Configuring cMT-SVR100 Remote Access to Siemens PLCs

David Krause6 min read
Industrial NetworkingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Remote engineering access reaches both the Siemens PLC and the SIMATIC KTP700 after the cMT-SVR100 establishes its 4G connection, joins the local Ethernet network, and exposes the selected device through EasyAccess PassThrough. Use the cMT-SVR100 with a compatible USB 4G dongle for this commissioning path. The supplied configuration does not establish the cMT-G01 as an equivalent substitute.

Remote-access architecture

The cellular connection may not provide a public address that accepts unsolicited inbound traffic. Direct port forwarding therefore depends on a network condition that the Iliad connection may not supply. EasyAccess removes that dependency by creating a VPN between the remote computer and the cMT-SVR100.

The term here means:

Term Function Commissioning decision
VPN Creates a logical private path across the Internet. Use EasyAccess instead of relying on inbound cellular connections.
PassThrough Presents one Ethernet device behind the cMT unit to the remote computer. Select the PLC or KTP700 address required for the current task.
Public IP address Allows an Internet host to receive connections directly when routing and firewall rules permit them. Do not make it a prerequisite for this design.

Check 1: expect the design to contain four functional blocks: the remote computer, EasyAccess, the 4G-connected cMT-SVR100, and the local Ethernet devices.

Local Ethernet addressing

The cMT-SVR100, Siemens PLC, and SIMATIC KTP700 must be reachable through the same routed Ethernet environment. PassThrough cannot correct duplicate addresses, incompatible subnet settings, a disconnected cable, or a target that is already unreachable from the cMT side.

  1. Record the current IP address and subnet mask of the PLC.
  2. Record the current IP address and subnet mask of the KTP700.
  3. Assign the Ethernet interface of the cMT-SVR100 an unused address that can communicate with both targets.
  4. Connect the PLC, KTP700, and cMT unit through the plant Ethernet network.
  5. Check for duplicate-address warnings and confirm that each device retains its intended address after power-up.

Keep the machine network separate from the cellular-facing interface at the addressing level. An address selected for the cMT Ethernet side must not duplicate the PLC, panel, router, or another automation device.

Check 2: expect the cMT-SVR100 to reach both recorded target addresses locally. If one target fails while the other responds, repair that target's addressing, cabling, switch port, or device state before configuring remote access.

USB 4G connection

Install a USB 4G dongle that is compatible with the cMT-SVR100, then use the Iliad SIM as the Internet path. The exact dongle model, SIM settings, and cellular parameters must come from the applicable cMT compatibility information and the active SIM configuration; no dongle model or parameter values are specified here.

  1. Activate the SIM and confirm that its service includes cellular data.
  2. Install the SIM in the compatible USB 4G dongle.
  3. Connect the dongle to the cMT-SVR100.
  4. Apply the carrier settings required by the SIM.
  5. Wait for cellular registration and confirm that the cMT unit has Internet connectivity.

Signal registration alone does not prove Internet access. The modem can attach to the cellular network while DNS, routing, authentication, or the data subscription remains unusable. Test the complete outbound path needed by the remote-access service.

Check 3: expect the 4G interface to show an active data connection and the cMT-SVR100 to establish outbound Internet communication. Stop here if the modem only reports cellular registration without data transfer.

EasyAccess enrollment and VPN connection

EasyAccess is required for the recommended architecture because it forms the VPN even when the SIM does not expose a usable public inbound address. Complete the product enrollment and activation steps presented by the EasyAccess configuration tools, then associate the cMT unit with the remote-access account used by the engineering computer.

  1. Enable and configure EasyAccess for the cMT-SVR100.
  2. Associate the unit with the authorized remote-access account.
  3. Install or open the corresponding EasyAccess client on the engineering computer.
  4. Sign in and select the commissioned cMT unit.
  5. Start the VPN connection.

Do not expose PLC or HMI engineering ports directly to the cellular network as a workaround. That method still depends on public addressing and inbound routing, and it bypasses the VPN path selected for this installation.

Check 4: expect the remote client to identify the correct cMT-SVR100 and report an active VPN session. A locally reachable PLC does not satisfy this check; the session must be established from the remote computer through the 4G path.

PassThrough target selection

PassThrough maps a selected Ethernet target into the remote computer's network path as though that computer were connected to the machine network. Enter the IP address of the device required for the current engineering task.

Required task PassThrough target Expected result
PLC diagnostics or programming Siemens PLC IP address The engineering computer reaches the PLC through the VPN.
Operator-panel access SIMATIC KTP700 IP address The engineering computer reaches the panel through the VPN.
Access to another Ethernet device That device's reachable IP address The selected host becomes reachable through the cMT path.
  1. Open PassThrough after the EasyAccess VPN reports connected.
  2. Enter the recorded PLC address for the first test.
  3. Start the PassThrough connection and perform a non-destructive online identification or diagnostic check.
  4. Disconnect or change the PassThrough target to the recorded KTP700 address.
  5. Repeat the online identification or diagnostic check for the panel.

Changing the target IP selects a different device; it does not change the actual IP configuration stored in the PLC or panel. Do not edit a device address merely to alternate between targets.

Check 5: expect the selected device to respond and the unselected target to remain outside that specific PassThrough mapping. If neither responds, recheck the VPN and cMT Ethernet path. If only one fails, troubleshoot that device's local network path.

End-to-end commissioning verification

  1. Cellular-path check: disconnect the engineering computer from the machine LAN and use an independent Internet connection. Expect the EasyAccess client to connect to the correct cMT-SVR100.
  2. PLC check: select the Siemens PLC address in PassThrough. Expect the engineering software to identify or diagnose the intended PLC without changing its stored IP address.
  3. Panel check: change the PassThrough target to the SIMATIC KTP700 address. Expect the panel to respond through the same VPN session.
  4. Isolation check: stop PassThrough and then stop the EasyAccess VPN. Expect remote access to the machine devices to cease.
  5. Recovery check: restore the VPN and reselect one recorded target. Expect communications to recover without modifying the PLC, panel, or cMT Ethernet addresses.

FAQ

What happens if the Iliad SIM has no public IP address?

Direct inbound access and ordinary port forwarding cannot be treated as the access method. Use EasyAccess to establish the VPN from the cMT-SVR100 across the cellular connection.

What happens if I use cMT-G01 instead of cMT-SVR100?

This commissioning path specifies the cMT-SVR100 with a compatible USB 4G dongle. Select a cMT-G01 only after confirming that its documented cellular, EasyAccess, and PassThrough functions satisfy the same architecture.

What happens if PassThrough connects but the PLC does not respond?

Verify that the selected address is the PLC's actual address and that the cMT-SVR100 can reach it locally. Then check for duplicate IP addresses, subnet mismatch, cabling faults, switch-port faults, and a stopped or unpowered target.

How do I verify remote access to both Siemens devices?

From an Internet connection outside the machine LAN, establish the EasyAccess VPN, target the PLC address in PassThrough, verify PLC identification, change the target to the KTP700 address, and verify panel identification.

Back to blog