 0, SDB 1, SDB 2 and the module-specific SDBs in the 1000-range). The CP is not a standalone device: it has no user program, no project file of its own, and no IP configuration stored locally. Every byte of its configuration—IP address, subnet mask, connection table, port mode—is held in the CPU's load memory and pushed to the CP on every restart. This is the root cause of the STOP-on-mismatch behaviour: the CPU cannot push parameters to a module that it has not been told exists.
The CP 343-1 family spans four order numbers relevant to a typical S7-300 application:
- 6GK7343-1EX30-0XE0 — CP 343-1, full version with two RJ45 ports fed by an internal switch, 16 connection resources, ISO-on-TCP, TCP, UDP, S7 communication, and limited PROFINET IO controller capability.
- 6GK7343-1CX10-0XE0 — CP 343-1 Lean, single port, 8 connection resources, ISO-on-TCP, TCP, UDP, S7 communication, no PROFINET controller.
- 6GK7343-1GX30-0XE0 — CP 343-1 ERPC, for redundant S7-400H coupling over Industrial Ethernet.
- 6GK7343-1HX00-0XE0 — CP 343-1 PN, with PROFINET IO controller and device capability.
For tag polling from an HMI, SCADA, or third-party OPC server, the Lean variant is the most cost-effective choice and is fully supported on every S7-300 CPU from the 312 firmware V2.0 onwards. The full CP 343-1 adds an internal switch and a second connection resource pool, which is required only if the network design includes ring redundancy (MRP) or a large number of concurrent connections.
Prerequisites and Required Components
Before powering down the rack, verify that every item below is on hand. A missing MMC write-protect tab or the wrong HSP installed in TIA Portal is the single most common cause of a stuck commissioning.
| Item | Specification / Part Number | Notes |
|---|---|---|
| CP 343-1 (full) | 6GK7343-1EX30-0XE0 | Two ports, internal switch |
| CP 343-1 Lean | 6GK7343-1CX10-0XE0 | Single port |
| Bus connector | Pre-installed on CP | Verify it is intact and the plastic frame is not cracked |
| Free slot in central rack | Slot 4–11 | Slot 3 reserved for IM in distributed I/O configurations |
| Engineering software | TIA Portal V16+ or STEP 7 V5.6+ | HSP for CP 343-1 must be installed |
| SIMATIC MMC | 6ES7953-1LF00-0AA0 (2 MB) or larger | Required for CPU 31xC and 31x-2 |
| Ethernet cable | Cat 5e or higher, RJ45 | Cross-over not required for any CP 343-1 variant |
| Engineering station | Laptop with TIA Portal / STEP 7 | Static IP on the same subnet as the planned CP IP |
| Anti-static wrist strap | — | Mandatory when handling the module |
| Documentation of the existing project | Offline project, SDB upload, S7 program | Mandatory for rollback |
S7-300 CPU Behaviour on Configuration Mismatch
The S7-300 family treats hardware configuration as a hard constraint. On every restart—cold restart, warm restart, or hot restart—the CPU enumerates the modules present in the backplane and compares the detected set to the configuration table stored in the system data area. When a CP 343-1 is physically present in a slot that is empty in HW Config, the CPU experiences a parameter assignment error on the slot and reacts as follows by default.
| Trigger | CPU State | LED Indication | Diagnostic Buffer Entry |
|---|---|---|---|
| Slot populated, not in HW Config | STOP | SF (CPU) and SF (CP) red | "Module does not exist" / cause 0x0010 |
| Slot populated, wrong order code in HW Config | STOP | SF (CPU) and SF (CP) red | "Parameter assignment error" / cause 0x0001 |
| Slot populated, correct HW Config, SDBs not downloaded | STOP after timeout (default 650 ms per module) | SF (CPU) and SF (CP) red | "Startup not completed within monitoring time" |
| Slot empty, listed in HW Config | STOP (default) | SF (CPU) red | "Module removed" / cause 0x0003 |
| CP firmware mismatch with SDB | STOP | SF (CPU) and SF (CP) red | "Firmware version incompatible" / cause 0x000E |
The default monitoring time for the parameter assignment phase is set in the CPU properties under Startup → Monitoring time for parameter assignment of modules in TIA Portal, or under CPU → Properties → Startup in STEP 7 V5.x. The factory default is 650 ms per module. For an S7-300 with 6 SMs and a newly added CP, expect roughly 4.5 seconds of additional startup time on a warm restart. Cold restarts take longer because the entire user program must be reloaded from the MMC.
The default STOP behaviour is deterministic and is not a defect. TIA Portal offers the option CPU properties → Startup → "Startup when expected configuration does not match actual configuration". Enabling this option allows the CPU to enter RUN with a warning if the configuration differs, but it is intended only for non-critical installations and is not recommended for safety-relevant applications. An unconfigured CP in this mode produces no diagnostic entries and is effectively invisible to the user program until the configuration is reconciled.
The S7-200 platform that many engineers have used before is more permissive. The S7-200 micro-PLCs do not enforce a fixed slot map against HW Config in the same way, and an unconfigured module is reported in the I/O error LED rather than bringing the CPU down. The S7-300 does not have that forgiveness. Plan on a controlled shutdown.
Pre-Installation: Backing Up the Existing Project
Before powering down, capture the current state of the PLC. Use TIA Portal with the project file, or STEP 7 V5.x with the offline/online project. The backup is mandatory: if the new HW Config is rejected by the CPU on first restart (for example, because an old CP 341 serial module's SDB is still in the project), the only fast recovery is to re-download the backup SDB set.
- Open the existing project in TIA Portal. Right-click the S7-300 station and select Online → Backup as online snapshot, or use Project → Card Reader/USB memory → Read device memory to dump the SIMATIC memory card contents to a folder on the engineering station.
- Export the HW Config: Station → Export station to a configuration file. Save the resulting .zap file alongside the project archive. The .zap file is a plain-text representation of the SDB set and is human-readable for troubleshooting.
- For STEP 7 V5.x, use PLC → Upload Station to PG with the option "Include SDBs" to mirror the operational system data to the engineering station. This is mandatory for matching the actual configured module set to the new project before modification. Without "Include SDBs", the upload contains only the user program blocks and the configuration table is empty.
- Note the CPU order number, firmware version, and the slot count currently used. The S7-300 supports up to 8 modules per central rack, with the CPU occupying slot 2 by default and slots 4–11 available for signal and communication modules.
- Verify the SDBs in the online project contain no surprising items: open the S7 program blocks and confirm no user-defined SDBs (for example, for CP 341 serial or FM 350 counters) are loaded. These must be re-engineered into the new HW Config to avoid a parameter conflict at next restart.
- Note the existing IP address space of the plant. Confirm the planned CP IP does not overlap with any device on the subnet. A duplicate IP is the most common post-commissioning fault that does not show up in the diagnostic buffer.
The goal of the backup is two-fold: (a) ensure the original commissioning can be restored if the CP 343-1 installation has to be rolled back, and (b) provide a known-good starting point to merge the CP 343-1 configuration into the offline project.
Physical Installation of the CP 343-1
With the rack powered down and the CPU in the OFF state, follow the sequence below. Inserting a module with the CPU in RUN causes arcing on the backplane bus connector pins, may corrupt the diagnostic buffer, and risks the CPU transitioning to STOP with a non-recoverable fault.
- Identify a free slot. Slot 4 is the conventional first I/O position; the CP can be placed in any free slot, but placing it in the highest-numbered free slot keeps wiring changes minimal and avoids renumbering the existing SMs in HW Config.
- Hook the CP onto the top DIN-rail notch and pivot the bottom into the bus connector at the back of the rack. The bus connector ships pre-installed on CP 343-1 modules. If the slot previously held an SM, ensure the bus connector of that SM is removed first: slide it horizontally out of the rear of the rack and store it on the new CP.
- Screw the module down at the top and bottom captive screws. Torque to 0.8–1.0 N·m to ensure the bus connector seats fully against the backplane. An undertightened module can cause intermittent bus faults that are difficult to reproduce.
- Insert the SIMATIC memory card (MMC) into the CPU before applying power, if the CPU is a 31xC or 31x-2 DP/PN model. The CP 343-1 configuration is stored in SDBs on the MMC, not on the CP itself. Without the MMC, the CPU will not retain the configuration across a power cycle.
- Apply 24 V to the rack. The CPU performs a cold restart. The CP 343-1 boots and illuminates the SF LED red, since HW Config has not yet been updated. The LINK LED remains off because no Ethernet cable is connected.
Do not connect the Ethernet cable to the CP at this point. The CP will not pass any frames, but having an active link during a configuration mismatch occasionally confuses commissioning software when the CP's MAC is interrogated by a network scan. Hold the cable until the SF LED is cleared by the SDB download.
Hardware Configuration in TIA Portal
Use TIA Portal V16 or later for the most up-to-date HSP support. The Hardware Support Package for the CP 343-1 modules is shipped with TIA Portal from V14 onwards. If the catalog entry for the new order number is missing, install the HSP via Options → Support Packages → Install Hardware Support Package.
- Open the project, navigate to Devices & Networks, and select the S7-300 station.
- In the device view, identify the empty slot where the CP will be placed. Empty slots are shown as greyed rectangles. Click the slot to select it.
- From the Hardware catalog on the right, expand PLC → SIMATIC S7-300 → Communication modules → CP 343-1. Drag the correct order number to the slot. TIA Portal automatically matches the firmware version of the CP to the project's HSP. If a firmware conflict warning appears, accept the firmware upgrade and re-download the SDBs after the hardware download.
- Open the CP's properties panel. Under Ethernet addresses, set the IP address, subnet mask, and (if used) router address. Example for a typical plant network:
IP address: 192.168.10.50 Subnet mask: 255.255.255.0 Use router: No - Under Connection mechanisms, enable "Permit S7 communication" and "Permit PG communication". For Lean variants, also enable "Permit PUT/GET" if the SCADA server uses PUT/GET blocks rather than S7 connections.
- Add an Ethernet subnet object: right-click the CP port in the device view, choose Add subnet, or use Ethernet addresses → New. Attach the engineering station's PG/PC interface to the same subnet so the project can reach the CP for online access.
- Configure connection resources. In the CP's properties, open Connection resources and verify the planned connections fit within the resource count. The full CP supports 16; the Lean supports 8. Each HMI, OPC server, and S7 partner consumes one resource.
- Compile the hardware configuration: Station → Compile and download to device. The project is recompiled to system data blocks and downloaded to the CPU. The CPU must be in STOP, or be in RUN with the "Download in RUN" permission enabled for the affected SDB group.
- For a green-field CP, also click Online → Download to device on the CP node to push any CP-specific firmware updates. The CP's firmware is held in the CPU's load memory and pushed to the CP on every restart, so an out-of-date CP firmware does not require a separate download.
The download rewrites SDBs in the CPU's load memory. The CPU performs a reinitialisation of the CP, after which the SF LED on the CP extinguishes and the LINK LED on the active Ethernet port lights green. If the CPU was in STOP before the download, it will not automatically return to RUN. Move the mode selector to RUN or issue an Online → Run command from the engineering software.
Hardware Configuration in STEP 7 V5.x (Classic)
For installations that have not been migrated to TIA Portal, the procedure is similar but uses the classic HW Config tool. STEP 7 V5.6 is the last release for the S7-300 and is still under maintenance until 2027. Projects can be migrated to TIA Portal at any point, but the field procedure below is the standard for an active brown-field installation.
- Open SIMATIC Manager and load the offline project.
- Double-click Hardware to open HW Config.
- From the catalog on the right, locate SIMATIC 300 → CP 300 → Industrial Ethernet → CP 343-1. The catalog entry uses the order number 6GK7 343-1EX30-0XE0. Drag the module to the empty slot.
- Double-click the CP to open its properties dialog. In the General tab, click Ethernet Interface and set the IP address, subnet mask, and (if used) router address. Click New to create an Ethernet subnet object that the rest of the project can attach to.
- In the Options tab, enable the required communication channels: S7 Communication, PG Communication, PG/OP Communication, and for the Lean module, PUT/GET.
- In the Time-of-day synchronisation tab, configure NTP servers if plant time sync is required. The CP supports up to four NTP servers with a 10-second synchronisation interval by default.
- Save and compile: Station → Save and Compile. The resulting system data is stored as SDBs in the offline project.
- Download to the target device: PLC → Download. Confirm the prompt to overwrite the existing SDBs. The download typically takes 10–30 seconds for a 6-slot configuration with one CP.
The download to a CPU in RUN is only possible if the SDBs to be replaced do not require a STOP transition. Communication-related SDBs (those generated by the CP's properties dialog) are typically downloaded in RUN without disturbing the user program execution, but the CPU display will indicate "Download in RUN" for a few seconds. The user program scan time is briefly extended by the SDB processing load.
Network Parameter Configuration
The CP 343-1 supports both static IP and DHCP. The factory default is static IP 0.0.0.0 with no operational mode selected, which means the CP will not communicate until configured. The default MAC address is vendor-assigned and printed on the module housing; the first three octets are the Siemens OUI 00:0E:8C.
| Parameter | Default | Typical Value | Notes |
|---|---|---|---|
| IP address | 0.0.0.0 | 192.168.10.50 | Must be unique on the subnet |
| Subnet mask | 0.0.0.0 | 255.255.255.0 | Match subnet of engineering station and target devices |
| Router address | 0.0.0.0 | 192.168.10.1 | Required only if CP communicates across a router |
| MAC address | Vendor assigned | 00:0E:8C:xx:xx:xx | Read-only; printed on housing |
| Port 1 / Port 2 mode (full CP) | Auto-negotiate | Auto-negotiate | Both ports share same IP; internal switch fabric |
| Connection resources | 16 max (full) / 8 max (Lean) | 6–8 typical | Sum of all configured S7 / TCP / UDP connections |
| Keep-alive timeout | 30 s | 30 s | For S7 connections |
| Connection establishment | Active or Passive | Project-dependent | Active = CP initiates; Passive = CP accepts |
| Port 102 (ISO-on-TCP) | Enabled | Enabled | Standard port for S7 communication |
The full CP 343-1 (6GK7 343-1EX30-0XE0) has two RJ45 ports fed by an internal managed switch. The Lean variant has a single port. If the network design uses a ring, both ports of the full CP can be activated with MRP (Media Redundancy Protocol) roles, with one port as MRP client and the other as MRP manager. The Lean does not support MRP redundancy and must be connected to a ring through an external managed switch.
Communication Protocol Selection
After the CP is operational, choose a transport for the application data. The CP 343-1 supports four protocol families, each with different properties. The protocol choice depends on the partner device: a Siemens HMI panel uses S7 connections natively, while a third-party SCADA package typically uses ISO-on-TCP with the LibNoDave or Snap7 library.
| Protocol | Layer | Configured In | Typical Use | Header Overhead |
|---|---|---|---|---|
| S7 Communication (S7 Conn) | Application, Siemens proprietary | NetPro / TIA "Connections" | HMI, S7-to-S7, OPC Scout | 12 bytes per PDU |
| ISO-on-TCP (RFC 1006) | Transport, port 102 | NetPro / TIA "Connections" | Open PLC-to-PLC, third-party SCADA | 4 bytes TSAP + ISO header |
| TCP native (socket) | Transport, configurable port | TIA "Open user communication" / TCON, TSEND, TRCV | Custom integrations, MQTT, REST gateways | 20-byte TCP header |
| UDP native (datagram) | Transport, configurable port | TIA "Open user communication" / TCON, TSEND, TRCV | Broadcast, low-overhead polling | 8-byte UDP header |
For a typical "read some tags online" requirement, the S7 connection or ISO-on-TCP is the simplest path. S7 connections are configured declaratively in NetPro or in the TIA Portal Connections editor; the CP handles all PDU assembly. The right-click procedure on the PLC CPU in TIA Portal is: Connections → Add new connection, choose S7 connection or ISO-on-TCP, specify the partner IP, and assign a local connection ID. The CP automatically handles the connection establishment and reconnection on link loss.
ISO-on-TCP requires the application to use the SEND/RECEIVE (S/R) interface in STEP 7 or the native TCON/TSEND/TRCV blocks in TIA Portal. The TSAP (Transport Service Access Point) is a 4-byte identifier that the partner uses to address the connection; the local TSAP is typically padded with ASCII characters that match the slot number (for example, 03.01 for slot 3, submodule 1).
For a third-party HMI or SCADA that cannot speak the Siemens S7 protocol, ISO-on-TCP is the most universally supported option. The LibNoDave library, the Snap7 library, and most open-source PLC drivers can speak ISO-on-TCP with a 4-byte TSAP selector. The partner establishes a TCP connection to port 102 on the CP, sends an ISO-on-TP CR (Connection Request) TPDU containing the partner and local TSAP, and the CP accepts the connection once the TSAPs match its internal table.
Diagnostic LEDs and Buffer Entries
The CP 343-1 has five LEDs on the front bezel. Reading these is the fastest field diagnostic.
| LED | Colour | Meaning | Expected State |
|---|---|---|---|
| SF | Red | System fault: configuration mismatch, SDB error, hardware fault | Off in RUN with valid SDBs |
| BF | Red | Bus fault: link down, no Ethernet carrier, no IP negotiation | Off when cable connected and partner on same subnet |
| LINK (Port 1) | Green | Physical link up on port 1 | Solid green when cable connected |
| LINK (Port 2, full CP only) | Green | Physical link up on port 2 | Solid green when cable connected |
| RX/TX | Green / flashing | Receive / transmit activity | Flickers on traffic |
| MAINT | Yellow | Maintenance demand (PROFINET diagnostics) | Off in normal operation |
When the CPU detects a configuration mismatch, it logs an entry in the diagnostic buffer. The most common entries for a CP 343-1 installation are:
| Buffer Text (truncated) | Cause Code | Remedy |
|---|---|---|
| "Parameter assignment error module in slot X" | 0x0010 | Re-download HW Config with the CP inserted in the matching slot |
| "Module does not exist" | 0x0003 | Add the CP to HW Config or remove it from the rack |
| "Station failure" | 0x001E | Check the Ethernet cable and partner device |
| "Communication error" with detail "Connection aborted" | 0x0001 | Verify connection partner is online; check TSAP and IP |
| "Configuration in RUN inconsistent" | 0x0007 | Compile and re-download HW Config |
| "Time-of-day synchronisation error" | 0x000A | Reconfigure NTP or SIMATIC mode |
| "Firmware version incompatible" | 0x000E | Update HSP in TIA Portal or STEP 7 |
The buffer is viewed in TIA Portal under Online → Online & Diagnostics → Diagnostic Buffer or in STEP 7 V5.x under PLC → Diagnostic/Setting → Diagnostic Buffer. The first entry on cold start is the most recent; navigate backwards with the Previous button to find the mismatch event. The cause codes are documented in the CPU 31x manual available on the Siemens Industry Online Support portal under entry ID 13206798.
Commissioning Verification Checklist
After the SDB download and CPU restart, walk through the following checklist before handing the system back to production. Each step has a pass criterion; a single failure is enough to stop and investigate.
- CPU state. Confirm the CPU mode selector is in RUN and the RUN LED is solid green; the STOP LED must be off. The CPU display should show the operating mode (RUN) and not a fault code.
- CP 343-1 LEDs. SF off, BF off, LINK on at least one port, MAINT off. RX/TX may flash intermittently on broadcast traffic. The BF LED must be off within 30 seconds of the Ethernet cable being connected, once the partner device (switch, engineering station, HMI) is on the same subnet.
- Online connection. From TIA Portal or STEP 7, execute Online → Accessible Nodes. The CP 343-1's MAC address and configured IP must appear in the list within the broadcast timeout (typically 5 seconds for a directly-connected subnet).
-
Ping test. From a workstation on the same subnet, run
ping 192.168.10.50. A reply confirms the IP stack and ARP are functional. A time-out with a green LINK LED indicates an IP misconfiguration or a firewall on the workstation blocking ICMP echo. - S7 connection test. Use the CP's diagnostic page: Online → Online & Diagnostics → Diagnostics → Connection Statistics. Establish a test S7 connection from the engineering station. The state should transition from "Not connected" to "Established" within 2 seconds of the connection request.
- Tag read/write. Open a watch table in TIA Portal or a VAT in STEP 7. Monitor a real DB tag in the user program. The value must update live as the HMI or test client writes to it. For a S7 connection, the read cycle is configured at the partner and is typically 250 ms to 1 s.
- Diagnostic buffer. Confirm no new error entries appeared during the verification. A clean buffer post-commissioning is the strongest single sign that the installation is correct. Any buffer entry with a cause code in the 0x0001–0x001E range is an active fault requiring resolution before sign-off.
- Backup the new project. Archive the final project to a version-controlled location, and write a fresh backup of the SIMATIC MMC for the next maintenance window. The MMC content is the only source of truth for SDBs after a power cycle; the offline project is a copy.
If any of the checks fail, the most likely causes are: (a) the IP address overlaps with another device on the subnet, (b) a managed switch is filtering frames from an unknown MAC, (c) the connection resource is exhausted (visible in connection statistics), or (d) a firewall on the partner device is rejecting port 102 traffic. Address these one at a time; the diagnostic buffer will narrow the cause quickly. For a deeper investigation, the CP's web server can be enabled under Properties → Web diagnostics; it provides a browser-accessible diagnostic page at the configured IP on port 80.
FAQ
Will the S7-300 CPU go to STOP if I install a CP 343-1 before updating HW Config?
Yes, by default. The CPU detects the new module during the parameter assignment phase, finds no matching SDB, and transitions to STOP with the SF LED lit on both the CPU and the CP. The diagnostic buffer records an entry with cause code 0x0010 (parameter assignment error) or 0x0003 (module does not exist). Update HW Config in TIA Portal or STEP 7 V5.x, compile, and download the SDBs to clear the fault.
Is the CP 343-1 hot-swappable like ET 200S modules?
No. The S7-300 central rack does not support hot-swap of any module type, including the CP 343-1. The backplane bus connector relies on a clean power-down to avoid contact arcing and bus corruption. Always power down the rack (24 V OFF, CPU display blank) before inserting or removing a module. ET 200S and ET 200SP are hot-swappable because they use a different backplane design.
What is the difference between CP 343-1 and CP 343-1 Lean?
The CP 343-1 (6GK7343-1EX30-0XE0) has two RJ45 ports fed by an internal switch, supports 16 connection resources, ISO-on-TCP, TCP, UDP, S7 communication, MRP ring redundancy, and limited PROFINET IO controller. The CP 343-1 Lean (6GK7343-1CX10-0XE0) has a single port, 8 connection resources, no PROFINET controller, and no MRP. For HMI, SCADA, and OPC tag polling, the Lean is sufficient and is the most cost-effective choice.
How many S7 connections can a CP 343-1 handle simultaneously?
The full CP 343-1 supports up to 16 connections combined across S7, ISO-on-TCP, TCP, and UDP. The Lean variant supports 8. Each HMI panel, SCADA client, OPC server, and S7 partner consumes one connection resource. Verify the count in the CP's diagnostic buffer under Connection Statistics—the maximum concurrent active connections is shown alongside the configured and rejected counters.
Why does the SF LED stay lit on the CP 343-1 after I download HW Config?
Three common causes: (1) the SDB download did not include the CP's SDBs—re-run Compile and download to device with Replace all SDBs enabled; (2) the slot number in HW Config does not match the physical position of the module, in which case the CPU keeps the configuration error active; (3) the CP order number in HW Config differs from the actual module, for example, the project lists 6GK7343-1CX10-0XE0 but the installed module is 6GK7343-1EX30-0XE0. Check the diagnostic buffer for the specific cause code.