Configuring CP 343-1 v3.0 as a PROFINET IO Controller in STEP 7

David Krause11 min read
ProfibusSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Overview

The SIMATIC CP 343-1 communications processor connects an S7-300 station to Industrial Ethernet and can operate as a PROFINET IO controller, IO device, or standard S7 communication peer. The IO controller role is the most common deployment: a central S7-300 CPU with the CP 343-1 distributes PROFINET IO to distributed field devices (ET200S, ET200MP, ET200SP, drives, third-party PROFINET devices) over a single Industrial Ethernet line.

This guide resolves a frequent field issue: in CP 343-1 firmware v2.0, the PROFINET tab exposes a dedicated "IO controller" checkbox that reveals a PROFINET IO system directly beneath the PN-IO node. In firmware v3.0, that checkbox is intentionally hidden; the role is implied when the CP is not operated as an IO device, and the IO system is created manually under the PN-IO node. The configuration path differs subtly between the two firmware branches, and the wrong assumption ("the option is missing in v3.0") is the typical cause of failed commissioning.

Reference: CP 343-1 as PROFINET IO controller in STEP 7 Professional - Siemens Support (ID 109820745).

2. CP 343-1 Hardware and Firmware Branches

The CP 343-1 family spans several order numbers. Identify the exact module and firmware before configuration because the PROFINET role UI differs:

Order Number (MLFB) Designation Firmware Branch PROFINET Role UI
6GK7 343-1EX20-0XE0 CP 343-1 v1.x Classic IO controller tab
6GK7 343-1EX21-0XE0 CP 343-1 v2.x IO controller checkbox visible
6GK7 343-1EX30-0XE0 CP 343-1 Lean v3.x No role checkbox; role inferred from IO system insertion
6GK7 343-1CX00-0XE0 CP 343-1 Advanced v2.x / v3.x No role checkbox; role inferred from IO system insertion
6GK7 343-1GX20-0XE0 CP 343-1 IT v2.x No role checkbox (IT focus)
Field note: The Lean variant (6GK7 343-1EX30-0XE0) supports a smaller maximum number of PROFINET IO devices than the standard CP 343-1. Check the SIMATIC NET manual for the exact limit (typically 8 or 16 IO devices on Lean vs. 32 or 64 on the standard part) before sizing the topology.

Physical interface: a single 8P8C (RJ45) jack labelled X1 on the front, supporting 10/100 Mbps autonegotiation, full duplex, and PROFINET real-time (RT). IRT is not supported on CP 343-1; use CP 343-1 Advanced or an ET200S PROFINET interface for IRT applications.

3. Prerequisites

  1. Engineering tool: STEP 7 V5.5 SP4 or later, or STEP 7 Professional (TIA Portal) V14 SP1 or later, with the HSP (Hardware Support Package) for the CP 343-1 module installed. The v2.x and v3.x GSD/HSP files must match the firmware on the physical module.
  2. SIMATIC NET block library: The PNIO_SEND (FC11) and PNIO_RECV (FC12) blocks are supplied with the SIMATIC NET installation media for S7-300. The library is typically located at ...\Siemens\Automation\SIMATIC_NET\CP300\Library.
  3. Firmware version verified: Open HW Config, right-click the CP, select "Object Properties", navigate to the "Diagnostics" or "Identification" tab. Confirm the firmware matches the HSP selected in the catalog.
  4. IP plan: Reserve an IPv4 address for the CP (e.g., 192.168.0.10) and confirm it sits on the same subnet as the planned IO devices.
  5. Topology: PROFINET devices require a unique station name (device name) and an IP address. The CP 343-1 acts as the naming and IP server for the IO system.

4. Configuring the Interface and Subnet

  1. Open the S7 project in STEP 7 and double-click the CP 343-1 in HW Config.
  2. Select the Properties entry; the object properties dialog opens.
  3. Navigate to General > Interface. For the v3.x branch, this is the only place where PROFINET parameters are defined.
  4. Click New under "Subnet" to create an Industrial Ethernet subnet (e.g., "PN_IO"), or attach the CP to an existing subnet.
  5. Assign the CP's IP address (e.g., 192.168.0.10) and subnet mask (255.255.255.0).
  6. Optionally configure a router if the PROFINET network must reach another subnet. CP 343-1 supports a single default router entry.
  7. Click OK and save the hardware configuration. Run "Download to Target > PG/PC [Hardware Config]" once at this point so STEP 7 has the interface parameters committed, even though full PROFINET IO has not yet been built.

5. Creating the PROFINET IO System

This is the critical step that differs between v2.x and v3.x firmware:

  1. In the station window of HW Config, expand the CP 343-1. Locate the PN-IO subnode (sometimes labelled "PROFINET Interface" on the v3.x branch).
  2. Right-click the PN-IO subnode.
  3. Select Insert PROFINET IO System.
  4. The IO system is created and visually attached to the PN-IO node. A new entry "PROFINET-IO-System (1)" appears beneath the CP.
  5. If a dialog asks whether the CP should act as IO controller or IO device, choose IO controller. On the v3.x branch, this dialog is typically suppressed because the absence of an IO device assignment implies the controller role. To force the role, do not enable the "IO device" mode check in the PN-IO properties.
Why the v2.x checkbox is absent in v3.x: The v3.x firmware expects the IO system to be created first. The PROFINET role is then derived from the configuration: if the PN-IO node has no "I-device" checkbox set and at least one IO system attached, the module operates as an IO controller. This implicit-mode design reduces the chance of double-assignment (controller + device) that occasionally occurred on v2.x.

6. Port Configuration on X1

The v3.x CP 343-1 exposes the X1 port as a configurable PROFINET port. Most users do not change the defaults, but field sites with managed switches or specific cable diagnostics should verify:

  1. Right-click the CP 343-1 PN-IO node and select Object Properties > Port X1.
  2. Confirm Transmission medium/Duplex is set to Auto for typical deployments, or pin to 100 Mbps FD if the connected switch port is fixed.
  3. Disable End of detection of accessible devices only if you intend to operate the port with no end-of-line termination (daisy-chain topology with disabled port at the end node is not recommended).
  4. Optionally enable Port statistics and Cable diagnostics for commissioning diagnostics. The CP will then report per-port counters (discarded frames, CRC errors, link-down events) to the diagnostic buffer and to STEP 7 online diagnostics.
  5. Click OK to apply.

7. Adding PROFINET IO Devices

  1. With the PROFINET IO system selected, open the PROFINET IO catalog on the right side of HW Config.
  2. Drag an ET200S, ET200MP, ET200SP, or a third-party PROFINET device (GSD file) into the IO system.
  3. For each device, double-click the device and assign a unique PROFINET device name (e.g., et200sp_1), IP address, and device number.
  4. Configure the slots. The default slot 0 is the device head; subsequent slots correspond to I/O modules or submodules. Slot numbering must be continuous starting at 1 for the head module.
  5. Save and compile (Station > Consistency Check > Compile).

After downloading the hardware configuration to the CPU, the CP 343-1 acts as the PROFINET IO controller and begins the PROFINET naming and connection process. Devices without a name will appear in the diagnostic buffer with a "Device not found" or "Name assignment error" entry.

8. PNIO_SEND (FC11) and PNIO_RECV (FC12) Programming

Configuring the IO system alone is not sufficient. The user program must call the SIMATIC NET blocks to:

  • PNIO_SEND (FC11): transfer the controller's output process image to the IO devices' input slots.
  • PNIO_RECV (FC12): fetch the IO devices' input process image into the controller's input area.

Standard block call signature (STEP 7 V5.x):

// PNIO_SEND (FC11) - transfer output data to PROFINET IO
CALL  FC11  (
     CPLADDR      := W#16#0100,         // Logical base address of the CP (from HW Config: Properties > Interface > Addresses)
     SEND         := P#M 100.0 BYTE 32, // Source area in process image (outputs to IO devices)
     LEN          := 32,                // Length in bytes
     DONE         := M 200.0,           // 1 = transfer complete
     ERROR        := M 200.1,           // 1 = error, see STATUS
     STATUS       := MW 202,            // Hex error code (e.g., W#16#0000 = OK)
     SENDMODE     := 0                  // 0 = full update, 1 = partial update
);
// PNIO_RECV (FC12) - read input data from PROFINET IO
CALL  FC12  (
     CPLADDR      := W#16#0100,
     RECV         := P#M 150.0 BYTE 32, // Destination area (inputs from IO devices)
     LEN          := 32,
     NDR          := M 201.0,           // 1 = new data received
     ERROR        := M 201.1,
     STATUS       := MW 204,
     RECVMODE     := 0
);

The CPLADDR value must match the I/O start address assigned to the CP in HW Config. Open the CP's object properties, tab "Addresses", and use the value shown under "Inputs" or "Outputs" (both are usually the same base address, often 256 decimal / 0x100 hex).

Common programming error: Calling the FCs with the wrong CPLADDR (e.g., using the CPU's address instead of the CP's address) is the single most common cause of STATUS = W#16#8A4A or W#16#80B0 in the field. Always cross-check the CP base address in HW Config before downloading the program.

9. Status and Error Code Reference

STATUS (hex) Meaning Likely Cause Remediation
W#16#0000 Job completed, no error Normal operation None required
W#16#80B0 CPLADDR cannot be reached Wrong CP base address or CP not initialised Verify CPLADDR; check that the CP is on the same subnet and physically connected
W#16#80B1 Wrong length / area length mismatch LEN does not match configured I/O length Compare LEN with the IO system's configured input/output lengths
W#16#8A4A CP not in IO controller mode CP is operating as an I-device instead Remove I-device configuration; ensure PROFINET IO system is inserted under PN-IO
W#16#80C0 IO device not reachable Physical link, naming, or IP issue Verify cabling, port LEDs (LINK/ACT), and PROFINET device name assignment
W#16#80C1 Slot configuration mismatch IO device slot map differs from project Re-compile and download HW Config; verify slot order matches the device
W#16#80C2 Diagnostic interrupt from IO device Submodule pulled or failed Read device diagnostic record; check slot 0 diagnostic

10. Verification

  1. Online diagnostics: In STEP 7, select the S7 station and choose PLC > Online & Diagnostics. Open the CP's "PROFINET IO" diagnostics folder. All configured IO devices should appear with status "OK".
  2. Diagnostic buffer: PLC > Diagnostic/Setting > Diagnostic Buffer. Confirm the CP has logged "PROFINET IO controller startup completed" after download.
  3. Process image test: Force a known value into a configured output area and read the corresponding input from the connected device. The IO device's local LED indicators should change state.
  4. Web server (where available): CP 343-1 Advanced and some v3.x variants expose a web server at the CP's IP address. Log in and inspect the "PROFINET" page for live port and device status.
  5. PRONETA: Use Siemens PRONETA (free tool) to scan the network, verify device names and IP addresses, and run a topology check before commissioning.

11. Troubleshooting Matrix

Symptom Likely Root Cause Diagnostic Step Resolution
No PROFINET IO system appears beneath the CP v3.x firmware; role not yet implied Right-click PN-IO; check whether "Insert PROFINET IO System" is greyed out Confirm CP base address is valid and the IO device role is not enabled
IO system created but devices remain offline PROFINET device name not assigned or duplicate PRONETA or topology editor scan Re-assign the device name from the controller using STEP 7 "Assign PROFINET Device Name"
FC11/FC12 return STATUS 80B0 Wrong CPLADDR Compare HW Config CP addresses with FC parameter Update CPLADDR to the actual CP base address (hex 0100 typical)
FC11/FC12 return STATUS 8A4A CP is acting as I-device PN-IO properties > "Operate as IO device" checkbox Uncheck; rebuild IO system under the CP
LINK LED off on X1 Cable/port issue Swap patch cable, check switch port Replace cable; verify switch port is enabled (no admin-down state)
PROFINET alarm storm in diagnostic buffer Submodule removed or under-provisioned power Filter diagnostic buffer for "Station failure" Re-seat the submodule or check the power budget of the IO device
PNIO_RECV shows NDR=0 continuously No I/O data updating Inspect SEND block first; verify DONE pulses Ensure SEND completes before RECV; check watchdog time on the IO device

12. TIA Portal Considerations (Brief)

For new projects, Siemens recommends migrating the S7-300 station to TIA Portal and using a CPU with an integrated PROFINET interface (CPU 315-2 PN/DP, CPU 317-2 PN/DP, or CPU 319-3 PN/DP) instead of the CP 343-1. The integrated PN interface simplifies configuration and is the modern replacement path. For sites that must keep the CP 343-1 due to existing wiring or slot constraints, the configuration steps above apply.

If the CP 343-1 is to be used as an I-device (intelligent PROFINET device) instead of an IO controller, the configuration is fundamentally different: enable "Operate as IO device" in the PN-IO properties, define the transfer area, and expose the CP as a sub-slave to an upper-level controller. See Configure CP 343-1 as a PROFINET I device in STEP 7 (TIA Portal) - Siemens Support (ID 109744406) for the device-mode procedure.

Why does the CP 343-1 v3.0 not show the IO controller checkbox like v2.0 did?

On v3.x firmware, the role is implicit. If the PN-IO node has no "Operate as IO device" checkbox set and you insert a PROFINET IO system beneath it, the CP becomes the IO controller automatically. The v2.x checkbox is a redundant UI element that was removed in v3.x to avoid double-assignment.

Do I really need to call PNIO_SEND (FC11) and PNIO_RECV (FC12) in my S7-300 program?

Yes. Configuring the IO system defines the slots and addresses, but the cyclic data exchange is driven by these FCs. Without them, the CP cannot move the controller's process outputs to the IO devices, and NDR/DONE flags in the FCs will remain low. The blocks are part of the SIMATIC NET library supplied with STEP 7.

What is the typical base address (CPLADDR) for the CP 343-1?

STEP 7 commonly assigns 0x100 (256 decimal) as the I/O base address of the CP 343-1. Always confirm by opening the CP's object properties, tab "Addresses", and reading the value directly from the project rather than assuming a constant.

How many PROFINET IO devices can a CP 343-1 manage?

The number depends on the variant. The CP 343-1 Lean (6GK7 343-1EX30-0XE0) supports a smaller maximum than the standard CP 343-1. Refer to the SIMATIC NET manual for the exact limit of your specific order number and firmware version.

Can the CP 343-1 act as both an IO controller and an I-device at the same time?

No. The PROFINET role is exclusive on the CP 343-1. To operate the station as an I-device (subordinate to another controller), disable the IO controller role by enabling "Operate as IO device" in the PN-IO properties and remove the local PROFINET IO system. The two modes cannot coexist on a single CP 343-1 instance.

Back to blog